Conversation

Correct, but for a website, you should probably disable DHE and other legacy ciphers. DHE is only useful for a website to support Internet Explorer when using RSA certificates since it only supports ECDHE with ECSDA certificates. Use ECDSA certificate and ECDHE works fine for it.
2
2
This is what we use for the GrapheneOS web servers: github.com/GrapheneOS/gra If you don't care about supporting legacy clients including various bots, disable TLS 1.2. TLS 1.3 only has ECDHE. For email it's a bit different due to servers without DANE falling back to plain text.
1
1