FAQ
Should I send from my root domain or a subdomain?
Choose between acme.com and a subdomain like mail.acme.com for sending. Subdomains separate reputation but each one needs its own verification.
You can send from your root domain (acme.com) or from a subdomain (mail.acme.com, news.acme.com). Both work with Emailit. This article explains the trade-offs so you can pick a setup before you add your domains.
Symptoms
- You’re adding your first sending domain and aren’t sure which name to enter.
- Your
Fromaddress uses a subdomain, and sending fails with “domain not verified” even though the root domain is verified. - Marketing complaints seem to be hurting delivery of receipts and password resets.
Cause
Emailit treats every domain and subdomain as a separate sending domain:
- Each one is verified on its own. Verifying
acme.comdoesn’t covernews.acme.com. The records go under the subdomain, for exampleemailit.news.acme.comandemailit._domainkey.news.acme.com. - The
Fromaddress must match exactly. Mail fromhello@news.acme.comneedsnews.acme.comverified. See Why does SMTP return 530 From domain not verified?. - Each one counts toward your plan’s domain limit. Pay as you go allows 3 domains (25 after your first credit purchase), Pro 100 and Business 1,000.
Mailbox providers build reputation for each domain, and partly for each subdomain. Mail from a subdomain still carries your brand, but a problem on news.acme.com affects acme.com less than if both shared one name.
Fix
-
Pick a layout. A common setup:
Mail Send from Receipts, sign-in codes, password resets acme.comormail.acme.comNewsletters and campaigns news.acme.comSmall senders with one kind of mail can simply use
acme.com. -
Add each domain you send from. In Email APIDomains, select Add domain and enter the exact name, without
http://orwww.. See Add a domain. -
Publish the records for each one. Every domain gets its own SPF, DKIM and return-path records. Then select Check DNS.
-
Cover DMARC. A subdomain follows the DMARC policy of your root domain unless it has its own
_dmarcrecord. Publishing_dmarc.acme.comcovers both. -
Restrict keys if you like. Create a Sending Only API key limited to one domain for each system, so a marketing tool can’t send as your transactional domain. See API keys.
On Pay as you go, a subdomain of a domain registered more than 30 days ago doesn’t need the new-domain review. See Why is my domain pending verification? and Domain limits.
Still stuck?
Contact support or ask in Discord if you want advice on a domain setup for your volume.