Skip to content
Docs

Troubleshooting

Why does my tracking CNAME fail on Cloudflare?

A proxied (orange cloud) Cloudflare record hides your tracking CNAME, so Emailit can't verify it. Switch the record to DNS only to fix it.

Updated Oct 1, 2026

This article is for domains whose DNS is hosted on Cloudflare. If the tracking record stays Invalid even though you created it, the Cloudflare proxy is the most likely cause.

Symptoms

  • In Email APIDomains, the tracking CNAME (go.acme.com by default) shows Invalid. SPF, DKIM and the return path show OK.
  • Track loads and Track clicks can’t be turned on for the domain.
  • Emails go out untracked, so you never see Loaded or Clicked.
  • dig CNAME go.acme.com +short returns nothing, while dig go.acme.com +short returns Cloudflare IP addresses.

Cause

Cloudflare proxies new CNAME records by default. The record shows an orange cloud and the status Proxied. A proxied record doesn’t publish the CNAME. Instead, Cloudflare answers with its own IP addresses.

Emailit verifies the tracking record with a CNAME lookup that must return exactly go.emailitmail.com. With the proxy on, the lookup finds no CNAME, so the record is marked Invalid. Even if it passed, Cloudflare’s proxy couldn’t serve Emailit’s tracking links for your domain.

Only the tracking record is affected. TXT and MX records, which make up SPF, DKIM and the return path, can’t be proxied.

Fix

  1. Open the record in Cloudflare. In the Cloudflare dashboard, go to your domain, then DNS > Records, and find the CNAME named go (or your custom tracking subdomain).

  2. Switch it to DNS only. Select Edit, click the orange cloud so it turns grey and shows DNS only, and save. Keep the target go.emailitmail.com.

  3. Confirm the change. After a minute or two, run:

    Terminal
    dig CNAME go.acme.com +short

    The result should be go.emailitmail.com.

  4. Check DNS in Emailit. Open the domain and select Check DNS. The tracking record should change to OK.

  5. Turn on tracking. Switch on Track loads and Track clicks on the domain page. New emails are tracked from now on. Emails sent earlier stay untracked.

If you used Emailit’s one-click Cloudflare setup, new tracking records are created as DNS only. A record that already existed with the right target is left as it is, so if it was proxied you still need to switch it yourself. See Set up DNS on Cloudflare and Custom tracking domain.

Still stuck?

Contact support or ask in Discord. Include the domain name and the output of the dig command.

Was this page helpful?

Thanks for the feedback.

Thanks, we read every message.