Reference
DNS records for email
Syntax and examples for MX, TXT, SPF, DKIM, DMARC, CNAME, PTR, BIMI, MTA-STS and TLS-RPT records, plus the exact records Emailit asks you to publish.
Email authentication and routing run on DNS. This page explains the record types involved, their syntax and common mistakes. For the step-by-step setup of a sending domain, see DNS records.
Records Emailit asks for
When you add a domain such as acme.com, Emailit shows these records on the domain’s DNS Setup tab. The DKIM key is unique to your domain.
| Purpose | Type | Name | Value | Required |
|---|---|---|---|---|
| Return path (bounces) | MX |
emailit.acme.com |
feedback-smtp.ffdc-1.emailit.com, priority 10 |
Yes |
| SPF for the return path | TXT |
emailit.acme.com |
v=spf1 include:_spf.emailit.com ~all |
Yes |
| DKIM | TXT |
emailit._domainkey.acme.com |
v=DKIM1; t=s; h=sha256; p=MIIBIjANBg... |
Yes |
| DMARC | TXT |
_dmarc.acme.com |
v=DMARC1; p=none; |
Recommended |
| Open and click tracking | CNAME |
go.acme.com |
go.emailitmail.com |
Only for tracking |
| Inbound email | MX |
inbound.acme.com |
inbound.emailitmail.com, priority 10 |
Only for inbound |
The SPF, DKIM and return-path records must all pass before the domain can send. The tracking and inbound subdomains are configurable, so yours may differ from go and inbound. With DMARC reports turned on, the suggested DMARC record also includes rua and ruf addresses on dmarc.emailitmail.com.
MX
An MX record names the servers that accept mail for a domain. Each record has a priority, and lower numbers are tried first.
acme.com. 3600 IN MX 10 mx1.mailprovider.example.
acme.com. 3600 IN MX 20 mx2.mailprovider.example.- Point an MX record to a hostname, never to an IP address or a CNAME.
- Emailit’s return-path and inbound MX records live on subdomains (
emailit.andinbound.), so they don’t affect the mailboxes on your root domain.
TXT
TXT records hold text. SPF, DKIM, DMARC, BIMI, MTA-STS and TLS-RPT are all published as TXT records. A single string in a TXT record can be at most 255 characters, so long values such as a 2048-bit DKIM key are split into several quoted strings that receivers join together:
emailit._domainkey.acme.com. IN TXT ( "v=DKIM1; t=s; h=sha256; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA..."
"...IDAQAB;" )Most DNS providers split long values for you. If yours doesn’t, split the value yourself rather than truncating it.
SPF
SPF lists the servers allowed to send mail with your domain in the envelope sender (MAIL FROM). A domain name can have only one SPF record.
v=spf1 ip4:203.0.113.10 include:_spf.example.net ~all| Part | Meaning |
|---|---|
v=spf1 |
Version. Must come first. |
ip4: / ip6: |
Allow an IP address or range, such as ip4:203.0.113.0/24. |
a / mx |
Allow the IPs of the domain’s A or MX records. |
include: |
Allow everything another domain’s SPF record allows. Used for email services, such as include:_spf.emailit.com. |
exists: |
Allow if a constructed hostname resolves. Rarely needed. |
redirect= |
Use another domain’s SPF record instead of this one. |
-all |
Fail everything not listed (hard fail). |
~all |
Soft fail everything not listed. Receivers treat it as suspicious, and DMARC decides the outcome. |
?all |
Neutral, no opinion. |
+all |
Allow everyone. Never use it. |
DKIM
A DKIM record publishes the public key that receivers use to verify the DKIM-Signature header. It lives at selector._domainkey.domain, where the selector comes from the signature’s s= tag. Emailit signs with a 2048-bit RSA key and the selector emailit.
| Tag | Meaning | Emailit’s record |
|---|---|---|
v |
Version, DKIM1. |
v=DKIM1 |
k |
Key type, rsa (default) or ed25519. |
Omitted, so RSA. |
p |
The public key, base64-encoded. An empty p= revokes the key. |
Your domain’s key. |
t |
Flags: y means testing, s means the signing identity can’t be a subdomain of d=. |
t=s |
h |
Hash algorithms the key may be used with. | h=sha256 |
s |
Service type, email or *. |
Omitted. |
Emailit verifies DKIM by comparing the v, k and p values, so extra whitespace, quoting and tag order don’t matter. Each selector is independent, so Emailit’s emailit selector doesn’t conflict with keys from other services on the same domain.
DMARC
A DMARC record tells receivers what to do when a message fails both SPF and DKIM alignment, and where to send reports. It lives at _dmarc.domain.
v=DMARC1; p=quarantine; rua=mailto:dmarc@acme.com; adkim=r; aspf=r; pct=100| Tag | Meaning | Default |
|---|---|---|
v |
Version, DMARC1. Must come first. |
Required |
p |
Policy for the domain: none (monitor only), quarantine (send to spam) or reject. |
Required |
sp |
Policy for subdomains. | Same as p |
rua |
Where to send aggregate reports, as mailto: URIs separated by commas. |
None |
ruf |
Where to send forensic (failure) reports. | None |
pct |
Percentage of failing mail the policy applies to. | 100 |
adkim |
DKIM alignment: r (relaxed, subdomains match) or s (strict, exact match). |
r |
aspf |
SPF alignment: r or s. |
r |
fo |
When to send forensic reports: 0 (all checks fail), 1 (any check fails), d (DKIM fails) or s (SPF fails). |
0 |
ri |
Requested interval between aggregate reports, in seconds. | 86400 |
Emailit mail passes DMARC with relaxed alignment on both checks: DKIM signs with d=acme.com, and the envelope sender emailit.acme.com is a subdomain of acme.com. Emailit marks the DMARC record as valid when it has a p= policy of none, quarantine or reject. Start with p=none, read your DMARC reports, then move to quarantine and reject once every service that sends as your domain passes.
CNAME
A CNAME record makes one hostname an alias of another. Emailit uses one for your tracking domain.
go.acme.com. 3600 IN CNAME go.emailitmail.com.- A name with a CNAME can’t have any other record, and you can’t put a CNAME on the root domain.
- In Cloudflare, set the tracking record to DNS only. A proxied record hides the CNAME, so verification fails.
PTR
A PTR record maps an IP address back to a hostname (reverse DNS). Receivers check that a sending IP has one and that it resolves forward to the same IP. PTR records belong to whoever owns the IP, so Emailit manages them for its sending IPs and you don’t publish one.
BIMI
BIMI shows your logo next to authenticated mail in supporting inboxes. It’s a TXT record at default._bimi.domain:
v=BIMI1; l=https://acme.com/brand/logo.svg; a=https://acme.com/brand/vmc.pem| Tag | Meaning |
|---|---|
v |
Version, BIMI1. |
l |
HTTPS URL of the logo, an SVG in the Tiny Portable/Secure profile. |
a |
HTTPS URL of a Verified Mark Certificate or Common Mark Certificate, which Gmail and Apple Mail require. |
BIMI works only when the domain’s DMARC policy is quarantine or reject, with pct=100.
MTA-STS and TLS-RPT
MTA-STS and TLS-RPT protect mail sent to your domain, so they matter for domains that receive mail, such as your mailboxes or an inbound subdomain. They don’t affect mail you send through Emailit.
MTA-STS tells sending servers to require valid TLS when they deliver to your MX hosts. It needs a TXT record and a policy file served over HTTPS:
_mta-sts.acme.com. IN TXT "v=STSv1; id=20261001"version: STSv1
mode: enforce
mx: mx1.mailprovider.example
max_age: 604800TLS-RPT asks sending servers to send daily reports about TLS problems they hit when delivering to you:
_smtp._tls.acme.com. IN TXT "v=TLSRPTv1; rua=mailto:tls-reports@acme.com"TTL
Every record has a TTL (time to live): how many seconds resolvers may cache it. Lower the TTL to 300 a day before you change a record, so the change takes effect quickly, and raise it again afterwards. DNS changes usually appear within minutes but can take up to 48 hours.