XN-Matt +1
I also need the ability to remove the default imap, pop, and smtp CNAME records from the global DNS template for new zones.
The reason is that there are no Let’s Encrypt certificates issued for these subdomains, and some mail clients (for example, Thunderbird v152) give these CNAMEs higher priority than the SRV records during autoconfiguration. When these CNAMEs exist, Thunderbird autoconfig prefers them and fails due to the missing certificates; once the CNAMEs are removed, autodiscovery works correctly using the SRV records.
End users now expect a smooth, automatic mail client setup experience similar to Gmail, Outlook, and Microsoft 365, so having full control over the default DNS records is quite important.
I would suggest to list all current default records under Settings / Platform / DNS and the allow admin to add/edit/remove as needed.