1) Setup a postmaster account. Always pretty good practice though I do have port 25 inbound blocked to the server. I’ll set it up on Bluehost instead as everything is associated with the TLD there.
2) Setup SSH keys from my machine to the server. That way no passwords get used on the system just keys. If anyone gets in they don’t get the keys to the kingdom. I also need to remember to put myself in group wheel and to grant wheel the right to sudo without password.
And I really do want to make an image of the server – just in case it suffers catastrophic failure then all we have to do is build a base image and roll the image on external back to it.