# Why does SMTP return 530 From domain not verified?

> Fix "530 From/Sender domain is not verified for this workspace" and "API key is restricted to sending domain" errors from Emailit SMTP.

This article explains why the Emailit SMTP relay refuses a message after you send its content, and how to fix the `From` address or the API key so it's accepted.

## Symptoms

The relay accepts your login and recipients, then rejects the message after `DATA` with one of these replies:

- `530 From/Sender domain is not verified for this workspace. From: …`
- `530 API key is restricted to sending domain: acme.com. From/Sender address must use this domain. From: …`
- `550 Sending from this domain is paused`

The rejected attempt also appears under **Email API → Logs** with the source **SMTP** and the `DATA` command.

## Cause

Emailit decides the sending domain from the **`From` header** of your message, not from the envelope `MAIL FROM`. Every address in the `From` header must be on a domain that is verified in the same workspace as the API key. The message is rejected when:

- **The domain isn't added or isn't verified** in this workspace. A domain verified in a different workspace doesn't count.
- **The `From` uses a different subdomain.** `news.acme.com` and `acme.com` are separate domains, and each needs its own verification.
- **The domain lost verification.** Emailit re-checks DNS every day. If a required record disappears, sending stops until it passes again.
- **Your library sets a default `From`**, such as `root@localhost` or the server host name, because the app didn't set one.
- **The API key is restricted to one domain** and the `From` uses another. Sending Only keys can be limited to a single domain.
- **The domain is paused** because of a high bounce rate (the `550` reply). See [Sending health](/docs/deliverability/sending-health/).

## Fix

1. **Read the `From` value in the error.** The reply ends with the exact `From` header Emailit received. Check its domain, including any subdomain.

2. **Confirm the domain is verified.** Open **Email API → Domains**. The domain must show **Verified**. If it shows **Not verified**, select it, fix the records marked **Missing** or **Invalid**, and select **Check DNS**. See [Domain verification](/docs/domains/verification/).

3. **Add the domain if it's missing.** Add exactly the domain you send from. See [Add a domain](/docs/domains/add-a-domain/).

4. **Set the `From` address explicitly.** Configure your framework's default sender, for example `MAIL_FROM_ADDRESS=hello@acme.com` in Laravel or `DEFAULT_FROM_EMAIL` in Django.

5. **Check the API key's restriction.** In **Email API → API Keys**, open the key. If its scope shows **Sending Only** with a domain, either send from that domain or create a key for the other domain. See [API keys](/docs/developers/api-keys/).

6. **For a paused domain, contact support.** Paused domains are restored by the Emailit team after the bounce problem is fixed.

Domain matching ignores letter case, so `Hello@ACME.com` matches `acme.com`. For other reply codes, see [SMTP reply codes](/docs/dictionary/smtp-reply-codes/).

## Still stuck?

[Contact support](/contact/) or ask in [Discord](https://discord.emailit.com). Include the full `530` reply, the domain name and the API key's name.

---
Source: https://emailit.com/docs/kb/smtp-530-from-domain-not-verified/
