Skip to content
Docs

Concept

How Emailit verifies sending domains, what each domain and record status means, how manual review and daily re-checks work, and how to fix failures.

Updated Oct 1, 2026

A sending domain must be verified before Emailit sends mail from it. This page explains what Emailit checks, what each status means, how the review for new Pay as you go domains works and how to fix a domain that won’t verify.

What Emailit checks

Verification looks at three DNS records. All three must pass:

Check Record Passes when
SPF TXT at emailit.<domain> A v=spf1 record includes _spf.emailit.com.
DKIM TXT at emailit._domainkey.<domain> The record’s p= key matches the domain’s DKIM key.
Return Path MX at emailit.<domain> There’s exactly one MX record and it points to feedback-smtp.ffdc-1.emailit.com.

Emailit also checks DMARC, the tracking CNAME and the inbound MX record at the same time and shows their status, but they don’t affect verification. See DNS records for every value.

On Pay as you go, Emailit also checks the domain’s age. See Pending verification.

Domain statuses

The Verification column in Email APIDomains and the API field verification_status show one of three states.

Dashboard API value Meaning Can send?
Verified verified SPF, DKIM and the return path pass. Yes
Not verified pending A required record is missing or invalid, or DNS hasn’t been checked yet. No
Pending verification pending_review The domain is waiting for a manual review by Emailit. No

The API also returns verified_at (when the domain last passed), dns_checked_at (when DNS was last checked) and manual_review_required.

Record statuses

Each record on the domain page, and each item in the API’s dns_records array, has its own status.

Dashboard API value Meaning
OK ok The record is published with the expected value.
Missing missing Emailit found no matching record at that host.
Invalid invalid A record exists, but its value is wrong, for example an MX pointing elsewhere or a DKIM key that doesn’t match.
Not checked pending DNS hasn’t been checked since the record was created or its host changed.

DMARC can also return error when the lookup itself fails, which the dashboard shows as Not checked. Hover over Missing or Invalid in the dashboard, or read the record’s error field in the API, to see exactly what Emailit found.

What verification unlocks

  • Sending. You can send from any address on the domain through the API, SMTP, campaigns and automations.
  • Inbound email. Emailit only accepts mail for inbound.<domain> on verified domains.
  • Production access. You need at least one verified domain before you can request production access.
  • Tracking, once the tracking CNAME also shows OK. See Open and click tracking.

Run a check

Verification runs when you ask for it:

  • In the dashboard, select Check DNS on the domain page.
  • With the API, call Verify a domain.
  • Cloudflare setup runs the check for you after it creates the records.

Emailit doesn’t verify a new domain on its own, so run a check after you publish or fix records.

Pending verification

On Pay as you go, a domain that was registered less than 30 days ago needs a manual review before it can send. Emailit reads the registration date of the domain from WHOIS. For a subdomain such as mail.acme.com, it uses the registration date of acme.com. If WHOIS doesn’t return a date, the domain isn’t held for review.

While a domain waits for review:

  • It shows Pending verification, and the domain page shows a banner explaining why.
  • It can’t send, even when all records show OK.
  • You don’t need to do anything else. Keep the DNS records in place so the domain verifies as soon as it’s approved.

Pro and Business workspaces skip the age check. If you upgrade while a domain is pending, select Check DNS and it verifies as soon as DNS passes.

Pay as you goProBusinessCustom
Review of domains under 30 days oldYesNoNoYes

Approval is permanent

Once Emailit approves a domain, the approval stays. If DNS breaks later, the domain shows Not verified and stops sending until you fix the records, but it doesn’t go back into review. Running Check DNS never removes an approval.

Daily re-check

Emailit re-checks the DNS of every domain once a day and updates each record’s status and Last checked time.

  • If a verified domain fails, Emailit marks it Not verified and emails the workspace owner: “Sending domain <domain> is no longer verified”. The email lists the SPF, DKIM and return path results. Mail from the domain doesn’t send until it passes again.
  • If only the DNS lookups time out, Emailit treats it as a temporary resolver problem and keeps the domain verified.
  • If a domain that Emailit approved after review passes again, the daily check restores it to Verified.

For any other domain that lost verification, fix the records and select Check DNS to bring it back. The daily check doesn’t verify those domains on its own.

Paused domains

A verified domain can still be paused when its bounce rate is too high. The domain page shows a Sending paused banner, the API returns restricted: true, and:

  • the API rejects sends from the domain with 403 Domain paused,
  • SMTP replies 550 Sending from this domain is paused,
  • queued mail from the domain gets the status held.

Pausing is part of sending health, not DNS. Contact support to restore a paused domain after you’ve fixed the cause.

Troubleshooting

Symptom Likely cause Fix
SPF, DKIM or Return Path is Missing The record is at the wrong host, often with the domain added twice, such as emailit.acme.com.acme.com. Enter only the relative host (emailit, emailit._domainkey). Check with dig. See DNS records.
Everything is OK but the domain isn’t verified The records were published after the last check. Select Check DNS.
Pending verification stays for days The domain was registered less than 30 days ago and is waiting for review. Contact support if it’s urgent, or upgrade to Pro or Business and run Check DNS.
SPF is Invalid The record at emailit.<domain> doesn’t include _spf.emailit.com. Use the exact value v=spf1 include:_spf.emailit.com ~all.
DKIM is Invalid The key was cut off, or it’s from a domain you deleted and added again. Each new domain gets a new key. Copy the current value from the domain page.
Return Path is Invalid There’s a second MX record on emailit.<domain>, or it points elsewhere. Keep one MX record pointing to feedback-smtp.ffdc-1.emailit.com.
The domain was verified and suddenly isn’t Someone removed or changed a record, or the domain moved to a new DNS provider without the records. Check the “no longer verified” email for which record failed, restore it and select Check DNS.
Sending fails with 422 Domain not verified The From address uses a different domain or subdomain than the verified one. Send from the exact verified domain, or add and verify the subdomain.
Add a domain and publish its records.
How many domains your plan includes.
Bounce rates, scores and paused domains.
Create, verify and update domains.

Was this page helpful?

Thanks for the feedback.

Thanks, we read every message.