Concept
Domain verification
How Emailit verifies sending domains, what each domain and record status means, how manual review and daily re-checks work, and how to fix failures.
A sending domain must be verified before Emailit sends mail from it. This page explains what Emailit checks, what each status means, how the review for new Pay as you go domains works and how to fix a domain that won’t verify.
What Emailit checks
Verification looks at three DNS records. All three must pass:
| Check | Record | Passes when |
|---|---|---|
| SPF | TXT at emailit.<domain> |
A v=spf1 record includes _spf.emailit.com. |
| DKIM | TXT at emailit._domainkey.<domain> |
The record’s p= key matches the domain’s DKIM key. |
| Return Path | MX at emailit.<domain> |
There’s exactly one MX record and it points to feedback-smtp.ffdc-1.emailit.com. |
Emailit also checks DMARC, the tracking CNAME and the inbound MX record at the same time and shows their status, but they don’t affect verification. See DNS records for every value.
On Pay as you go, Emailit also checks the domain’s age. See Pending verification.
Domain statuses
The Verification column in Email APIDomains and the API field verification_status show one of three states.
| Dashboard | API value | Meaning | Can send? |
|---|---|---|---|
| Verified | verified |
SPF, DKIM and the return path pass. | Yes |
| Not verified | pending |
A required record is missing or invalid, or DNS hasn’t been checked yet. | No |
| Pending verification | pending_review |
The domain is waiting for a manual review by Emailit. | No |
The API also returns verified_at (when the domain last passed), dns_checked_at (when DNS was last checked) and manual_review_required.
Record statuses
Each record on the domain page, and each item in the API’s dns_records array, has its own status.
| Dashboard | API value | Meaning |
|---|---|---|
| OK | ok |
The record is published with the expected value. |
| Missing | missing |
Emailit found no matching record at that host. |
| Invalid | invalid |
A record exists, but its value is wrong, for example an MX pointing elsewhere or a DKIM key that doesn’t match. |
| Not checked | pending |
DNS hasn’t been checked since the record was created or its host changed. |
DMARC can also return error when the lookup itself fails, which the dashboard shows as Not checked. Hover over Missing or Invalid in the dashboard, or read the record’s error field in the API, to see exactly what Emailit found.
What verification unlocks
- Sending. You can send from any address on the domain through the API, SMTP, campaigns and automations.
- Inbound email. Emailit only accepts mail for
inbound.<domain>on verified domains. - Production access. You need at least one verified domain before you can request production access.
- Tracking, once the tracking CNAME also shows OK. See Open and click tracking.
Run a check
Verification runs when you ask for it:
- In the dashboard, select Check DNS on the domain page.
- With the API, call Verify a domain.
- Cloudflare setup runs the check for you after it creates the records.
Emailit doesn’t verify a new domain on its own, so run a check after you publish or fix records.
Pending verification
On Pay as you go, a domain that was registered less than 30 days ago needs a manual review before it can send. Emailit reads the registration date of the domain from WHOIS. For a subdomain such as mail.acme.com, it uses the registration date of acme.com. If WHOIS doesn’t return a date, the domain isn’t held for review.
While a domain waits for review:
- It shows Pending verification, and the domain page shows a banner explaining why.
- It can’t send, even when all records show OK.
- You don’t need to do anything else. Keep the DNS records in place so the domain verifies as soon as it’s approved.
Pro and Business workspaces skip the age check. If you upgrade while a domain is pending, select Check DNS and it verifies as soon as DNS passes.
| Pay as you go | Pro | Business | Custom | |
|---|---|---|---|---|
| Review of domains under 30 days old | Yes | No | No | Yes |
Approval is permanent
Once Emailit approves a domain, the approval stays. If DNS breaks later, the domain shows Not verified and stops sending until you fix the records, but it doesn’t go back into review. Running Check DNS never removes an approval.
Daily re-check
Emailit re-checks the DNS of every domain once a day and updates each record’s status and Last checked time.
- If a verified domain fails, Emailit marks it Not verified and emails the workspace owner: “Sending domain
<domain>is no longer verified”. The email lists the SPF, DKIM and return path results. Mail from the domain doesn’t send until it passes again. - If only the DNS lookups time out, Emailit treats it as a temporary resolver problem and keeps the domain verified.
- If a domain that Emailit approved after review passes again, the daily check restores it to Verified.
For any other domain that lost verification, fix the records and select Check DNS to bring it back. The daily check doesn’t verify those domains on its own.
Paused domains
A verified domain can still be paused when its bounce rate is too high. The domain page shows a Sending paused banner, the API returns restricted: true, and:
- the API rejects sends from the domain with
403 Domain paused, - SMTP replies
550 Sending from this domain is paused, - queued mail from the domain gets the status
held.
Pausing is part of sending health, not DNS. Contact support to restore a paused domain after you’ve fixed the cause.
Troubleshooting
| Symptom | Likely cause | Fix |
|---|---|---|
| SPF, DKIM or Return Path is Missing | The record is at the wrong host, often with the domain added twice, such as emailit.acme.com.acme.com. |
Enter only the relative host (emailit, emailit._domainkey). Check with dig. See DNS records. |
| Everything is OK but the domain isn’t verified | The records were published after the last check. | Select Check DNS. |
| Pending verification stays for days | The domain was registered less than 30 days ago and is waiting for review. | Contact support if it’s urgent, or upgrade to Pro or Business and run Check DNS. |
| SPF is Invalid | The record at emailit.<domain> doesn’t include _spf.emailit.com. |
Use the exact value v=spf1 include:_spf.emailit.com ~all. |
| DKIM is Invalid | The key was cut off, or it’s from a domain you deleted and added again. Each new domain gets a new key. | Copy the current value from the domain page. |
| Return Path is Invalid | There’s a second MX record on emailit.<domain>, or it points elsewhere. |
Keep one MX record pointing to feedback-smtp.ffdc-1.emailit.com. |
| The domain was verified and suddenly isn’t | Someone removed or changed a record, or the domain moved to a new DNS provider without the records. | Check the “no longer verified” email for which record failed, restore it and select Check DNS. |
Sending fails with 422 Domain not verified |
The From address uses a different domain or subdomain than the verified one. |
Send from the exact verified domain, or add and verify the subdomain. |