Skip to content
Docs

FAQ

Do I need to change my SPF record for Emailit?

Emailit's SPF record lives on its own subdomain, so you don't edit your root SPF. Here's how to fix duplicate SPF records if you have them anyway.

Updated Oct 1, 2026

Most email services ask you to add an include: to your domain’s SPF record, which often leads to two SPF records and broken authentication. Emailit works differently. This article explains where Emailit’s SPF record goes and how to fix duplicates on your root domain.

Symptoms

  • You’re unsure whether to add include:_spf.emailit.com to the SPF record on acme.com.
  • A DNS checker reports “multiple SPF records” or permerror for your domain.
  • DMARC reports show SPF failures for mail from Google Workspace, Microsoft 365 or another service after you edited SPF.

Cause

SPF is checked against the return-path domain, the address bounces go to, not the address in From. Emailit uses its own return-path subdomain, emailit.acme.com, and the SPF record for Emailit lives there:

Text
emailit.acme.com  TXT  "v=spf1 include:_spf.emailit.com ~all"

Your root SPF record on acme.com is used by your other senders, such as your mailbox provider. You don’t need to change it for Emailit. SPF still aligns for DMARC because emailit.acme.com is a subdomain of acme.com.

Duplicate SPF records happen when two v=spf1 TXT records exist on the same name. Receivers then return permerror and SPF fails for every sender on that name. Common reasons:

  • Someone added a second SPF record for a new service instead of editing the existing one.
  • include:_spf.emailit.com was added as a separate record on acme.com.
  • On emailit.acme.com, an old record was left behind next to the new one.

Fix

  1. List the SPF records on each name.

    Terminal
    dig TXT acme.com +short | grep spf1
    dig TXT emailit.acme.com +short | grep spf1

    Each name should return at most one line that starts with v=spf1.

  2. Keep Emailit’s record on the subdomain. emailit.acme.com should have exactly the record shown in the domain’s DNS setup in Email APIDomains.

  3. Remove Emailit from the root record. If you added include:_spf.emailit.com to acme.com, you can remove it. It isn’t needed.

  4. Merge duplicates into one record. If acme.com has two SPF records, combine their mechanisms into one and delete the other:

    Text
    Before:  "v=spf1 include:_spf.google.com ~all"
             "v=spf1 include:spf.protection.outlook.com ~all"
    After:   "v=spf1 include:_spf.google.com include:spf.protection.outlook.com ~all"

    Keep one v=spf1 at the start and one all mechanism at the end. SPF allows at most 10 DNS lookups, so remove includes for services you no longer use.

  5. Check DNS in Emailit. Open the domain and select Check DNS to confirm SPF shows OK.

For the full list of records, see DNS records and the DNS records dictionary.

Still stuck?

Contact support or ask in Discord with your domain name and the output of the dig commands.

Was this page helpful?

Thanks for the feedback.

Thanks, we read every message.