Skip to content
Docs

Reference

Syntax and examples for MX, TXT, SPF, DKIM, DMARC, CNAME, PTR, BIMI, MTA-STS and TLS-RPT records, plus the exact records Emailit asks you to publish.

Updated Oct 1, 2026

Email authentication and routing run on DNS. This page explains the record types involved, their syntax and common mistakes. For the step-by-step setup of a sending domain, see DNS records.

Records Emailit asks for

When you add a domain such as acme.com, Emailit shows these records on the domain’s DNS Setup tab. The DKIM key is unique to your domain.

Purpose Type Name Value Required
Return path (bounces) MX emailit.acme.com feedback-smtp.ffdc-1.emailit.com, priority 10 Yes
SPF for the return path TXT emailit.acme.com v=spf1 include:_spf.emailit.com ~all Yes
DKIM TXT emailit._domainkey.acme.com v=DKIM1; t=s; h=sha256; p=MIIBIjANBg... Yes
DMARC TXT _dmarc.acme.com v=DMARC1; p=none; Recommended
Open and click tracking CNAME go.acme.com go.emailitmail.com Only for tracking
Inbound email MX inbound.acme.com inbound.emailitmail.com, priority 10 Only for inbound

The SPF, DKIM and return-path records must all pass before the domain can send. The tracking and inbound subdomains are configurable, so yours may differ from go and inbound. With DMARC reports turned on, the suggested DMARC record also includes rua and ruf addresses on dmarc.emailitmail.com.

MX

An MX record names the servers that accept mail for a domain. Each record has a priority, and lower numbers are tried first.

Text
acme.com.           3600  IN  MX  10 mx1.mailprovider.example.
acme.com.           3600  IN  MX  20 mx2.mailprovider.example.
  • Point an MX record to a hostname, never to an IP address or a CNAME.
  • Emailit’s return-path and inbound MX records live on subdomains (emailit. and inbound.), so they don’t affect the mailboxes on your root domain.

TXT

TXT records hold text. SPF, DKIM, DMARC, BIMI, MTA-STS and TLS-RPT are all published as TXT records. A single string in a TXT record can be at most 255 characters, so long values such as a 2048-bit DKIM key are split into several quoted strings that receivers join together:

Text
emailit._domainkey.acme.com. IN TXT ( "v=DKIM1; t=s; h=sha256; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA..."
                                      "...IDAQAB;" )

Most DNS providers split long values for you. If yours doesn’t, split the value yourself rather than truncating it.

SPF

SPF lists the servers allowed to send mail with your domain in the envelope sender (MAIL FROM). A domain name can have only one SPF record.

Text
v=spf1 ip4:203.0.113.10 include:_spf.example.net ~all
Part Meaning
v=spf1 Version. Must come first.
ip4: / ip6: Allow an IP address or range, such as ip4:203.0.113.0/24.
a / mx Allow the IPs of the domain’s A or MX records.
include: Allow everything another domain’s SPF record allows. Used for email services, such as include:_spf.emailit.com.
exists: Allow if a constructed hostname resolves. Rarely needed.
redirect= Use another domain’s SPF record instead of this one.
-all Fail everything not listed (hard fail).
~all Soft fail everything not listed. Receivers treat it as suspicious, and DMARC decides the outcome.
?all Neutral, no opinion.
+all Allow everyone. Never use it.

DKIM

A DKIM record publishes the public key that receivers use to verify the DKIM-Signature header. It lives at selector._domainkey.domain, where the selector comes from the signature’s s= tag. Emailit signs with a 2048-bit RSA key and the selector emailit.

Tag Meaning Emailit’s record
v Version, DKIM1. v=DKIM1
k Key type, rsa (default) or ed25519. Omitted, so RSA.
p The public key, base64-encoded. An empty p= revokes the key. Your domain’s key.
t Flags: y means testing, s means the signing identity can’t be a subdomain of d=. t=s
h Hash algorithms the key may be used with. h=sha256
s Service type, email or *. Omitted.

Emailit verifies DKIM by comparing the v, k and p values, so extra whitespace, quoting and tag order don’t matter. Each selector is independent, so Emailit’s emailit selector doesn’t conflict with keys from other services on the same domain.

DMARC

A DMARC record tells receivers what to do when a message fails both SPF and DKIM alignment, and where to send reports. It lives at _dmarc.domain.

Text
v=DMARC1; p=quarantine; rua=mailto:dmarc@acme.com; adkim=r; aspf=r; pct=100
Tag Meaning Default
v Version, DMARC1. Must come first. Required
p Policy for the domain: none (monitor only), quarantine (send to spam) or reject. Required
sp Policy for subdomains. Same as p
rua Where to send aggregate reports, as mailto: URIs separated by commas. None
ruf Where to send forensic (failure) reports. None
pct Percentage of failing mail the policy applies to. 100
adkim DKIM alignment: r (relaxed, subdomains match) or s (strict, exact match). r
aspf SPF alignment: r or s. r
fo When to send forensic reports: 0 (all checks fail), 1 (any check fails), d (DKIM fails) or s (SPF fails). 0
ri Requested interval between aggregate reports, in seconds. 86400

Emailit mail passes DMARC with relaxed alignment on both checks: DKIM signs with d=acme.com, and the envelope sender emailit.acme.com is a subdomain of acme.com. Emailit marks the DMARC record as valid when it has a p= policy of none, quarantine or reject. Start with p=none, read your DMARC reports, then move to quarantine and reject once every service that sends as your domain passes.

CNAME

A CNAME record makes one hostname an alias of another. Emailit uses one for your tracking domain.

Text
go.acme.com.  3600  IN  CNAME  go.emailitmail.com.
  • A name with a CNAME can’t have any other record, and you can’t put a CNAME on the root domain.
  • In Cloudflare, set the tracking record to DNS only. A proxied record hides the CNAME, so verification fails.

PTR

A PTR record maps an IP address back to a hostname (reverse DNS). Receivers check that a sending IP has one and that it resolves forward to the same IP. PTR records belong to whoever owns the IP, so Emailit manages them for its sending IPs and you don’t publish one.

BIMI

BIMI shows your logo next to authenticated mail in supporting inboxes. It’s a TXT record at default._bimi.domain:

Text
v=BIMI1; l=https://acme.com/brand/logo.svg; a=https://acme.com/brand/vmc.pem
Tag Meaning
v Version, BIMI1.
l HTTPS URL of the logo, an SVG in the Tiny Portable/Secure profile.
a HTTPS URL of a Verified Mark Certificate or Common Mark Certificate, which Gmail and Apple Mail require.

BIMI works only when the domain’s DMARC policy is quarantine or reject, with pct=100.

MTA-STS and TLS-RPT

MTA-STS and TLS-RPT protect mail sent to your domain, so they matter for domains that receive mail, such as your mailboxes or an inbound subdomain. They don’t affect mail you send through Emailit.

MTA-STS tells sending servers to require valid TLS when they deliver to your MX hosts. It needs a TXT record and a policy file served over HTTPS:

Text
_mta-sts.acme.com.  IN TXT  "v=STSv1; id=20261001"
https://mta-sts.acme.com/.well-known/mta-sts.txt
version: STSv1
mode: enforce
mx: mx1.mailprovider.example
max_age: 604800

TLS-RPT asks sending servers to send daily reports about TLS problems they hit when delivering to you:

Text
_smtp._tls.acme.com.  IN TXT  "v=TLSRPTv1; rua=mailto:tls-reports@acme.com"

TTL

Every record has a TTL (time to live): how many seconds resolvers may cache it. Lower the TTL to 300 a day before you change a record, so the change takes effect quickly, and raise it again afterwards. DNS changes usually appear within minutes but can take up to 48 hours.

Was this page helpful?

Thanks for the feedback.

Thanks, we read every message.