# Do I need to change my SPF record for Emailit?

> Emailit's SPF record lives on its own subdomain, so you don't edit your root SPF. Here's how to fix duplicate SPF records if you have them anyway.

Most email services ask you to add an `include:` to your domain's SPF record, which often leads to two SPF records and broken authentication. Emailit works differently. This article explains where Emailit's SPF record goes and how to fix duplicates on your root domain.

## Symptoms

- You're unsure whether to add `include:_spf.emailit.com` to the SPF record on `acme.com`.
- A DNS checker reports "multiple SPF records" or `permerror` for your domain.
- DMARC reports show SPF failures for mail from Google Workspace, Microsoft 365 or another service after you edited SPF.

## Cause

SPF is checked against the **return-path** domain, the address bounces go to, not the address in `From`. Emailit uses its own return-path subdomain, `emailit.acme.com`, and the SPF record for Emailit lives there:

```text
emailit.acme.com  TXT  "v=spf1 include:_spf.emailit.com ~all"
```

Your root SPF record on `acme.com` is used by your other senders, such as your mailbox provider. **You don't need to change it for Emailit.** SPF still aligns for DMARC because `emailit.acme.com` is a subdomain of `acme.com`.

Duplicate SPF records happen when two `v=spf1` TXT records exist on the **same name**. Receivers then return `permerror` and SPF fails for every sender on that name. Common reasons:

- Someone added a second SPF record for a new service instead of editing the existing one.
- `include:_spf.emailit.com` was added as a separate record on `acme.com`.
- On `emailit.acme.com`, an old record was left behind next to the new one.

## Fix

1. **List the SPF records on each name.**

```bash
dig TXT acme.com +short | grep spf1
dig TXT emailit.acme.com +short | grep spf1
```

   Each name should return **at most one** line that starts with `v=spf1`.

2. **Keep Emailit's record on the subdomain.** `emailit.acme.com` should have exactly the record shown in the domain's DNS setup in **Email API → Domains**.

3. **Remove Emailit from the root record.** If you added `include:_spf.emailit.com` to `acme.com`, you can remove it. It isn't needed.

4. **Merge duplicates into one record.** If `acme.com` has two SPF records, combine their mechanisms into one and delete the other:

```text
Before:  "v=spf1 include:_spf.google.com ~all"
         "v=spf1 include:spf.protection.outlook.com ~all"
After:   "v=spf1 include:_spf.google.com include:spf.protection.outlook.com ~all"
```

   Keep one `v=spf1` at the start and one `all` mechanism at the end. SPF allows at most 10 DNS lookups, so remove includes for services you no longer use.

5. **Check DNS in Emailit.** Open the domain and select **Check DNS** to confirm SPF shows **OK**.

For the full list of records, see [DNS records](/docs/domains/dns-records/) and the [DNS records dictionary](/docs/dictionary/dns-records/).

## Still stuck?

[Contact support](/contact/) or ask in [Discord](https://discord.emailit.com) with your domain name and the output of the `dig` commands.

---
Source: https://emailit.com/docs/kb/multiple-spf-records/
