Skip to content
Docs

Reference

DNS records for sending domains

Every DNS record Emailit generates for a sending domain, what each one does, how to enter it at your DNS provider and how to check it with dig.

Updated Oct 1, 2026

This page lists every DNS record Emailit generates for a sending domain and explains why each one exists. Use it while you publish records, or when a record shows Missing or Invalid on the domain page.

All records

The examples use acme.com. Replace it with your sending domain. If you send from a subdomain such as mail.acme.com, every host below moves under it, for example emailit.mail.acme.com.

Purpose Type Host Value Priority Required
Return path MX emailit.acme.com feedback-smtp.ffdc-1.emailit.com 10 Yes
SPF TXT emailit.acme.com v=spf1 include:_spf.emailit.com ~all – Yes
DKIM TXT emailit._domainkey.acme.com v=DKIM1; t=s; h=sha256; p=MIIBIjANBgkqh… (your public key) – Yes
DMARC TXT _dmarc.acme.com v=DMARC1; p=none; – No
Tracking CNAME go.acme.com go.emailitmail.com – No
Inbound MX inbound.acme.com inbound.emailitmail.com 10 No

The DKIM key is unique to each domain, so always copy it from the domain page or from the dns_records array of Retrieve a domain. The tracking and inbound hosts change if you set a custom tracking_key or inbound_key. When DMARC reports are on, the suggested DMARC value also includes your reporting address.

A domain is verified when the return path, SPF and DKIM records all pass. The other three records turn on optional features and never block verification.

Return path (MX)

Text
emailit.acme.com.   MX   10 feedback-smtp.ffdc-1.emailit.com.

Every message Emailit sends uses an envelope sender (return path) on this subdomain, in the form <workspace_id>@emailit.acme.com. Receiving servers send bounces and delivery reports to that address. The MX record routes them back to Emailit, which matches them to the original message and updates its status.

The check passes when emailit.acme.com has exactly one MX record and it points to feedback-smtp.ffdc-1.emailit.com. A second MX record on the same host makes it Invalid.

SPF (TXT on the return-path subdomain)

Text
emailit.acme.com.   TXT   "v=spf1 include:_spf.emailit.com ~all"

SPF tells receivers which servers may send mail for a domain. Receivers check SPF against the return-path domain, not the From address. Because Emailit’s return path is emailit.acme.com, that’s the host that needs the SPF record.

This setup has two benefits:

  • You don’t touch your root SPF record. Your existing acme.com SPF record for Google Workspace, Microsoft 365 or other services stays as it is. Adding include:_spf.emailit.com to the root record isn’t needed and only uses up one of SPF’s 10 DNS lookups.
  • SPF still aligns for DMARC. DMARC’s default relaxed alignment accepts a return path on a subdomain of the From domain. Mail from hello@acme.com with return path emailit.acme.com passes SPF alignment.

The check passes when a TXT record starting with v=spf1 at emailit.acme.com includes _spf.emailit.com. Publish only one SPF record per host; two SPF records on the same host make SPF fail at receivers.

DKIM (TXT)

Text
emailit._domainkey.acme.com.   TXT   "v=DKIM1; t=s; h=sha256; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA…"

Emailit signs every message with a 2048-bit RSA key using the selector emailit and d=acme.com. Receivers fetch the public key from this record to check the signature. A valid signature proves the message came from you and wasn’t changed in transit, and because the signing domain matches your From domain, DKIM aligns for DMARC.

The value is about 420 characters long, which is longer than the 255-character limit of a single TXT string. Most DNS providers split it for you. If yours asks you to do it, split the value into quoted chunks in one record: "v=DKIM1; t=s; h=sha256; p=MIIB…" "…IDAQAB;". Emailit joins the chunks before it checks the key.

The check compares the DKIM tags, not the exact text, so extra spaces or a different tag order are fine. It fails if the p= key doesn’t match.

DMARC (TXT, optional)

Text
_dmarc.acme.com.   TXT   "v=DMARC1; p=none;"

DMARC tells receivers what to do with mail that claims to be from your domain but fails SPF and DKIM alignment, and where to send reports about it. Gmail and Yahoo require a DMARC record from bulk senders, so publish one even though Emailit doesn’t need it for verification.

  • Start with p=none. It changes nothing about delivery and lets you collect reports first.
  • Move to p=quarantine, then p=reject, once reports show that all legitimate mail passes. See Read DMARC reports for a safe rollout.
  • Keep one DMARC record. If _dmarc.acme.com already exists, don’t add a second one. Edit the existing record instead.

With DMARC reports on, the suggested value adds rua and ruf addresses at dmarc.emailitmail.com. Set up DMARC reports shows how to merge them into an existing record.

Emailit only looks at _dmarc on the exact sending domain. If you send from mail.acme.com and rely on the policy published at _dmarc.acme.com, receivers apply the parent policy, but the DMARC row on the domain page won’t show OK.

Tracking (CNAME, optional)

Text
go.acme.com.   CNAME   go.emailitmail.com.

Open and click tracking uses a hostname on your own domain. Emailit rewrites links to https://go.acme.com/<token> and loads the open pixel from the same host. Without a verified CNAME, mail is sent untracked. See Custom tracking domain.

The CNAME must point straight at go.emailitmail.com. If your DNS provider proxies records (Cloudflare’s orange cloud), set this record to DNS only.

Inbound (MX, optional)

Text
inbound.acme.com.   MX   10 inbound.emailitmail.com.

With this record, Emailit accepts mail for any address at inbound.acme.com, such as support@inbound.acme.com, and delivers it to your workspace as an inbound email. The check requires priority 10. Inbound mail only works for verified domains. See Set up inbound email.

Enter hosts at your DNS provider

DNS providers name the host field differently, and most of them add your domain to whatever you type. Enter the relative name (the part before your domain) unless your provider asks for the full name.

Record Relative host (most providers) Full name (FQDN)
Return path and SPF emailit emailit.acme.com
DKIM emailit._domainkey emailit._domainkey.acme.com
DMARC _dmarc _dmarc.acme.com
Tracking go go.acme.com
Inbound inbound inbound.acme.com

For a subdomain such as mail.acme.com hosted in the acme.com zone, the relative host includes the subdomain: emailit.mail, emailit._domainkey.mail, _dmarc.mail, go.mail and inbound.mail.

Provider Host field Notes
Cloudflare Name Accepts the relative or full name. Set the tracking CNAME to DNS only. Or use one-click setup.
GoDaddy Name Relative name only. Typing the full name creates emailit.acme.com.acme.com.
Namecheap Host Relative name only. MX records go in the Mail Settings section, set to Custom MX.
Amazon Route 53 Record name Relative name; the console shows the zone after the field. Enter MX values as 10 feedback-smtp.ffdc-1.emailit.com. Wrap TXT values in double quotes and split the DKIM value into quoted chunks.
DigitalOcean Hostname Relative name.

TTL

Emailit shows the TTL as auto. Use your provider’s default or automatic TTL. A short TTL such as 300 seconds helps while you set things up, because corrections reach resolvers faster. TTL doesn’t affect verification.

Check records with dig

Query a record directly to see what the rest of the internet sees. These commands use the public resolver 1.1.1.1 so a cached answer from your network doesn’t mislead you.

Terminal
dig +short MX emailit.acme.com @1.1.1.1
dig +short TXT emailit.acme.com @1.1.1.1
dig +short TXT emailit._domainkey.acme.com @1.1.1.1
dig +short TXT _dmarc.acme.com @1.1.1.1
dig +short CNAME go.acme.com @1.1.1.1
dig +short MX inbound.acme.com @1.1.1.1

Expected answers:

Text
10 feedback-smtp.ffdc-1.emailit.com.
"v=spf1 include:_spf.emailit.com ~all"
"v=DKIM1; t=s; h=sha256; p=MIIBIjANBgkqh…" "…IDAQAB;"
"v=DMARC1; p=none;"
go.emailitmail.com.
10 inbound.emailitmail.com.

An empty answer means the record isn’t published at that name yet. On Windows, use nslookup -type=TXT emailit.acme.com 1.1.1.1.

Common mistakes

Mistake Symptom Fix
Domain added twice to the host Missing. The record exists at emailit.acme.com.acme.com. Enter only the relative host, such as emailit.
Tracking CNAME proxied Tracking shows Invalid. The host returns Cloudflare IP addresses instead of a CNAME. Switch the record to DNS only (grey cloud).
Emailit’s SPF added to the root record only SPF shows Missing. Add the SPF record at emailit.acme.com. You don’t need it on the root domain.
Two SPF records on emailit.acme.com Emailit may show OK, but receivers see an SPF error. Keep a single v=spf1 record on that host.
Trailing dot handled differently Value becomes go.emailitmail.com.acme.com. Some providers treat a value without a trailing dot as relative. Enter go.emailitmail.com. with a trailing dot, or follow the provider’s example.
DKIM value cut off DKIM shows Invalid. Copy the whole value with the copy button. Split it into quoted chunks if the provider limits length.
Extra MX on the return-path host Return path shows Invalid. Keep exactly one MX record on emailit.acme.com.
Inbound MX with another priority Inbound shows Invalid. Set the priority to 10.
Second DMARC record added Receivers ignore DMARC for the domain. Merge everything into one _dmarc record.
Step-by-step setup.
Statuses and troubleshooting.
Background on MX, TXT, CNAME and more.
Authentication, DMARC alignment and list hygiene.

Was this page helpful?

Thanks for the feedback.

Thanks, we read every message.