# DNS records for sending domains

> Every DNS record Emailit generates for a sending domain, what each one does, how to enter it at your DNS provider and how to check it with dig.

This page lists every DNS record Emailit generates for a sending domain and explains why each one exists. Use it while you publish records, or when a record shows **Missing** or **Invalid** on the domain page.

## All records

The examples use `acme.com`. Replace it with your sending domain. If you send from a subdomain such as `mail.acme.com`, every host below moves under it, for example `emailit.mail.acme.com`.

| Purpose | Type | Host | Value | Priority | Required |
| --- | --- | --- | --- | --- | --- |
| Return path | MX | `emailit.acme.com` | `feedback-smtp.ffdc-1.emailit.com` | 10 | Yes |
| SPF | TXT | `emailit.acme.com` | `v=spf1 include:_spf.emailit.com ~all` | – | Yes |
| DKIM | TXT | `emailit._domainkey.acme.com` | `v=DKIM1; t=s; h=sha256; p=MIIBIjANBgkqh…` (your public key) | – | Yes |
| DMARC | TXT | `_dmarc.acme.com` | `v=DMARC1; p=none;` | – | No |
| Tracking | CNAME | `go.acme.com` | `go.emailitmail.com` | – | No |
| Inbound | MX | `inbound.acme.com` | `inbound.emailitmail.com` | 10 | No |

The DKIM key is unique to each domain, so always copy it from the domain page or from the `dns_records` array of [Retrieve a domain](/docs/api-reference/domains/get/). The tracking and inbound hosts change if you set a custom `tracking_key` or `inbound_key`. When [DMARC reports](/docs/dmarc/) are on, the suggested DMARC value also includes your reporting address.

A domain is verified when the return path, SPF and DKIM records all pass. The other three records turn on optional features and never block verification.

## Return path (MX)

```txt
emailit.acme.com.   MX   10 feedback-smtp.ffdc-1.emailit.com.
```

Every message Emailit sends uses an envelope sender (return path) on this subdomain, in the form `<workspace_id>@emailit.acme.com`. Receiving servers send bounces and delivery reports to that address. The MX record routes them back to Emailit, which matches them to the original message and updates its status.

The check passes when `emailit.acme.com` has exactly one MX record and it points to `feedback-smtp.ffdc-1.emailit.com`. A second MX record on the same host makes it **Invalid**.

## SPF (TXT on the return-path subdomain)

```txt
emailit.acme.com.   TXT   "v=spf1 include:_spf.emailit.com ~all"
```

SPF tells receivers which servers may send mail for a domain. Receivers check SPF against the return-path domain, not the `From` address. Because Emailit's return path is `emailit.acme.com`, that's the host that needs the SPF record.

This setup has two benefits:

- **You don't touch your root SPF record.** Your existing `acme.com` SPF record for Google Workspace, Microsoft 365 or other services stays as it is. Adding `include:_spf.emailit.com` to the root record isn't needed and only uses up one of SPF's 10 DNS lookups.
- **SPF still aligns for DMARC.** DMARC's default relaxed alignment accepts a return path on a subdomain of the `From` domain. Mail from `hello@acme.com` with return path `emailit.acme.com` passes SPF alignment.

The check passes when a TXT record starting with `v=spf1` at `emailit.acme.com` includes `_spf.emailit.com`. Publish only one SPF record per host; two SPF records on the same host make SPF fail at receivers.

## DKIM (TXT)

```txt
emailit._domainkey.acme.com.   TXT   "v=DKIM1; t=s; h=sha256; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA…"
```

Emailit signs every message with a 2048-bit RSA key using the selector `emailit` and `d=acme.com`. Receivers fetch the public key from this record to check the signature. A valid signature proves the message came from you and wasn't changed in transit, and because the signing domain matches your `From` domain, DKIM aligns for DMARC.

The value is about 420 characters long, which is longer than the 255-character limit of a single TXT string. Most DNS providers split it for you. If yours asks you to do it, split the value into quoted chunks in one record: `"v=DKIM1; t=s; h=sha256; p=MIIB…" "…IDAQAB;"`. Emailit joins the chunks before it checks the key.

The check compares the DKIM tags, not the exact text, so extra spaces or a different tag order are fine. It fails if the `p=` key doesn't match.

## DMARC (TXT, optional)

```txt
_dmarc.acme.com.   TXT   "v=DMARC1; p=none;"
```

DMARC tells receivers what to do with mail that claims to be from your domain but fails SPF and DKIM alignment, and where to send reports about it. Gmail and Yahoo require a DMARC record from bulk senders, so publish one even though Emailit doesn't need it for verification.

- **Start with `p=none`.** It changes nothing about delivery and lets you collect reports first.
- **Move to `p=quarantine`, then `p=reject`,** once reports show that all legitimate mail passes. See [Read DMARC reports](/docs/dmarc/reports/) for a safe rollout.
- **Keep one DMARC record.** If `_dmarc.acme.com` already exists, don't add a second one. Edit the existing record instead.

With [DMARC reports](/docs/dmarc/) on, the suggested value adds `rua` and `ruf` addresses at `dmarc.emailitmail.com`. [Set up DMARC reports](/docs/dmarc/set-up/) shows how to merge them into an existing record.

Emailit only looks at `_dmarc` on the exact sending domain. If you send from `mail.acme.com` and rely on the policy published at `_dmarc.acme.com`, receivers apply the parent policy, but the DMARC row on the domain page won't show **OK**.

## Tracking (CNAME, optional)

```txt
go.acme.com.   CNAME   go.emailitmail.com.
```

Open and click tracking uses a hostname on your own domain. Emailit rewrites links to `https://go.acme.com/<token>` and loads the open pixel from the same host. Without a verified CNAME, mail is sent untracked. See [Custom tracking domain](/docs/tracking/custom-tracking-domain/).

The CNAME must point straight at `go.emailitmail.com`. If your DNS provider proxies records (Cloudflare's orange cloud), set this record to **DNS only**.

## Inbound (MX, optional)

```txt
inbound.acme.com.   MX   10 inbound.emailitmail.com.
```

With this record, Emailit accepts mail for any address at `inbound.acme.com`, such as `support@inbound.acme.com`, and delivers it to your workspace as an inbound email. The check requires priority 10. Inbound mail only works for verified domains. See [Set up inbound email](/docs/inbound/set-up/).

## Enter hosts at your DNS provider

DNS providers name the host field differently, and most of them add your domain to whatever you type. Enter the **relative** name (the part before your domain) unless your provider asks for the full name.

| Record | Relative host (most providers) | Full name (FQDN) |
| --- | --- | --- |
| Return path and SPF | `emailit` | `emailit.acme.com` |
| DKIM | `emailit._domainkey` | `emailit._domainkey.acme.com` |
| DMARC | `_dmarc` | `_dmarc.acme.com` |
| Tracking | `go` | `go.acme.com` |
| Inbound | `inbound` | `inbound.acme.com` |

For a subdomain such as `mail.acme.com` hosted in the `acme.com` zone, the relative host includes the subdomain: `emailit.mail`, `emailit._domainkey.mail`, `_dmarc.mail`, `go.mail` and `inbound.mail`.

| Provider | Host field | Notes |
| --- | --- | --- |
| Cloudflare | **Name** | Accepts the relative or full name. Set the tracking CNAME to **DNS only**. Or use [one-click setup](/docs/domains/cloudflare/). |
| GoDaddy | **Name** | Relative name only. Typing the full name creates `emailit.acme.com.acme.com`. |
| Namecheap | **Host** | Relative name only. MX records go in the **Mail Settings** section, set to **Custom MX**. |
| Amazon Route 53 | **Record name** | Relative name; the console shows the zone after the field. Enter MX values as `10 feedback-smtp.ffdc-1.emailit.com`. Wrap TXT values in double quotes and split the DKIM value into quoted chunks. |
| DigitalOcean | **Hostname** | Relative name. |

## TTL

Emailit shows the TTL as `auto`. Use your provider's default or automatic TTL. A short TTL such as 300 seconds helps while you set things up, because corrections reach resolvers faster. TTL doesn't affect verification.

## Check records with dig

Query a record directly to see what the rest of the internet sees. These commands use the public resolver `1.1.1.1` so a cached answer from your network doesn't mislead you.

```bash
dig +short MX emailit.acme.com @1.1.1.1
dig +short TXT emailit.acme.com @1.1.1.1
dig +short TXT emailit._domainkey.acme.com @1.1.1.1
dig +short TXT _dmarc.acme.com @1.1.1.1
dig +short CNAME go.acme.com @1.1.1.1
dig +short MX inbound.acme.com @1.1.1.1
```

Expected answers:

```txt
10 feedback-smtp.ffdc-1.emailit.com.
"v=spf1 include:_spf.emailit.com ~all"
"v=DKIM1; t=s; h=sha256; p=MIIBIjANBgkqh…" "…IDAQAB;"
"v=DMARC1; p=none;"
go.emailitmail.com.
10 inbound.emailitmail.com.
```

An empty answer means the record isn't published at that name yet. On Windows, use `nslookup -type=TXT emailit.acme.com 1.1.1.1`.

## Common mistakes

| Mistake | Symptom | Fix |
| --- | --- | --- |
| Domain added twice to the host | **Missing**. The record exists at `emailit.acme.com.acme.com`. | Enter only the relative host, such as `emailit`. |
| Tracking CNAME proxied | Tracking shows **Invalid**. The host returns Cloudflare IP addresses instead of a CNAME. | Switch the record to **DNS only** (grey cloud). |
| Emailit's SPF added to the root record only | SPF shows **Missing**. | Add the SPF record at `emailit.acme.com`. You don't need it on the root domain. |
| Two SPF records on `emailit.acme.com` | Emailit may show **OK**, but receivers see an SPF error. | Keep a single `v=spf1` record on that host. |
| Trailing dot handled differently | Value becomes `go.emailitmail.com.acme.com`. | Some providers treat a value without a trailing dot as relative. Enter `go.emailitmail.com.` with a trailing dot, or follow the provider's example. |
| DKIM value cut off | DKIM shows **Invalid**. | Copy the whole value with the copy button. Split it into quoted chunks if the provider limits length. |
| Extra MX on the return-path host | Return path shows **Invalid**. | Keep exactly one MX record on `emailit.acme.com`. |
| Inbound MX with another priority | Inbound shows **Invalid**. | Set the priority to 10. |
| Second DMARC record added | Receivers ignore DMARC for the domain. | Merge everything into one `_dmarc` record. |

## Related

  - [Add a domain](/docs/domains/add-a-domain/): Step-by-step setup.
  - [Domain verification](/docs/domains/verification/): Statuses and troubleshooting.
  - [DNS record types](/docs/dictionary/dns-records/): Background on MX, TXT, CNAME and more.
  - [Email best practices](/docs/deliverability/best-practices/): Authentication, DMARC alignment and list hygiene.

---
Source: https://emailit.com/docs/domains/dns-records/
