FAQ
Do I need to change my SPF record for Emailit?
Emailit's SPF record lives on its own subdomain, so you don't edit your root SPF. Here's how to fix duplicate SPF records if you have them anyway.
Most email services ask you to add an include: to your domain’s SPF record, which often leads to two SPF records and broken authentication. Emailit works differently. This article explains where Emailit’s SPF record goes and how to fix duplicates on your root domain.
Symptoms
- You’re unsure whether to add
include:_spf.emailit.comto the SPF record onacme.com. - A DNS checker reports “multiple SPF records” or
permerrorfor your domain. - DMARC reports show SPF failures for mail from Google Workspace, Microsoft 365 or another service after you edited SPF.
Cause
SPF is checked against the return-path domain, the address bounces go to, not the address in From. Emailit uses its own return-path subdomain, emailit.acme.com, and the SPF record for Emailit lives there:
emailit.acme.com TXT "v=spf1 include:_spf.emailit.com ~all"Your root SPF record on acme.com is used by your other senders, such as your mailbox provider. You don’t need to change it for Emailit. SPF still aligns for DMARC because emailit.acme.com is a subdomain of acme.com.
Duplicate SPF records happen when two v=spf1 TXT records exist on the same name. Receivers then return permerror and SPF fails for every sender on that name. Common reasons:
- Someone added a second SPF record for a new service instead of editing the existing one.
include:_spf.emailit.comwas added as a separate record onacme.com.- On
emailit.acme.com, an old record was left behind next to the new one.
Fix
-
List the SPF records on each name.
dig TXT acme.com +short | grep spf1 dig TXT emailit.acme.com +short | grep spf1Each name should return at most one line that starts with
v=spf1. -
Keep Emailit’s record on the subdomain.
emailit.acme.comshould have exactly the record shown in the domain’s DNS setup in Email APIDomains. -
Remove Emailit from the root record. If you added
include:_spf.emailit.comtoacme.com, you can remove it. It isn’t needed. -
Merge duplicates into one record. If
acme.comhas two SPF records, combine their mechanisms into one and delete the other:Before: "v=spf1 include:_spf.google.com ~all" "v=spf1 include:spf.protection.outlook.com ~all" After: "v=spf1 include:_spf.google.com include:spf.protection.outlook.com ~all"Keep one
v=spf1at the start and oneallmechanism at the end. SPF allows at most 10 DNS lookups, so remove includes for services you no longer use. -
Check DNS in Emailit. Open the domain and select Check DNS to confirm SPF shows OK.
For the full list of records, see DNS records and the DNS records dictionary.
Still stuck?
Contact support or ask in Discord with your domain name and the output of the dig commands.