# Domain verification

> How Emailit verifies sending domains, what each domain and record status means, how manual review and daily re-checks work, and how to fix failures.

A sending domain must be verified before Emailit sends mail from it. This page explains what Emailit checks, what each status means, how the review for new Pay as you go domains works and how to fix a domain that won't verify.

## What Emailit checks

Verification looks at three DNS records. All three must pass:

| Check | Record | Passes when |
| --- | --- | --- |
| **SPF** | TXT at `emailit.<domain>` | A `v=spf1` record includes `_spf.emailit.com`. |
| **DKIM** | TXT at `emailit._domainkey.<domain>` | The record's `p=` key matches the domain's DKIM key. |
| **Return Path** | MX at `emailit.<domain>` | There's exactly one MX record and it points to `feedback-smtp.ffdc-1.emailit.com`. |

Emailit also checks DMARC, the tracking CNAME and the inbound MX record at the same time and shows their status, but they don't affect verification. See [DNS records](/docs/domains/dns-records/) for every value.

On Pay as you go, Emailit also checks the domain's age. See [Pending verification](#pending-verification).

## Domain statuses

The **Verification** column in **Email API → Domains** and the API field `verification_status` show one of three states.

| Dashboard | API value | Meaning | Can send? |
| --- | --- | --- | --- |
| **Verified** | `verified` | SPF, DKIM and the return path pass. | Yes |
| **Not verified** | `pending` | A required record is missing or invalid, or DNS hasn't been checked yet. | No |
| **Pending verification** | `pending_review` | The domain is waiting for a manual review by Emailit. | No |

The API also returns `verified_at` (when the domain last passed), `dns_checked_at` (when DNS was last checked) and `manual_review_required`.

## Record statuses

Each record on the domain page, and each item in the API's `dns_records` array, has its own status.

| Dashboard | API value | Meaning |
| --- | --- | --- |
| **OK** | `ok` | The record is published with the expected value. |
| **Missing** | `missing` | Emailit found no matching record at that host. |
| **Invalid** | `invalid` | A record exists, but its value is wrong, for example an MX pointing elsewhere or a DKIM key that doesn't match. |
| **Not checked** | `pending` | DNS hasn't been checked since the record was created or its host changed. |

DMARC can also return `error` when the lookup itself fails, which the dashboard shows as **Not checked**. Hover over **Missing** or **Invalid** in the dashboard, or read the record's `error` field in the API, to see exactly what Emailit found.

## What verification unlocks

- **Sending.** You can send from any address on the domain through the API, SMTP, campaigns and automations.
- **Inbound email.** Emailit only accepts mail for `inbound.<domain>` on verified domains.
- **Production access.** You need at least one verified domain before you can [request production access](/docs/workspaces/production-access/).
- **Tracking,** once the tracking CNAME also shows **OK**. See [Open and click tracking](/docs/tracking/).

## Run a check

Verification runs when you ask for it:

- In the dashboard, select **Check DNS** on the domain page.
- With the API, call [Verify a domain](/docs/api-reference/domains/verify/).
- [Cloudflare setup](/docs/domains/cloudflare/) runs the check for you after it creates the records.

Emailit doesn't verify a new domain on its own, so run a check after you publish or fix records.

## Pending verification

On Pay as you go, a domain that was registered less than 30 days ago needs a manual review before it can send. Emailit reads the registration date of the domain from WHOIS. For a subdomain such as `mail.acme.com`, it uses the registration date of `acme.com`. If WHOIS doesn't return a date, the domain isn't held for review.

While a domain waits for review:

- It shows **Pending verification**, and the domain page shows a banner explaining why.
- It can't send, even when all records show **OK**.
- You don't need to do anything else. Keep the DNS records in place so the domain verifies as soon as it's approved.

Pro and Business workspaces skip the age check. If you upgrade while a domain is pending, select **Check DNS** and it verifies as soon as DNS passes.

| | Pay as you go | Pro | Business | Custom |
| --- | --- | --- | --- | --- |
| Review of domains under 30 days old | Yes | No | No | Yes |

### Approval is permanent

Once Emailit approves a domain, the approval stays. If DNS breaks later, the domain shows **Not verified** and stops sending until you fix the records, but it doesn't go back into review. Running **Check DNS** never removes an approval.

## Daily re-check

Emailit re-checks the DNS of every domain once a day and updates each record's status and **Last checked** time.

- **If a verified domain fails,** Emailit marks it **Not verified** and emails the workspace owner: "Sending domain `<domain>` is no longer verified". The email lists the SPF, DKIM and return path results. Mail from the domain doesn't send until it passes again.
- **If only the DNS lookups time out,** Emailit treats it as a temporary resolver problem and keeps the domain verified.
- **If a domain that Emailit approved after review passes again,** the daily check restores it to **Verified**.

For any other domain that lost verification, fix the records and select **Check DNS** to bring it back. The daily check doesn't verify those domains on its own.

## Paused domains

A verified domain can still be paused when its bounce rate is too high. The domain page shows a **Sending paused** banner, the API returns `restricted: true`, and:

- the API rejects sends from the domain with `403 Domain paused`,
- SMTP replies `550 Sending from this domain is paused`,
- queued mail from the domain gets the status `held`.

Pausing is part of [sending health](/docs/deliverability/sending-health/), not DNS. Contact support to restore a paused domain after you've fixed the cause.

## Troubleshooting

| Symptom | Likely cause | Fix |
| --- | --- | --- |
| SPF, DKIM or Return Path is **Missing** | The record is at the wrong host, often with the domain added twice, such as `emailit.acme.com.acme.com`. | Enter only the relative host (`emailit`, `emailit._domainkey`). Check with `dig`. See [DNS records](/docs/domains/dns-records/#check-records-with-dig). |
| Everything is **OK** but the domain isn't verified | The records were published after the last check. | Select **Check DNS**. |
| **Pending verification** stays for days | The domain was registered less than 30 days ago and is waiting for review. | Contact support if it's urgent, or upgrade to Pro or Business and run **Check DNS**. |
| SPF is **Invalid** | The record at `emailit.<domain>` doesn't include `_spf.emailit.com`. | Use the exact value `v=spf1 include:_spf.emailit.com ~all`. |
| DKIM is **Invalid** | The key was cut off, or it's from a domain you deleted and added again. Each new domain gets a new key. | Copy the current value from the domain page. |
| Return Path is **Invalid** | There's a second MX record on `emailit.<domain>`, or it points elsewhere. | Keep one MX record pointing to `feedback-smtp.ffdc-1.emailit.com`. |
| The domain was verified and suddenly isn't | Someone removed or changed a record, or the domain moved to a new DNS provider without the records. | Check the "no longer verified" email for which record failed, restore it and select **Check DNS**. |
| Sending fails with `422 Domain not verified` | The `From` address uses a different domain or subdomain than the verified one. | Send from the exact verified domain, or add and verify the subdomain. |

## Related

  - [Add a domain](/docs/domains/add-a-domain/): Add a domain and publish its records.
  - [Domain limits](/docs/domains/limits/): How many domains your plan includes.
  - [Sending health](/docs/deliverability/sending-health/): Bounce rates, scores and paused domains.
  - [Domains API](/docs/api-reference/domains/): Create, verify and update domains.

---
Source: https://emailit.com/docs/domains/verification/
