# Sending domains

> Why Emailit needs your own domain, which DNS records it sets up for authentication, tracking and inbound mail, and how domains stay verified.

Every email you send through Emailit comes from a sending domain that you own and have verified with DNS records. This page explains what Emailit sets up on that domain, how verification works and how many domains your plan includes.

## Why you need a sending domain

Mailbox providers such as Gmail, Outlook and Yahoo only trust mail that proves it comes from the domain in the `From` address. Emailit proves that with SPF and DKIM records on your domain, so your messages are authenticated as yours and build your domain's reputation, not a shared one.

Until a domain is verified, Emailit rejects messages from it. The API returns `422 Domain not verified` and SMTP replies `530 From/Sender domain is not verified for this workspace`. Every `From` address must use a verified domain in the same workspace, and each subdomain counts as its own domain.

## What Emailit configures

When you add a domain, Emailit generates a 2048-bit DKIM key and gives you up to six DNS records. Three are required; the rest switch on optional features.

| Record | Host | Purpose | Required |
| --- | --- | --- | --- |
| MX | `emailit.<domain>` | Return path. Receives bounces and delivery reports for your mail. | Yes |
| TXT (SPF) | `emailit.<domain>` | Authorizes Emailit's servers to send for the return-path subdomain. | Yes |
| TXT (DKIM) | `emailit._domainkey.<domain>` | Public key that verifies the DKIM signature on every message. | Yes |
| TXT (DMARC) | `_dmarc.<domain>` | Tells receivers what to do with mail that fails authentication. | No |
| CNAME | `go.<domain>` | Custom tracking domain for open and click tracking. | No |
| MX | `inbound.<domain>` | Receives inbound email at any address on `inbound.<domain>`. | No |

The SPF record lives on the return-path subdomain, not on your root domain, so you don't need to change an existing SPF record for Google Workspace, Microsoft 365 or another provider. See [DNS records](/docs/domains/dns-records/) for every value and why it's set up this way.

## How it works

1. **You add the domain** in the dashboard or with the API. Emailit creates the DNS records for it.
2. **You publish the records** at your DNS provider, or let Emailit create them in [Cloudflare](/docs/domains/cloudflare/).
3. **You run Check DNS.** Emailit looks up the records. When SPF, DKIM and the return path all pass, the domain is verified.
4. **You send.** Emailit signs every message with your DKIM key and uses `emailit.<domain>` as the return path, so SPF and DKIM both align with your `From` domain for DMARC.
5. **Emailit re-checks DNS every day.** If a required record breaks, the domain stops sending and the workspace owner receives an email titled "Sending domain `<domain>` is no longer verified".

## Domain statuses

| Status | Meaning |
| --- | --- |
| **Verified** | SPF, DKIM and the return path pass. You can send from the domain. |
| **Not verified** | One or more required records are missing or invalid, or you haven't run Check DNS yet. |
| **Pending verification** | DNS may be correct, but the domain is waiting for a manual review. This applies to domains registered less than 30 days ago on Pay as you go. |
| **Sending paused** | The domain's bounce rate is too high. A banner shows on the domain page. See [Sending health](/docs/deliverability/sending-health/). |

[Domain verification](/docs/domains/verification/) explains each status, the per-record checks and how to fix common failures.

## Limits

| | Pay as you go | Pro | Business | Custom |
| --- | --- | --- | --- | --- |
| Sending domains | 3 (25 after your first credit purchase) | 100 | 1,000 | By agreement |
| Review of domains under 30 days old | Yes | No | No | Yes |

AppSumo licenses set their own domain allowance. See [Domain limits](/docs/domains/limits/).

## Root domain or subdomain?

You can verify a root domain such as `acme.com` or a subdomain such as `mail.acme.com`. Both work. Pick based on how you send:

- **Use a subdomain for each type of mail** if you send both transactional and marketing email, for example `notify.acme.com` for receipts and password resets, and `news.acme.com` for campaigns. Each subdomain builds its own reputation, so a campaign that draws complaints doesn't hurt your receipts.
- **Use the root domain** if you only send a modest amount of transactional mail and want your `From` address to be `hello@acme.com`.
- **Send from exactly the domain you verified.** Verifying `acme.com` doesn't let you send from `mail.acme.com`, and the other way around.

Your existing email keeps working either way: Emailit's records sit on their own hosts (`emailit.`, `emailit._domainkey.`, `go.` and `inbound.`), so they don't replace your root MX or SPF records.

## Get started

  - [Add a domain](/docs/domains/add-a-domain/): Add your domain and publish its DNS records.
  - [DNS records](/docs/domains/dns-records/): Every record, its value and how to enter it.
  - [Set up with Cloudflare](/docs/domains/cloudflare/): Create all records in your Cloudflare zone in one step.
  - [Domain verification](/docs/domains/verification/): Statuses, daily re-checks and troubleshooting.

---
Source: https://emailit.com/docs/domains/
