# Why are my DNS records not verifying?

> Fix SPF, DKIM and return-path records that stay Missing or Invalid. Covers doubled host names, extra MX records, wrong zones and propagation delays.

This article helps when your sending domain stays **Not verified** after you've added the DNS records. A domain is verified when its SPF, DKIM and return-path records all show **OK**.

## Symptoms

- The domain shows **Not verified** in **Email API → Domains**.
- One or more records show **Missing** or **Invalid** after you select **Check DNS**.
- The **Error** column shows a message such as `An SPF record exists but it doesn't include _spf.emailit.com` or `The MX record at emailit.acme.com does not point to the expected mail server`.

## Cause

Emailit needs three records. All of them sit on subdomains, so they don't touch your existing website or mailbox records:

| Type | Name | Value |
| --- | --- | --- |
| TXT (SPF) | `emailit.acme.com` | `v=spf1 include:_spf.emailit.com ~all` |
| TXT (DKIM) | `emailit._domainkey.acme.com` | `v=DKIM1; t=s; h=sha256; p=…` (your key) |
| MX (return path) | `emailit.acme.com` | `feedback-smtp.ffdc-1.emailit.com`, priority 10 |

Common mistakes:

- **Doubled host name.** Many DNS providers add your domain automatically, so typing `emailit.acme.com` creates `emailit.acme.com.acme.com`. Enter only `emailit` or `emailit._domainkey`.
- **Extra MX records at `emailit`.** The return-path name must have exactly one MX record, pointing to Emailit.
- **Truncated or altered DKIM key.** Part of the key is missing, or extra quotes or spaces were pasted in.
- **SPF on the wrong name.** Emailit's SPF record goes on `emailit.acme.com`, not on `acme.com`.
- **A CNAME on the same name.** A CNAME at `emailit.acme.com` blocks the TXT and MX records there.
- **Wrong DNS zone.** You edited records at your registrar, but your nameservers point to another provider such as Cloudflare.
- **Propagation.** Most providers publish changes within minutes, but it can take up to 48 hours.

## Fix

1. **Read the error.** Open the domain. The **Error** column next to each record explains what Emailit found.

2. **Look up the records yourself.**

```bash
dig NS acme.com +short
dig TXT emailit.acme.com +short
dig TXT emailit._domainkey.acme.com +short
dig MX emailit.acme.com +short
```

   The first command shows which provider hosts your DNS. Make your changes there. Each of the others should return exactly the value from the table.

3. **Fix the host names.** If a lookup returns nothing, check for a doubled host name and re-enter just the subdomain part.

4. **Copy values with the copy button.** Use the copy buttons in the dashboard. If your provider splits long TXT values into several strings, that's fine.

5. **Remove conflicting records.** Delete other MX or CNAME records on `emailit.acme.com`.

6. **Check again.** Select **Check DNS**. Emailit also re-checks every day.

7. **Hand it off if you don't manage DNS.** Use **Send to email** on the domain page to email the records to whoever does.

If all three records show **OK** but the domain shows **Pending verification**, it's waiting for a manual review. See [Why is my domain pending verification?](/docs/kb/domain-pending-review-new-domain/). For record details, see [DNS records](/docs/domains/dns-records/). If your DNS is on Cloudflare, [one-click setup](/docs/domains/cloudflare/) avoids typos.

## Still stuck?

[Contact support](/contact/) or ask in [Discord](https://discord.emailit.com). Include the domain name and the output of the `dig` commands.

---
Source: https://emailit.com/docs/kb/dns-records-not-verifying/
