# Should I send from my root domain or a subdomain?

> Choose between acme.com and a subdomain like mail.acme.com for sending. Subdomains separate reputation but each one needs its own verification.

You can send from your root domain (`acme.com`) or from a subdomain (`mail.acme.com`, `news.acme.com`). Both work with Emailit. This article explains the trade-offs so you can pick a setup before you add your domains.

## Symptoms

- You're adding your first sending domain and aren't sure which name to enter.
- Your `From` address uses a subdomain, and sending fails with "domain not verified" even though the root domain is verified.
- Marketing complaints seem to be hurting delivery of receipts and password resets.

## Cause

Emailit treats every domain and subdomain as a separate sending domain:

- **Each one is verified on its own.** Verifying `acme.com` doesn't cover `news.acme.com`. The records go under the subdomain, for example `emailit.news.acme.com` and `emailit._domainkey.news.acme.com`.
- **The `From` address must match exactly.** Mail from `hello@news.acme.com` needs `news.acme.com` verified. See [Why does SMTP return 530 From domain not verified?](/docs/kb/smtp-530-from-domain-not-verified/).
- **Each one counts toward your plan's domain limit.** Pay as you go allows 3 domains (25 after your first credit purchase), Pro 100 and Business 1,000.

Mailbox providers build reputation for each domain, and partly for each subdomain. Mail from a subdomain still carries your brand, but a problem on `news.acme.com` affects `acme.com` less than if both shared one name.

## Fix

1. **Pick a layout.** A common setup:

   | Mail | Send from |
   | --- | --- |
   | Receipts, sign-in codes, password resets | `acme.com` or `mail.acme.com` |
   | Newsletters and campaigns | `news.acme.com` |

   Small senders with one kind of mail can simply use `acme.com`.

2. **Add each domain you send from.** In **Email API → Domains**, select **Add domain** and enter the exact name, without `http://` or `www.`. See [Add a domain](/docs/domains/add-a-domain/).

3. **Publish the records for each one.** Every domain gets its own SPF, DKIM and return-path records. Then select **Check DNS**.

4. **Cover DMARC.** A subdomain follows the DMARC policy of your root domain unless it has its own `_dmarc` record. Publishing `_dmarc.acme.com` covers both.

5. **Restrict keys if you like.** Create a **Sending Only** API key limited to one domain for each system, so a marketing tool can't send as your transactional domain. See [API keys](/docs/developers/api-keys/).

On Pay as you go, a subdomain of a domain registered more than 30 days ago doesn't need the new-domain review. See [Why is my domain pending verification?](/docs/kb/domain-pending-review-new-domain/) and [Domain limits](/docs/domains/limits/).

## Still stuck?

[Contact support](/contact/) or ask in [Discord](https://discord.emailit.com) if you want advice on a domain setup for your volume.

---
Source: https://emailit.com/docs/kb/root-domain-or-subdomain/
