Another option: add mail.domain.com to an existing service in rule=Host (using ||) to let Traefik create a cert for it.
mail.domain.com
rule=Host