How-to
Set up DNS with Cloudflare
Create every DNS record for a sending domain in your Cloudflare zone in one step with a scoped API token, then re-sync or disconnect it later.
If your domain’s DNS is hosted on Cloudflare, Emailit can create all of its DNS records for you. You paste a Cloudflare API token that’s limited to the zone, and Emailit adds the records, then checks DNS right away. This guide shows how to create the token, run the setup, re-sync records and disconnect.
Before you begin
- Add the domain to Emailit.
- The domain’s nameservers must be Cloudflare’s. Emailit detects this automatically, including Cloudflare’s Foundation DNS nameservers. For a subdomain such as
mail.acme.com, the parent zoneacme.commust be on Cloudflare. - You need a Cloudflare account that can create API tokens for the zone.
When Emailit detects Cloudflare, the DNS Setup card on the domain page shows a banner titled This domain uses Cloudflare DNS with a Set up with Cloudflare button. If you don’t see it, the domain’s nameservers aren’t Cloudflare’s. Add the records manually as described in DNS records.
Create a Cloudflare API token
The token only needs to read the zone and edit its DNS records.
-
Open API tokens. In Cloudflare, go to My Profile > API Tokens (
https://dash.cloudflare.com/profile/api-tokens) and select Create Token. -
Start from the Edit zone DNS template. It grants Zone > DNS > Edit.
-
Add Zone Read. Add a second permission, Zone > Zone > Read. Emailit needs it to find the zone.
-
Limit it to your zone. Under Zone Resources, select Include > Specific zone and pick the zone, for example
acme.com. -
Create and copy the token. Cloudflare shows the token once. Keep the page open until you’ve pasted it into Emailit.
Create the records
-
Open the domain. In Email APIDomains, select the domain and stay on the DNS Setup tab.
-
Select Set up with Cloudflare. The Set up DNS with Cloudflare dialog opens and shows the zone and its nameservers.
-
Paste the token. Paste it into Cloudflare API token. Emailit stores it encrypted and never shows it again.
-
Choose the optional records. Under Records to create, the return path, SPF and DKIM records are always included. DMARC, tracking and inbound are selected by default. Clear any you don’t want.
-
Select Create records. Emailit creates the records, then runs Check DNS for you.
The dialog then lists each record with what happened to it:
| Result | Meaning |
|---|---|
| Created | The record didn’t exist and was added. |
| Updated | A record with the same name and type existed with a different value. Emailit replaced its value. |
| Already set | An identical record already existed. Nothing changed. |
| Kept existing | A DMARC record already existed. Emailit never changes an existing DMARC record. |
| Failed | Cloudflare rejected this record. The message from Cloudflare is shown under it. The other records are still applied. |
If every required record passes, the dialog says The domain is verified. Otherwise, wait a few minutes and select Check DNS on the domain page.
How the records are created
- TTL is set to Auto.
- The tracking CNAME is DNS only (not proxied), which tracking requires.
- Each record gets a comment in Cloudflare so you can tell it was created by Emailit.
- DMARC is only created when the zone has no
_dmarcrecord. To add Emailit’s reporting address to an existing record, edit it yourself. See Set up DMARC reports.
Sync records later
After the first setup, the banner changes to Connected to Cloudflare and shows when you last ran the setup. Emailit doesn’t watch the zone or change it on its own. Select Sync records to apply the records again with the stored token, for example after you:
- change the tracking subdomain under Custom Subdomains, or
- turn on DMARC reports for the domain, or
- deleted one of the records by mistake.
If the last run didn’t finish cleanly, the banner shows the error. Fix the cause, then select Sync records again.
Disconnect Cloudflare
Select Disconnect on the banner and confirm. Emailit deletes the stored API token. The DNS records it created stay in your Cloudflare zone, so the domain keeps working. You can also revoke the token in Cloudflare at any time.
Deleting the domain from Emailit also deletes the stored token.
Troubleshooting
| Error | Cause and fix |
|---|---|
Cloudflare rejected the API token. Check that it was copied fully and is still active. |
The token is incomplete, expired or revoked. Create a new one and paste it again. |
No Cloudflare zone for acme.com is visible to this token. |
The token doesn’t include the zone or lacks Zone > Zone > Read. Edit the token’s permissions and zone resources. |
Cloudflare API error: … with an authentication message |
The token lacks Zone > DNS > Edit. Nothing was created. Fix the permissions and try again. |
| A record shows Failed | Cloudflare refused that record, often because a CNAME exists at the same host. Remove the conflicting record in Cloudflare, then select Sync records. |
| Tracking still shows Invalid | Someone switched the CNAME to Proxied. Set it back to DNS only and select Check DNS. |