# DNS records for email

> Syntax and examples for MX, TXT, SPF, DKIM, DMARC, CNAME, PTR, BIMI, MTA-STS and TLS-RPT records, plus the exact records Emailit asks you to publish.

Email authentication and routing run on DNS. This page explains the record types involved, their syntax and common mistakes. For the step-by-step setup of a sending domain, see [DNS records](/docs/domains/dns-records/).

## Records Emailit asks for

When you [add a domain](/docs/domains/add-a-domain/) such as `acme.com`, Emailit shows these records on the domain's **DNS Setup** tab. The DKIM key is unique to your domain.

| Purpose | Type | Name | Value | Required |
|---|---|---|---|---|
| Return path (bounces) | `MX` | `emailit.acme.com` | `feedback-smtp.ffdc-1.emailit.com`, priority `10` | Yes |
| SPF for the return path | `TXT` | `emailit.acme.com` | `v=spf1 include:_spf.emailit.com ~all` | Yes |
| DKIM | `TXT` | `emailit._domainkey.acme.com` | `v=DKIM1; t=s; h=sha256; p=MIIBIjANBg...` | Yes |
| DMARC | `TXT` | `_dmarc.acme.com` | `v=DMARC1; p=none;` | Recommended |
| Open and click tracking | `CNAME` | `go.acme.com` | `go.emailitmail.com` | Only for tracking |
| Inbound email | `MX` | `inbound.acme.com` | `inbound.emailitmail.com`, priority `10` | Only for inbound |

The SPF, DKIM and return-path records must all pass before the domain can send. The tracking and inbound subdomains are configurable, so yours may differ from `go` and `inbound`. With [DMARC reports](/docs/dmarc/set-up/) turned on, the suggested DMARC record also includes `rua` and `ruf` addresses on `dmarc.emailitmail.com`.

> **Your root SPF record doesn't change:** Emailit sends with an envelope sender on `emailit.acme.com`, so SPF is checked against that subdomain's record. You don't need to add Emailit to the SPF record on `acme.com`, and the 10-lookup limit of your root record isn't affected.

## MX

An MX record names the servers that accept mail for a domain. Each record has a priority, and lower numbers are tried first.

```text
acme.com.           3600  IN  MX  10 mx1.mailprovider.example.
acme.com.           3600  IN  MX  20 mx2.mailprovider.example.
```

- Point an MX record to a hostname, never to an IP address or a CNAME.
- Emailit's return-path and inbound MX records live on subdomains (`emailit.` and `inbound.`), so they don't affect the mailboxes on your root domain.

## TXT

TXT records hold text. SPF, DKIM, DMARC, BIMI, MTA-STS and TLS-RPT are all published as TXT records. A single string in a TXT record can be at most 255 characters, so long values such as a 2048-bit DKIM key are split into several quoted strings that receivers join together:

```text
emailit._domainkey.acme.com. IN TXT ( "v=DKIM1; t=s; h=sha256; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA..."
                                      "...IDAQAB;" )
```

Most DNS providers split long values for you. If yours doesn't, split the value yourself rather than truncating it.

## SPF

SPF lists the servers allowed to send mail with your domain in the envelope sender (`MAIL FROM`). A domain name can have only one SPF record.

```text
v=spf1 ip4:203.0.113.10 include:_spf.example.net ~all
```

| Part | Meaning |
|---|---|
| `v=spf1` | Version. Must come first. |
| `ip4:` / `ip6:` | Allow an IP address or range, such as `ip4:203.0.113.0/24`. |
| `a` / `mx` | Allow the IPs of the domain's A or MX records. |
| `include:` | Allow everything another domain's SPF record allows. Used for email services, such as `include:_spf.emailit.com`. |
| `exists:` | Allow if a constructed hostname resolves. Rarely needed. |
| `redirect=` | Use another domain's SPF record instead of this one. |
| `-all` | Fail everything not listed (hard fail). |
| `~all` | Soft fail everything not listed. Receivers treat it as suspicious, and DMARC decides the outcome. |
| `?all` | Neutral, no opinion. |
| `+all` | Allow everyone. Never use it. |

> **The 10-lookup limit:** Evaluating an SPF record may trigger at most 10 DNS lookups. Each `include`, `a`, `mx`, `ptr`, `exists` and `redirect` counts, including those inside included records, while `ip4`, `ip6` and `all` don't. Above 10, the result is `permerror` and SPF fails. Remove services you no longer use, and replace `a` and `mx` with `ip4` ranges where you can.

## DKIM

A DKIM record publishes the public key that receivers use to verify the `DKIM-Signature` header. It lives at `selector._domainkey.domain`, where the selector comes from the signature's `s=` tag. Emailit signs with a 2048-bit RSA key and the selector `emailit`.

| Tag | Meaning | Emailit's record |
|---|---|---|
| `v` | Version, `DKIM1`. | `v=DKIM1` |
| `k` | Key type, `rsa` (default) or `ed25519`. | Omitted, so RSA. |
| `p` | The public key, base64-encoded. An empty `p=` revokes the key. | Your domain's key. |
| `t` | Flags: `y` means testing, `s` means the signing identity can't be a subdomain of `d=`. | `t=s` |
| `h` | Hash algorithms the key may be used with. | `h=sha256` |
| `s` | Service type, `email` or `*`. | Omitted. |

Emailit verifies DKIM by comparing the `v`, `k` and `p` values, so extra whitespace, quoting and tag order don't matter. Each selector is independent, so Emailit's `emailit` selector doesn't conflict with keys from other services on the same domain.

## DMARC

A DMARC record tells receivers what to do when a message fails both SPF and DKIM alignment, and where to send reports. It lives at `_dmarc.domain`.

```text
v=DMARC1; p=quarantine; rua=mailto:dmarc@acme.com; adkim=r; aspf=r; pct=100
```

| Tag | Meaning | Default |
|---|---|---|
| `v` | Version, `DMARC1`. Must come first. | Required |
| `p` | Policy for the domain: `none` (monitor only), `quarantine` (send to spam) or `reject`. | Required |
| `sp` | Policy for subdomains. | Same as `p` |
| `rua` | Where to send aggregate reports, as `mailto:` URIs separated by commas. | None |
| `ruf` | Where to send forensic (failure) reports. | None |
| `pct` | Percentage of failing mail the policy applies to. | `100` |
| `adkim` | DKIM alignment: `r` (relaxed, subdomains match) or `s` (strict, exact match). | `r` |
| `aspf` | SPF alignment: `r` or `s`. | `r` |
| `fo` | When to send forensic reports: `0` (all checks fail), `1` (any check fails), `d` (DKIM fails) or `s` (SPF fails). | `0` |
| `ri` | Requested interval between aggregate reports, in seconds. | `86400` |

Emailit mail passes DMARC with relaxed alignment on both checks: DKIM signs with `d=acme.com`, and the envelope sender `emailit.acme.com` is a subdomain of `acme.com`. Emailit marks the DMARC record as valid when it has a `p=` policy of `none`, `quarantine` or `reject`. Start with `p=none`, read your [DMARC reports](/docs/dmarc/reports/), then move to `quarantine` and `reject` once every service that sends as your domain passes.

## CNAME

A CNAME record makes one hostname an alias of another. Emailit uses one for your [tracking domain](/docs/tracking/custom-tracking-domain/).

```text
go.acme.com.  3600  IN  CNAME  go.emailitmail.com.
```

- A name with a CNAME can't have any other record, and you can't put a CNAME on the root domain.
- In Cloudflare, set the tracking record to **DNS only**. A proxied record hides the CNAME, so verification fails.

## PTR

A PTR record maps an IP address back to a hostname (reverse DNS). Receivers check that a sending IP has one and that it resolves forward to the same IP. PTR records belong to whoever owns the IP, so Emailit manages them for its sending IPs and you don't publish one.

## BIMI

BIMI shows your logo next to authenticated mail in supporting inboxes. It's a TXT record at `default._bimi.domain`:

```text
v=BIMI1; l=https://acme.com/brand/logo.svg; a=https://acme.com/brand/vmc.pem
```

| Tag | Meaning |
|---|---|
| `v` | Version, `BIMI1`. |
| `l` | HTTPS URL of the logo, an SVG in the Tiny Portable/Secure profile. |
| `a` | HTTPS URL of a Verified Mark Certificate or Common Mark Certificate, which Gmail and Apple Mail require. |

BIMI works only when the domain's DMARC policy is `quarantine` or `reject`, with `pct=100`.

## MTA-STS and TLS-RPT

MTA-STS and TLS-RPT protect mail sent **to** your domain, so they matter for domains that receive mail, such as your mailboxes or an inbound subdomain. They don't affect mail you send through Emailit.

MTA-STS tells sending servers to require valid TLS when they deliver to your MX hosts. It needs a TXT record and a policy file served over HTTPS:

```text
_mta-sts.acme.com.  IN TXT  "v=STSv1; id=20261001"
```

```text title="https://mta-sts.acme.com/.well-known/mta-sts.txt"
version: STSv1
mode: enforce
mx: mx1.mailprovider.example
max_age: 604800
```

TLS-RPT asks sending servers to send daily reports about TLS problems they hit when delivering to you:

```text
_smtp._tls.acme.com.  IN TXT  "v=TLSRPTv1; rua=mailto:tls-reports@acme.com"
```

## TTL

Every record has a TTL (time to live): how many seconds resolvers may cache it. Lower the TTL to 300 a day before you change a record, so the change takes effect quickly, and raise it again afterwards. DNS changes usually appear within minutes but can take up to 48 hours.

## Related

- [DNS records for Emailit](/docs/domains/dns-records/)
- [Set up DNS with Cloudflare](/docs/domains/cloudflare/)
- [Domain verification](/docs/domains/verification/)
- [Set up DMARC](/docs/dmarc/set-up/)
- [Email headers](/docs/dictionary/email-headers/)

---
Source: https://emailit.com/docs/dictionary/dns-records/
