Verifying a domain proves your organization controls it — once done, colleagues signing in with an address on that domain can ask to join, and your sign-in connections can accept the domain automatically.
Overview
- Verification uses a one-off DNS record — nothing happens until it's in place.
- An unverified domain grants no access at all.
- Once verified, the domain can be used to let colleagues join and to simplify sign-in restrictions.
Verify a domain
- Go to Settings → Sign-in → Verified domains.
- Type the domain (for example
acme.com) and choose Add domain. - You'll see the exact record to create:
- Type: TXT
- Host:
_infranest-challenge.acme.com - Value: a code unique to you
- Create that record at whoever runs your DNS, then choose Check now.
NoteDNS changes take a few minutes to spread, so "not found yet" on the first check is normal. We keep checking in the background and the domain flips to Verified on its own.
If your DNS is already here
When the domain sits in a DNS zone you manage in InfraNest, you don't have to touch anything — the panel says so and offers Add it for me. We create the record and start checking.
If the zone is here but connected read-only, we'll say that too — add the record at your provider instead, or connect the provider so we can write to it.
Invite colleagues who already have an account
- Once a domain is verified, check for people on it who already have an account but aren't members of your organization.
- Choose Invite them — each person gets a normal invitation to accept.
WarningThis is never automatic. Verifying a domain does not pull existing accounts into your organization, and it never moves anyone out of an organization they're already in.
What a verified domain is used for
- Joining. Depending on your connection's setting, someone signing in with an address on the domain can request to join.
- Restricting sign-in. A connection can accept "our verified domains" instead of a list you maintain by hand.
Exact matches only: verifying acme.com does not cover mail.acme.com. Verify that separately if you need it.
Keeping it verified
We re-check verified domains periodically. If the TXT record disappears, we don't drop the domain immediately — a single failed lookup is usually a DNS hiccup, not a lost domain. It's only withdrawn after the record has been missing for a while, and that's recorded in your Audit Log.
Leave the record in place. Its description in your DNS says the same.
Remove a domain
- Remove it from the list at any time.
- If we created the TXT record for you, we clean it up too.
Anything you added by hand stays — we don't delete records we didn't create.
Troubleshooting
"That domain is already claimed." A domain can belong to only one organization, so nobody can claim yours. If you believe it's yours, contact support.
It never verifies. Check the host is the full _infranest-challenge.<your domain> — some DNS providers add the domain automatically, which can produce a doubled name. Then confirm the value matches exactly.
Was this article helpful?