Domains
Add sending domains, read their DNS records and verification status, and verify them.
Create a domain
Adds a sending domain and returns the DNS records to publish for it.
/domainsRequires a full API key. Emailit generates a 2048-bit DKIM key for the domain. Publish the records in dns_records at your DNS provider, then call Verify a domain. You can send from the domain once it’s verified. See Add a domain and DNS records.
The number of domains depends on your plan: 3 on Pay as you go (25 after your first credit purchase), 100 on Pro and 1,000 on Business. Fires a domain.created event.
Body parameters
namestringrequiredThe domain to send from, such as acme.com or mail.acme.com, without http://, https:// or www.. Stored in lowercase. Your from addresses must use exactly this domain.
tracking_keystringThe subdomain label for the open and click tracking CNAME. Defaults to go, which gives go.acme.com. Letters, digits and hyphens.
inbound_keystringThe subdomain label for receiving email. Defaults to inbound, which gives inbound.acme.com. Letters, digits and hyphens.
dmarc_reportsbooleandefault: falseCollect DMARC reports for the domain. Emailit creates a reporting address and adds it to the suggested DMARC record. Available on Pro, Business and Custom plans. See DMARC.
track_loadsbooleandefault: falsefalse when you create a domain. Turn tracking on with Update a domain once the tracking CNAME is verified.track_clicksbooleandefault: falsetrack_loads, for click tracking.The older outgoing, incoming and use_for_any flags are accepted for compatibility and have no effect.
Returns
Returns 201 with the domain object, including dns_records. A new domain has the status pending, or pending_review on Pay as you go until its first DNS check.
curl https://api.emailit.com/v2/domains \
-H "Authorization: Bearer $EMAILIT_API_KEY" \
-H "Content-Type: application/json" \
-d '{
"name": "acme.com",
"tracking_key": "links",
"inbound_key": "reply",
"dmarc_reports": true
}'{
"object": "domain",
"id": "dom_4K468YrjOkR1wwdhqiO0G9XEUey",
"name": "acme.com",
"verification_token": "vt_4KY8weirBN9sxnfbIt78tsFWteY",
"verification_method": "dns",
"verified_at": null,
"manually_verified_at": null,
"manual_review_required": false,
"verification_status": "pending",
"dkim_identifier_string": "emailit",
"dns_checked_at": null,
"spf_status": "pending",
"spf_error": null,
"dkim_status": "pending",
"dkim_error": null,
"mx_status": "pending",
"mx_error": null,
"return_path_status": "pending",
"return_path_error": null,
"dmarc_status": "pending",
"dmarc_error": null,
"tracking_status": "pending",
"tracking_error": null,
"tracking_key": null,
"inbound_status": "pending",
"inbound_error": null,
"inbound_key": null,
"track_loads": 0,
"track_clicks": 0,
"dmarc_reports": false,
"dmarc_address": null,
"created_at": "2026-10-01T09:12:03.551208Z",
"updated_at": "2026-10-01T09:12:03.551208Z",
"dns_records": [
{
"required": true,
"type": "MX",
"name": "emailit.acme.com",
"value": "feedback-smtp.ffdc-1.emailit.com",
"priority": 10,
"ttl": "auto",
"status": "pending",
"error": null
},
{
"required": true,
"type": "TXT",
"name": "emailit.acme.com",
"value": "v=spf1 include:_spf.emailit.com ~all",
"priority": null,
"ttl": "auto",
"status": "pending",
"error": null
},
{
"required": true,
"type": "TXT",
"name": "emailit._domainkey.acme.com",
"value": "v=DKIM1; t=s; h=sha256; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAx3kQ...IDAQAB;",
"priority": null,
"ttl": "auto",
"status": "pending",
"error": null
},
{
"required": false,
"type": "TXT",
"name": "_dmarc.acme.com",
"value": "v=DMARC1; p=none;",
"priority": null,
"ttl": "auto",
"status": "pending",
"error": null
},
{
"required": false,
"type": "CNAME",
"name": "go.acme.com",
"value": "go.emailitmail.com",
"priority": null,
"ttl": "auto",
"status": "pending",
"error": null
},
{
"required": false,
"type": "MX",
"name": "inbound.acme.com",
"value": "inbound.emailitmail.com",
"priority": 10,
"ttl": "auto",
"status": "pending",
"error": null
}
]
}{
"error": "The domain must be in apex format (e.g., domain.com) without http://, https://, or www."
}{
"error": "plan_required",
"required_plan": "pro"
}{
"error": "Domain with this name already exists",
"existing": {
"object": "domain",
"id": "dom_4K468YrjOkR1wwdhqiO0G9XEUey",
"name": "acme.com"
}
}{
"error": "Pay as you go includes 3 domain(s)."
}{
"error": "Tracking requires a verified custom CNAME. New messages are not rewritten to a shared tracking URL."
}Retrieve a domain
Retrieves a sending domain with its verification status and DNS records.
/domains/{id}Requires a full API key. Record statuses reflect the last DNS check, which runs when you call Verify a domain and once a day automatically.
Path parameters
idstringrequireddom_…, or sd_… and sed_… for older domains) or the domain name, such as acme.com.Returns
Returns the domain object.
objectstringdomain.idstringnamestringverification_statusstringverified when the domain can send. pending while SPF, DKIM or the return path isn’t correct yet. pending_review on Pay as you go when the domain needs a manual review by Emailit before it can be verified, for example because it was registered less than 30 days ago.
verified_atstring | nullnull if the domain isn’t verified. A failed check clears it.manual_review_requiredbooleanmanually_verified_atstring | nullnull.dns_checked_atstring | nullspf_status, dkim_status, return_path_statusstringStatus of the three required records: pending (not checked yet), ok, missing or invalid. All three must be ok for the domain to be verified.
mx_statusstringreturn_path_status.dmarc_statusstringpending, ok, missing, invalid or error. Optional for verification.tracking_statusstringok before you can turn on tracking.inbound_statusstringspf_error, dkim_error, mx_error, return_path_error, dmarc_error, tracking_error, inbound_errorstring | nullnull.tracking_keystring | nullnull for the default go.inbound_keystring | nullnull for the default inbound.track_loadsinteger1 if open tracking is on by default for emails from this domain, 0 if not.track_clicksinteger1 if click tracking is on by default, 0 if not.dmarc_reportsbooleandmarc_addressstring | nullnull when dmarc_reports is off.verification_token, verification_method, dkim_identifier_stringstringverification_method is dns and dkim_identifier_string is the DKIM selector, emailit.created_at, updated_atstringdns_recordsobject[]The records to publish. Each has type (MX, TXT or CNAME), name, value, priority (for MX records), ttl (auto), required (whether it’s needed for verification), and its current status and error.
| Record | Type | Name | Value | Required |
|---|---|---|---|---|
| Return path | MX | emailit.acme.com |
feedback-smtp.ffdc-1.emailit.com, priority 10 |
Yes |
| SPF | TXT | emailit.acme.com |
v=spf1 include:_spf.emailit.com ~all |
Yes |
| DKIM | TXT | emailit._domainkey.acme.com |
v=DKIM1; t=s; h=sha256; p=… |
Yes |
| DMARC | TXT | _dmarc.acme.com |
v=DMARC1; p=none;, plus report addresses when dmarc_reports is on |
No |
| Tracking | CNAME | go.acme.com |
go.emailitmail.com |
No |
| Inbound | MX | inbound.acme.com |
inbound.emailitmail.com, priority 10 |
No |
{
"object": "domain",
"id": "dom_4K468YrjOkR1wwdhqiO0G9XEUey",
"name": "acme.com",
"verification_token": "vt_4KY8weirBN9sxnfbIt78tsFWteY",
"verification_method": "dns",
"verified_at": "2026-10-01T03:00:12.000000Z",
"manually_verified_at": null,
"manual_review_required": false,
"verification_status": "verified",
"dkim_identifier_string": "emailit",
"dns_checked_at": "2026-10-01T03:00:12.000000Z",
"spf_status": "ok",
"spf_error": null,
"dkim_status": "ok",
"dkim_error": null,
"mx_status": "ok",
"mx_error": null,
"return_path_status": "ok",
"return_path_error": null,
"dmarc_status": "ok",
"dmarc_error": null,
"tracking_status": "ok",
"tracking_error": null,
"tracking_key": null,
"inbound_status": "invalid",
"inbound_error": "queryMx ENOTFOUND inbound.acme.com",
"inbound_key": null,
"track_loads": 1,
"track_clicks": 1,
"dmarc_reports": true,
"dmarc_address": "4KXUJdXRVlVgbkWQm4GHLy8BleP@dmarc.emailitmail.com",
"created_at": "2026-09-14T08:02:51.000000Z",
"updated_at": "2026-10-01T03:00:12.000000Z",
"dns_records": [
{
"required": true,
"type": "MX",
"name": "emailit.acme.com",
"value": "feedback-smtp.ffdc-1.emailit.com",
"priority": 10,
"ttl": "auto",
"status": "ok",
"error": null
},
{
"required": true,
"type": "TXT",
"name": "emailit.acme.com",
"value": "v=spf1 include:_spf.emailit.com ~all",
"priority": null,
"ttl": "auto",
"status": "ok",
"error": null
},
{
"required": true,
"type": "TXT",
"name": "emailit._domainkey.acme.com",
"value": "v=DKIM1; t=s; h=sha256; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAx3kQ...IDAQAB;",
"priority": null,
"ttl": "auto",
"status": "ok",
"error": null
},
{
"required": false,
"type": "TXT",
"name": "_dmarc.acme.com",
"value": "v=DMARC1; p=none; rua=mailto:4KXUJdXRVlVgbkWQm4GHLy8BleP@dmarc.emailitmail.com; ruf=mailto:4KXUJdXRVlVgbkWQm4GHLy8BleP@dmarc.emailitmail.com;",
"priority": null,
"ttl": "auto",
"status": "ok",
"error": null
},
{
"required": false,
"type": "CNAME",
"name": "go.acme.com",
"value": "go.emailitmail.com",
"priority": null,
"ttl": "auto",
"status": "ok",
"error": null
},
{
"required": false,
"type": "MX",
"name": "inbound.acme.com",
"value": "inbound.emailitmail.com",
"priority": 10,
"ttl": "auto",
"status": "invalid",
"error": "queryMx ENOTFOUND inbound.acme.com"
}
]
}{
"error": "Domain not found"
}Verify a domain
Looks up the domain’s DNS records now, saves the result and returns the domain with its new statuses.
/domains/{id}/verifyRequires a full API key. Call it after you publish the records from Create a domain, and again whenever you change them. DNS changes can take a while to propagate, so if a record shows missing, wait a few minutes and retry.
The domain becomes verified when all three required records are ok:
- SPF: a TXT record at
emailit.<domain>that includes_spf.emailit.com. - DKIM: a TXT record at
emailit._domainkey.<domain>with the domain’s public key. - Return path: a single MX record at
emailit.<domain>pointing tofeedback-smtp.ffdc-1.emailit.com.
On Pay as you go, a domain registered less than 30 days ago gets pending_review instead, and Emailit reviews it manually. The DMARC, tracking and inbound records are checked too, but they don’t affect verification.
Emailit also re-checks every domain once a day. If a required record stops passing, the domain is no longer verified, sends from it fail, and the workspace owner gets an email. See Domain verification.
Path parameters
idstringrequiredReturns
Returns the domain object with the result of this check in verification_status, each *_status and *_error field, and dns_records. This response doesn’t include dmarc_reports and dmarc_address; read them with Retrieve a domain.
{
"object": "domain",
"id": "dom_4K468YrjOkR1wwdhqiO0G9XEUey",
"name": "acme.com",
"verification_token": "vt_4KY8weirBN9sxnfbIt78tsFWteY",
"verification_method": "dns",
"verified_at": null,
"manually_verified_at": null,
"manual_review_required": false,
"dkim_identifier_string": "emailit",
"dns_checked_at": "2026-10-01T09:20:41.000000Z",
"spf_status": "ok",
"spf_error": null,
"dkim_status": "missing",
"dkim_error": "queryTxt ENOTFOUND emailit._domainkey.acme.com",
"mx_status": "ok",
"mx_error": null,
"return_path_status": "ok",
"return_path_error": null,
"dmarc_status": "error",
"dmarc_error": "queryTxt ENOTFOUND _dmarc.acme.com",
"tracking_status": "invalid",
"tracking_error": "queryCname ENOTFOUND go.acme.com",
"tracking_key": null,
"inbound_status": "invalid",
"inbound_error": "queryMx ENOTFOUND inbound.acme.com",
"inbound_key": null,
"track_loads": 0,
"track_clicks": 0,
"created_at": "2026-10-01T09:12:03.000000Z",
"updated_at": "2026-10-01T09:20:41.000000Z",
"dns_records": [
{
"required": true,
"type": "MX",
"name": "emailit.acme.com",
"value": "feedback-smtp.ffdc-1.emailit.com",
"priority": 10,
"ttl": "auto",
"status": "ok",
"error": null
},
{
"required": true,
"type": "TXT",
"name": "emailit.acme.com",
"value": "v=spf1 include:_spf.emailit.com ~all",
"priority": null,
"ttl": "auto",
"status": "ok",
"error": null
},
{
"required": true,
"type": "TXT",
"name": "emailit._domainkey.acme.com",
"value": "v=DKIM1; t=s; h=sha256; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAx3kQ...IDAQAB;",
"priority": null,
"ttl": "auto",
"status": "missing",
"error": "queryTxt ENOTFOUND emailit._domainkey.acme.com"
},
{
"required": false,
"type": "TXT",
"name": "_dmarc.acme.com",
"value": "v=DMARC1; p=none;",
"priority": null,
"ttl": "auto",
"status": "error",
"error": "queryTxt ENOTFOUND _dmarc.acme.com"
},
{
"required": false,
"type": "CNAME",
"name": "go.acme.com",
"value": "go.emailitmail.com",
"priority": null,
"ttl": "auto",
"status": "invalid",
"error": "queryCname ENOTFOUND go.acme.com"
},
{
"required": false,
"type": "MX",
"name": "inbound.acme.com",
"value": "inbound.emailitmail.com",
"priority": 10,
"ttl": "auto",
"status": "invalid",
"error": "queryMx ENOTFOUND inbound.acme.com"
}
],
"verification_status": "pending"
}{
"error": "Domain not found"
}Update a domain
Updates the settings of a sending domain. Only the fields you send change.
/domains/{id}Requires a full API key. Fires a domain.updated event.
Path parameters
idstringrequiredBody parameters
track_loadsbooleanTurn open tracking on or off by default for emails from this domain. Turning it on requires a verified tracking CNAME (tracking_status is ok). See Custom tracking domain.
track_clicksbooleantrack_loads.tracking_keystring | nullA new subdomain label for the tracking CNAME, or null for the default go. Changing it resets tracking_status to pending, so publish the new CNAME and verify again.
inbound_keystring | nullnull for the default inbound. Changing it resets inbound_status to pending.dmarc_reportsbooleanCollect DMARC reports for the domain. Turning it on adds a reporting address to the suggested DMARC record, so update your _dmarc record afterward. Pro, Business and Custom plans only. Turning it off keeps the address for later.
namestringA new domain name. The DNS records move to the new name, so publish them there and verify again before you send from it.
The older outgoing, incoming and use_for_any flags are accepted and have no effect. Unknown fields are ignored. A request without any of these fields returns 400.
Returns
Returns the updated domain object, including dns_records.
curl -X POST https://api.emailit.com/v2/domains/acme.com \
-H "Authorization: Bearer $EMAILIT_API_KEY" \
-H "Content-Type: application/json" \
-d '{"track_loads": true, "track_clicks": true}'{
"object": "domain",
"id": "dom_4K468YrjOkR1wwdhqiO0G9XEUey",
"name": "acme.com",
"verification_token": "vt_4KY8weirBN9sxnfbIt78tsFWteY",
"verification_method": "dns",
"verified_at": "2026-10-01T03:00:12.000000Z",
"manually_verified_at": null,
"manual_review_required": false,
"verification_status": "verified",
"dkim_identifier_string": "emailit",
"dns_checked_at": "2026-10-01T03:00:12.000000Z",
"spf_status": "ok",
"spf_error": null,
"dkim_status": "ok",
"dkim_error": null,
"mx_status": "ok",
"mx_error": null,
"return_path_status": "ok",
"return_path_error": null,
"dmarc_status": "ok",
"dmarc_error": null,
"tracking_status": "ok",
"tracking_error": null,
"tracking_key": null,
"inbound_status": "invalid",
"inbound_error": "queryMx ENOTFOUND inbound.acme.com",
"inbound_key": null,
"track_loads": 1,
"track_clicks": 0,
"dmarc_reports": false,
"dmarc_address": null,
"created_at": "2026-09-14T08:02:51.000000Z",
"updated_at": "2026-10-01T10:44:20.000000Z",
"dns_records": [
{
"required": true,
"type": "MX",
"name": "emailit.acme.com",
"value": "feedback-smtp.ffdc-1.emailit.com",
"priority": 10,
"ttl": "auto",
"status": "ok",
"error": null
},
{
"required": true,
"type": "TXT",
"name": "emailit.acme.com",
"value": "v=spf1 include:_spf.emailit.com ~all",
"priority": null,
"ttl": "auto",
"status": "ok",
"error": null
},
{
"required": true,
"type": "TXT",
"name": "emailit._domainkey.acme.com",
"value": "v=DKIM1; t=s; h=sha256; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAx3kQ...IDAQAB;",
"priority": null,
"ttl": "auto",
"status": "ok",
"error": null
},
{
"required": false,
"type": "TXT",
"name": "_dmarc.acme.com",
"value": "v=DMARC1; p=none;",
"priority": null,
"ttl": "auto",
"status": "ok",
"error": null
},
{
"required": false,
"type": "CNAME",
"name": "go.acme.com",
"value": "go.emailitmail.com",
"priority": null,
"ttl": "auto",
"status": "ok",
"error": null
},
{
"required": false,
"type": "MX",
"name": "inbound.acme.com",
"value": "inbound.emailitmail.com",
"priority": 10,
"ttl": "auto",
"status": "invalid",
"error": "queryMx ENOTFOUND inbound.acme.com"
}
]
}{
"error": "No valid fields provided for update. Provide at least one of: name, outgoing, incoming, use_for_any, track_loads, track_clicks, tracking_key, inbound_key, dmarc_reports"
}{
"error": "plan_required",
"required_plan": "pro"
}{
"error": "Domain not found"
}{
"error": "Another domain with this name already exists"
}{
"error": "Tracking requires a verified custom CNAME. New messages are not rewritten to a shared tracking URL."
}List domains
Returns a page of sending domains, newest first, with your plan’s domain allowance.
/domainsRequires a full API key. List items don’t include dns_records; use Retrieve a domain for those.
Query parameters
pageintegerdefault: 1limitintegerdefault: 10searchstringmatchstringdefault: allall or or. How the filters below combine.orderstringdirectionstringasc or desc.Filters
Add filters as key.condition=value, for example dkim_status.exact=ok. See Filtering.
| Key | Type | Values and notes |
|---|---|---|
name |
string | |
created_at |
date | |
spf_status |
enum | ok, missing, invalid |
dkim_status |
enum | ok, missing, invalid |
return_path_status |
enum | ok, missing, invalid |
Every key is also a sort key.
Returns
dataobject[]dns_records.next_page_urlstring | nullnull. See Pagination.previous_page_urlstring | nullnull.domain_limitinteger | nullnull for no limit.domain_countintegerplan_namestring | nullPay as you go or Pro.curl -G https://api.emailit.com/v2/domains \
-H "Authorization: Bearer $EMAILIT_API_KEY" \
-d dkim_status.not_exact=ok \
-d spf_status.not_exact=ok \
-d match=or{
"data": [
{
"object": "domain",
"id": "dom_4K468YrjOkR1wwdhqiO0G9XEUey",
"name": "acme.com",
"verification_token": "vt_4KY8weirBN9sxnfbIt78tsFWteY",
"verification_method": "dns",
"verified_at": "2026-10-01T03:00:12.000000Z",
"manually_verified_at": null,
"manual_review_required": false,
"verification_status": "verified",
"dkim_identifier_string": "emailit",
"dns_checked_at": "2026-10-01T03:00:12.000000Z",
"spf_status": "ok",
"spf_error": null,
"dkim_status": "ok",
"dkim_error": null,
"mx_status": "ok",
"mx_error": null,
"return_path_status": "ok",
"return_path_error": null,
"dmarc_status": "ok",
"dmarc_error": null,
"tracking_status": "ok",
"tracking_error": null,
"tracking_key": null,
"inbound_status": "invalid",
"inbound_error": "queryMx ENOTFOUND inbound.acme.com",
"inbound_key": null,
"track_loads": 1,
"track_clicks": 1,
"dmarc_reports": true,
"dmarc_address": "4KXUJdXRVlVgbkWQm4GHLy8BleP@dmarc.emailitmail.com",
"created_at": "2026-09-14T08:02:51.000000Z",
"updated_at": "2026-10-01T03:00:12.000000Z"
}
],
"next_page_url": null,
"previous_page_url": null,
"domain_limit": 100,
"domain_count": 1,
"plan_name": "Pro"
}Delete a domain
Permanently deletes a sending domain.
/domains/{id}Requires a full API key. After the delete, sends from the domain fail with Domain not verified, and API keys restricted to the domain can’t send anymore. The domain’s DKIM key, sending health history and any stored Cloudflare connection are removed too. Emails already sent stay in your logs. Fires a domain.deleted event.
To send from the domain again, create it again. It gets a new DKIM key, so you’ll need to update the DKIM record.
Path parameters
idstringrequiredReturns
objectstringdomain.idstringnamestringdeletedbooleantrue.{
"object": "domain",
"id": "dom_4K468YrjOkR1wwdhqiO0G9XEUey",
"name": "acme.com",
"deleted": true
}{
"error": "Domain not found"
}