# Set up DNS with Cloudflare

> Create every DNS record for a sending domain in your Cloudflare zone in one step with a scoped API token, then re-sync or disconnect it later.

If your domain's DNS is hosted on Cloudflare, Emailit can create all of its DNS records for you. You paste a Cloudflare API token that's limited to the zone, and Emailit adds the records, then checks DNS right away. This guide shows how to create the token, run the setup, re-sync records and disconnect.

## Before you begin

- [Add the domain](/docs/domains/add-a-domain/) to Emailit.
- The domain's nameservers must be Cloudflare's. Emailit detects this automatically, including Cloudflare's Foundation DNS nameservers. For a subdomain such as `mail.acme.com`, the parent zone `acme.com` must be on Cloudflare.
- You need a Cloudflare account that can create API tokens for the zone.

When Emailit detects Cloudflare, the **DNS Setup** card on the domain page shows a banner titled **This domain uses Cloudflare DNS** with a **Set up with Cloudflare** button. If you don't see it, the domain's nameservers aren't Cloudflare's. Add the records manually as described in [DNS records](/docs/domains/dns-records/).

## Create a Cloudflare API token

The token only needs to read the zone and edit its DNS records.

1. **Open API tokens.** In Cloudflare, go to **My Profile > API Tokens** (`https://dash.cloudflare.com/profile/api-tokens`) and select **Create Token**.

2. **Start from the Edit zone DNS template.** It grants **Zone > DNS > Edit**.

3. **Add Zone Read.** Add a second permission, **Zone > Zone > Read**. Emailit needs it to find the zone.

4. **Limit it to your zone.** Under **Zone Resources**, select **Include > Specific zone** and pick the zone, for example `acme.com`.

5. **Create and copy the token.** Cloudflare shows the token once. Keep the page open until you've pasted it into Emailit.

## Create the records

1. **Open the domain.** In **Email API → Domains**, select the domain and stay on the **DNS Setup** tab.

2. **Select Set up with Cloudflare.** The **Set up DNS with Cloudflare** dialog opens and shows the zone and its nameservers.

3. **Paste the token.** Paste it into **Cloudflare API token**. Emailit stores it encrypted and never shows it again.

4. **Choose the optional records.** Under **Records to create**, the return path, SPF and DKIM records are always included. DMARC, tracking and inbound are selected by default. Clear any you don't want.

5. **Select Create records.** Emailit creates the records, then runs **Check DNS** for you.

The dialog then lists each record with what happened to it:

| Result | Meaning |
| --- | --- |
| **Created** | The record didn't exist and was added. |
| **Updated** | A record with the same name and type existed with a different value. Emailit replaced its value. |
| **Already set** | An identical record already existed. Nothing changed. |
| **Kept existing** | A DMARC record already existed. Emailit never changes an existing DMARC record. |
| **Failed** | Cloudflare rejected this record. The message from Cloudflare is shown under it. The other records are still applied. |

If every required record passes, the dialog says **The domain is verified.** Otherwise, wait a few minutes and select **Check DNS** on the domain page.

> **Existing records with the same name are replaced:** If the zone already has a record with the same name and type, for example an MX record at `inbound.acme.com`, Emailit overwrites its value. Clear the **Inbound** or **Tracking** checkbox if those hosts are already in use for something else. Your root records, such as the MX and SPF on `acme.com`, are never touched.

### How the records are created

- **TTL** is set to Auto.
- **The tracking CNAME is DNS only** (not proxied), which tracking requires.
- **Each record gets a comment** in Cloudflare so you can tell it was created by Emailit.
- **DMARC** is only created when the zone has no `_dmarc` record. To add Emailit's reporting address to an existing record, edit it yourself. See [Set up DMARC reports](/docs/dmarc/set-up/).

## Sync records later

After the first setup, the banner changes to **Connected to Cloudflare** and shows when you last ran the setup. Emailit doesn't watch the zone or change it on its own. Select **Sync records** to apply the records again with the stored token, for example after you:

- change the tracking subdomain under **Custom Subdomains**, or
- turn on DMARC reports for the domain, or
- deleted one of the records by mistake.

If the last run didn't finish cleanly, the banner shows the error. Fix the cause, then select **Sync records** again.

## Disconnect Cloudflare

Select **Disconnect** on the banner and confirm. Emailit deletes the stored API token. The DNS records it created stay in your Cloudflare zone, so the domain keeps working. You can also revoke the token in Cloudflare at any time.

Deleting the domain from Emailit also deletes the stored token.

## Troubleshooting

| Error | Cause and fix |
| --- | --- |
| `Cloudflare rejected the API token. Check that it was copied fully and is still active.` | The token is incomplete, expired or revoked. Create a new one and paste it again. |
| `No Cloudflare zone for acme.com is visible to this token.` | The token doesn't include the zone or lacks **Zone > Zone > Read**. Edit the token's permissions and zone resources. |
| `Cloudflare API error: …` with an authentication message | The token lacks **Zone > DNS > Edit**. Nothing was created. Fix the permissions and try again. |
| A record shows **Failed** | Cloudflare refused that record, often because a CNAME exists at the same host. Remove the conflicting record in Cloudflare, then select **Sync records**. |
| Tracking still shows **Invalid** | Someone switched the CNAME to **Proxied**. Set it back to **DNS only** and select **Check DNS**. |

## Related

  - [DNS records](/docs/domains/dns-records/): What each record does.
  - [Domain verification](/docs/domains/verification/): Statuses and daily re-checks.

---
Source: https://emailit.com/docs/domains/cloudflare/
