Guide
Go-live checklist
Everything to check before you send production email with Emailit, from DNS, production access and API keys to webhooks, suppressions, limits and warm-up.
Updated Oct 1, 2026
Work through this checklist before you send email to real recipients. Most items take a few minutes. Production access and limit increases are reviewed by the Emailit team, so start those first.
Domains and DNS
- Verify every domain you send from. In Email APIDomains, each domain should show Verified, with SPF, DKIM and Return Path all OK. A From address on any other domain is rejected. See Add a domain and DNS records.
- Publish a DMARC record. If your domain has no
_dmarcTXT record yet, start with the one suggested on the domain page,v=DMARC1; p=none;, and tighten the policy once reports look clean. Gmail and Yahoo expect a DMARC record from anyone who sends in bulk. If you already have a DMARC record, keep it. Emailit mail passes DMARC through DKIM aligned with your domain. See Set up DMARC. - Set up a tracking subdomain if you track opens or clicks. Publish a CNAME from
go.<your domain>togo.emailitmail.com, then turn on Track loads and Track clicks on the domain page. Without a verified CNAME, mail is sent untracked. See Custom tracking domain. - Use From addresses people recognize, and make sure replies reach someone: set
reply_toto a monitored mailbox, or receive replies with inbound.
Workspace and access
- Request production access. Until it’s approved, you can only send to the account email addresses of workspace members, and campaigns are blocked. An Admin goes to WorkspaceSettingsRequests and selects Request Verification. You need at least one verified domain. See Production access.
- Check your sending limits. New workspaces can send 2 emails per second and 5,000 emails per day, shared by the API and SMTP. If you need more on day one, select Request Increase on the Sending Limits card on the dashboard home page and explain your volume and where your list comes from. Requests are usually reviewed within 24 hours. See Limits.
- Make sure you have enough credits, and turn on auto-refill so sending doesn’t stop when the balance runs low. Auto-refill is off by default. See Credits.
- Secure the team. Give people the Member role unless they need to manage keys, members or billing, and turn on two-factor authentication. See Members and roles.
API keys
- Use a Sending Only key in production apps. A Sending Only key can send, reschedule, cancel, retry and forward email, and nothing else. Restrict it to the one domain the app sends from. Keep Full Access keys for tools that read emails or manage resources.
- Use one key per app and environment, so the logs show who sent what and you can rotate one key without touching the others.
- Keep keys secret. Store them in your secret manager or environment variables, never in client-side code or a repository. To rotate a key, select Regenerate. The old secret stops working immediately. See API keys.
Webhooks
- Create a webhook endpoint in Email APIWebhooks, on an HTTPS URL. A new webhook receives every event. Narrow it to the events you act on, such as
email.delivered,email.bounced,email.complainedandemail.suppressed. See Set up webhooks. - Verify the signature on every request.
X-Emailit-Signatureis the hex HMAC-SHA256 of<timestamp>.<raw body>, using the full webhook secret includingwhsec_, and the timestamp is inX-Emailit-Timestamp. See Request signature. - Handle batches and retries. Each request body is a JSON array of up to 100 events. Return a
2xxwithin 30 seconds, then process the events in the background, skipping anyevent_idyou’ve already seen. Failed requests are retried for about 3 days, and an endpoint that keeps failing for 3 days is disabled. See Retries and failures. - Send a test event with Send test on the webhook page and check that your handler accepts it.
Sending code
- Send an
Idempotency-Keywith every API request so network retries never send the same email twice. See Idempotency. - Handle errors. Retry
429and5xxresponses with backoff, and respect theretry-afterheader. Don’t retry other4xxresponses without fixing the request. See Errors and Rate limits. - Store the email IDs from each response (
id, andidswhen there are several recipients) so you can match webhook events to your own records.
Lists and compliance
- Import your existing suppressions before your first send if you’re moving from another provider. Use Import in Email APISuppressions with a CSV of
email,type,reason. Rows with the typerecipientblock every kind of sending. See Manage suppressions. - Review automatic suppression in WorkspaceSettings under Suppressions. Pro and Business workspaces can change which bounces and complaints are suppressed.
- Add unsubscribe headers to bulk mail. Campaigns add
List-Unsubscribeand one-click unsubscribe headers for you. If you send newsletters or promotions through the API or SMTP, addList-UnsubscribeandList-Unsubscribe-Post: List-Unsubscribe=One-Clickyourself, and honor every request. See Headers and metadata. - Only email people who asked for it. Cold email isn’t allowed. Check old or bought lists with email verification before you import them, or better, don’t import them.
Ramp up and monitor
- Warm up gradually. Start with your most engaged recipients and increase volume over days, not hours, especially on a new domain or a dedicated IP. See Warm-up.
- Watch sending health. Emailit scores each domain and workspace on its bounce rate, once at least 100 unique recipients have been reached. Above 4% a domain is at risk, above 5% sending from the domain is paused, and at 6% or more the workspace is suspended. See Sending health.
- Know where to look. Email APIEmails shows each email’s status, delivery attempts and spam checks. Email APILogs shows every API and SMTP request. Email APIAnalytics shows trends. Subscribe to status.emailit.com for incidents.
Test sends
- Send to real inboxes at Gmail, Outlook and Yahoo. Check that the message lands in the inbox, that SPF, DKIM and DMARC show
passin the message headers, and that links and images work on mobile. To send a quick one-off test without code, use Compose on the Email APIEmails page. - Check the spam score on each test email’s page under Spam Checks. Messages that score 7 or more are held and not delivered.
- Test every template with realistic data, including missing values. Temple replaces a missing variable with an empty string unless you give it a default, such as
{{first_name|"there"}}. See Temple.