# Go-live checklist

> Everything to check before you send production email with Emailit, from DNS, production access and API keys to webhooks, suppressions, limits and warm-up.

Work through this checklist before you send email to real recipients. Most items take a few minutes. Production access and limit increases are reviewed by the Emailit team, so start those first.

## Domains and DNS

- [ ] **Verify every domain you send from.** In **Email API → Domains**, each domain should show **Verified**, with **SPF**, **DKIM** and **Return Path** all **OK**. A From address on any other domain is rejected. See [Add a domain](/docs/domains/add-a-domain/) and [DNS records](/docs/domains/dns-records/).
- [ ] **Publish a DMARC record.** If your domain has no `_dmarc` TXT record yet, start with the one suggested on the domain page, `v=DMARC1; p=none;`, and tighten the policy once reports look clean. Gmail and Yahoo expect a DMARC record from anyone who sends in bulk. If you already have a DMARC record, keep it. Emailit mail passes DMARC through DKIM aligned with your domain. See [Set up DMARC](/docs/dmarc/set-up/).
- [ ] **Set up a tracking subdomain if you track opens or clicks.** Publish a CNAME from `go.<your domain>` to `go.emailitmail.com`, then turn on **Track loads** and **Track clicks** on the domain page. Without a verified CNAME, mail is sent untracked. See [Custom tracking domain](/docs/tracking/custom-tracking-domain/).
- [ ] **Use From addresses people recognize**, and make sure replies reach someone: set `reply_to` to a monitored mailbox, or [receive replies with inbound](/docs/inbound/).

## Workspace and access

- [ ] **Request production access.** Until it's approved, you can only send to the account email addresses of workspace members, and campaigns are blocked. An Admin goes to **Workspace → Settings → Requests** and selects **Request Verification**. You need at least one verified domain. See [Production access](/docs/workspaces/production-access/).
- [ ] **Check your sending limits.** New workspaces can send 2 emails per second and 5,000 emails per day, shared by the API and SMTP. If you need more on day one, select **Request Increase** on the **Sending Limits** card on the dashboard home page and explain your volume and where your list comes from. Requests are usually reviewed within 24 hours. See [Limits](/docs/limits/).
- [ ] **Make sure you have enough credits**, and turn on [auto-refill](/docs/billing/auto-refill/) so sending doesn't stop when the balance runs low. Auto-refill is off by default. See [Credits](/docs/billing/credits/).
- [ ] **Secure the team.** Give people the **Member** role unless they need to manage keys, members or billing, and turn on [two-factor authentication](/docs/account/two-factor-and-passkeys/). See [Members and roles](/docs/workspaces/members-and-roles/).

## API keys

- [ ] **Use a Sending Only key in production apps.** A **Sending Only** key can send, reschedule, cancel, retry and forward email, and nothing else. Restrict it to the one domain the app sends from. Keep **Full Access** keys for tools that read emails or manage resources.
- [ ] **Use one key per app and environment**, so the logs show who sent what and you can rotate one key without touching the others.
- [ ] **Keep keys secret.** Store them in your secret manager or environment variables, never in client-side code or a repository. To rotate a key, select **Regenerate**. The old secret stops working immediately. See [API keys](/docs/developers/api-keys/).

## Webhooks

- [ ] **Create a webhook endpoint** in **Email API → Webhooks**, on an HTTPS URL. A new webhook receives every event. Narrow it to the events you act on, such as `email.delivered`, `email.bounced`, `email.complained` and `email.suppressed`. See [Set up webhooks](/docs/webhooks/set-up/).
- [ ] **Verify the signature on every request.** `X-Emailit-Signature` is the hex HMAC-SHA256 of `<timestamp>.<raw body>`, using the full webhook secret including `whsec_`, and the timestamp is in `X-Emailit-Timestamp`. See [Request signature](/docs/webhooks/request-signature/).
- [ ] **Handle batches and retries.** Each request body is a JSON array of up to 100 events. Return a `2xx` within 30 seconds, then process the events in the background, skipping any `event_id` you've already seen. Failed requests are retried for about 3 days, and an endpoint that keeps failing for 3 days is disabled. See [Retries and failures](/docs/webhooks/retries-and-failures/).
- [ ] **Send a test event** with **Send test** on the webhook page and check that your handler accepts it.

## Sending code

- [ ] **Send an `Idempotency-Key` with every API request** so network retries never send the same email twice. See [Idempotency](/docs/email-api/idempotency/).
- [ ] **Handle errors.** Retry `429` and `5xx` responses with backoff, and respect the `retry-after` header. Don't retry other `4xx` responses without fixing the request. See [Errors](/docs/api-reference/errors/) and [Rate limits](/docs/api-reference/rate-limits/).
- [ ] **Store the email IDs** from each response (`id`, and `ids` when there are several recipients) so you can match webhook events to your own records.

## Lists and compliance

- [ ] **Import your existing suppressions** before your first send if you're moving from another provider. Use **Import** in **Email API → Suppressions** with a CSV of `email,type,reason`. Rows with the type `recipient` block every kind of sending. See [Manage suppressions](/docs/suppressions/manage/).
- [ ] **Review automatic suppression** in **Workspace → Settings** under **Suppressions**. Pro and Business workspaces can change which bounces and complaints are suppressed.
- [ ] **Add unsubscribe headers to bulk mail.** Campaigns add `List-Unsubscribe` and one-click unsubscribe headers for you. If you send newsletters or promotions through the API or SMTP, add `List-Unsubscribe` and `List-Unsubscribe-Post: List-Unsubscribe=One-Click` yourself, and honor every request. See [Headers and metadata](/docs/email-api/headers-and-metadata/).
- [ ] **Only email people who asked for it.** Cold email isn't allowed. Check old or bought lists with [email verification](/docs/email-verification/) before you import them, or better, don't import them.

## Ramp up and monitor

- [ ] **Warm up gradually.** Start with your most engaged recipients and increase volume over days, not hours, especially on a new domain or a dedicated IP. See [Warm-up](/docs/deliverability/warm-up/).
- [ ] **Watch sending health.** Emailit scores each domain and workspace on its bounce rate, once at least 100 unique recipients have been reached. Above 4% a domain is at risk, above 5% sending from the domain is paused, and at 6% or more the workspace is suspended. See [Sending health](/docs/deliverability/sending-health/).
- [ ] **Know where to look.** **Email API → Emails** shows each email's status, delivery attempts and spam checks. **Email API → Logs** shows every API and SMTP request. **Email API → Analytics** shows trends. Subscribe to [status.emailit.com](https://status.emailit.com) for incidents.

## Test sends

- [ ] **Send to real inboxes** at Gmail, Outlook and Yahoo. Check that the message lands in the inbox, that SPF, DKIM and DMARC show `pass` in the message headers, and that links and images work on mobile. To send a quick one-off test without code, use **Compose** on the **Email API → Emails** page.
- [ ] **Check the spam score** on each test email's page under **Spam Checks**. Messages that score 7 or more are held and not delivered.
- [ ] **Test every template** with realistic data, including missing values. Temple replaces a missing variable with an empty string unless you give it a default, such as `{{first_name|"there"}}`. See [Temple](/docs/templates/temple/).

> **Moving from another provider?:** Follow [Migrate to Emailit](/docs/migrate/) for the order to move domains, templates, suppressions and webhooks. The [Priority migration](/docs/programs/priority-migration/) service can do it with you.

## Related

- [How Emailit works](/docs/get-started/how-emailit-works/)
- [Deliverability best practices](/docs/deliverability/best-practices/)
- [Bounces and complaints](/docs/deliverability/bounces-and-complaints/)

---
Source: https://emailit.com/docs/get-started/go-live/
