The "custom" certificate: self-signed on first run, or your own uploaded cert/key above.
Which certificate each TLS listener uses — custom (above), or one of the two Let's
Encrypt certificates managed on the Let's Encrypt page. Independent
per listener, e.g. an HTTP-01 cert for mail while the dashboard keeps a DNS-01 or custom cert.
Changing which certificate a listener uses needs a restart to take effect. Once assigned, that listener's certificate then hot-reloads automatically on every future obtain/renew, no restart needed for that part.