# Why does my tracking CNAME fail on Cloudflare?

> A proxied (orange cloud) Cloudflare record hides your tracking CNAME, so Emailit can't verify it. Switch the record to DNS only to fix it.

This article is for domains whose DNS is hosted on Cloudflare. If the tracking record stays **Invalid** even though you created it, the Cloudflare proxy is the most likely cause.

## Symptoms

- In **Email API → Domains**, the tracking CNAME (`go.acme.com` by default) shows **Invalid**. SPF, DKIM and the return path show **OK**.
- **Track loads** and **Track clicks** can't be turned on for the domain.
- Emails go out untracked, so you never see **Loaded** or **Clicked**.
- `dig CNAME go.acme.com +short` returns nothing, while `dig go.acme.com +short` returns Cloudflare IP addresses.

## Cause

Cloudflare proxies new CNAME records by default. The record shows an orange cloud and the status **Proxied**. A proxied record doesn't publish the CNAME. Instead, Cloudflare answers with its own IP addresses.

Emailit verifies the tracking record with a CNAME lookup that must return exactly `go.emailitmail.com`. With the proxy on, the lookup finds no CNAME, so the record is marked **Invalid**. Even if it passed, Cloudflare's proxy couldn't serve Emailit's tracking links for your domain.

Only the tracking record is affected. TXT and MX records, which make up SPF, DKIM and the return path, can't be proxied.

## Fix

1. **Open the record in Cloudflare.** In the Cloudflare dashboard, go to your domain, then **DNS > Records**, and find the CNAME named `go` (or your custom tracking subdomain).

2. **Switch it to DNS only.** Select **Edit**, click the orange cloud so it turns grey and shows **DNS only**, and save. Keep the target `go.emailitmail.com`.

3. **Confirm the change.** After a minute or two, run:

```bash
dig CNAME go.acme.com +short
```

   The result should be `go.emailitmail.com.`

4. **Check DNS in Emailit.** Open the domain and select **Check DNS**. The tracking record should change to **OK**.

5. **Turn on tracking.** Switch on **Track loads** and **Track clicks** on the domain page. New emails are tracked from now on. Emails sent earlier stay untracked.

If you used Emailit's one-click Cloudflare setup, new tracking records are created as **DNS only**. A record that already existed with the right target is left as it is, so if it was proxied you still need to switch it yourself. See [Set up DNS on Cloudflare](/docs/domains/cloudflare/) and [Custom tracking domain](/docs/tracking/custom-tracking-domain/).

## Still stuck?

[Contact support](/contact/) or ask in [Discord](https://discord.emailit.com). Include the domain name and the output of the `dig` command.

---
Source: https://emailit.com/docs/kb/cloudflare-proxy-breaks-tracking-cname/
