---
name: azion-verify-a-domain-with-a-txt-record
description: >-
  Add the TXT record a service asks for to an Edge DNS zone in Azion Console, the Azion CLI, or the API, then check it at Azion's nameservers.
---

# Verify a domain with a TXT record

You can verify a domain with a TXT record in [Edge DNS](/en/documentation/platform/edge-dns/) from Azion Console, the Azion CLI, or the Azion API. A service that asks you to prove control of a domain gives you a value, then reads it back from the domain's DNS. To validate a certificate that Azion requests for a workload, refer to [Issuance and renewal](/en/documentation/platform/workloads/certificate-manager/issuance-and-renewal/#domain-validation) instead.

---

Select your interface once. The prerequisites and the task below show only that path.

## Prerequisites

- A zone in Edge DNS for the domain. To create one, refer to [Create, edit, or delete a zone](/en/documentation/guides/application-security/dns/edge-dns-configure-main-settings/).
- The value the service asks you to publish, and the record name if it gives one.
- The domain delegated to Azion's nameservers, so the service can read the record. Refer to [Migrate nameservers to Azion](/en/documentation/guides/platform/migration/migrate-ns-to-azion/).

**Console**

- Access to Azion Console. To sign in, refer to [Access Azion Console](/en/documentation/guides/platform/account-and-billing/how-to-access-azion-console/).

**CLI**

- The [Azion CLI](/en/documentation/devtools/cli/) installed and authorized.

**API**

- A [personal token](/en/documentation/guides/platform/account-and-billing/personal-tokens/) and `curl`.

---

## Add the TXT record

Add the record at `@`, the root domain, unless the service names another record. Record names are relative to the zone: for `<name>.example.com`, enter only `<name>`. The example below adds the value `verification-token-abc123` at `@`; replace it with the value the service gave you.

**Console**

To add the record in Azion Console:

1. **Open the Edge DNS page**

   Access [Azion Console](https://console.azion.com/) > **Edge DNS**.

2. **Open the zone's records**

   On the **Zones** page, select the row of the zone, then select the **Records** tab.

3. **Select + Record**

   The **Create Record** drawer opens.

4. **Enter the record name**

   In **Name**, enter `@`, or the name the service asks for without your domain. The Console adds the domain for you.

5. **Select the TXT record type**

   In **Record Type**, select *TXT - Text*.

6. **Keep the TTL**

   Keep **TTL (seconds)** at `3600`.

7. **Enter the value**

   In **Value**, enter the value the service gave you, on one line.

8. **Select Save**

The Console shows `Edge DNS Record has been created`, and the TXT record appears in the **Records** table.

**CLI**

To add the record with the Azion CLI, save the record as `txt.json`:

```json
{"name":"@","type":"TXT","rdata":["verification-token-abc123"],"ttl":3600}
```

Then create the record from the file. Replace `<zone-id>` with the ID of your zone:

```bash
azion create dns-record --zone-id <zone-id> --file txt.json
```

The command prints the ID of the record:

```text
Created DNS record with ID 100790
```

The zone holds the TXT record. The file keeps the value intact: `--rdata` reads its argument as a comma-separated list, so pass a value through `--rdata` only when it contains neither a comma nor a double quote.

**API**

To add the record with the Azion API, send a `POST` request to the zone's records endpoint. Replace `<zone-id>` with the `id` of your zone and `[TOKEN VALUE]` with your personal token:

```bash
curl -X POST https://api.azion.com/v4/workspace/dns/zones/<zone-id>/records \
  -H "Authorization: Token [TOKEN VALUE]" \
  -H "Content-Type: application/json" \
  -d '{"name":"@","type":"TXT","rdata":["verification-token-abc123"],"ttl":3600}'
```

A `201` returns the record:

```json
{
  "state": "executed",
  "data": {
    "id": 100791,
    "description": "",
    "name": "@",
    "ttl": 3600,
    "type": "TXT",
    "rdata": ["verification-token-abc123"],
    "policy": "simple",
    "weight": 255
  }
}
```

The zone holds the TXT record. Never include the domain in `name`: Edge DNS adds it.

A TXT value holds up to 1,000 characters. If the name already holds a TXT record, a second one is refused with `19004` `Record Already Exists`. Add the value as another line of the existing record instead, as in [Add, edit, or delete a record](/en/documentation/guides/application-security/dns/add-records/). For every TXT rule, refer to [Record types](/en/documentation/platform/edge-dns/record-types/#txt).

---

## Check the record at Azion's nameservers

Before the service checks the domain, ask Azion's nameserver directly, without your resolver's cache. This check needs no interface choice.

> **Caution**
>
> Query a name only after you save its record. A name queried before its record exists is answered `NXDOMAIN` for up to one hour, the SOA minimum, even after you add the record.

To query `ns1.aziondns.net` for the TXT record at `@`, replace `example.com` with your domain:

```bash
dig +short @ns1.aziondns.net example.com TXT
```

The nameserver returns each value of the record in double quotes:

```text
"verification-token-abc123"
```

If the command prints nothing, wait a few minutes and run it again. A change to an existing record can take a few minutes to reach every nameserver. If the name was queried before its record existed, the nameserver can return an empty answer or `NXDOMAIN` for up to one hour. For that case, refer to [A new record returns NXDOMAIN](/en/documentation/platform/edge-dns/troubleshooting/#a-new-record-returns-nxdomain).

When `ns1.aziondns.net` returns your value, ask the service to check the domain. Until the registrar delegates the domain to Azion's nameservers, a public resolver finds no delegation to Azion, and the service cannot read the record.

---

## Next steps

- [Add, edit, or delete a record](/en/documentation/guides/application-security/dns/add-records.md): Change the value or remove the record when the service no longer needs it.
- [Record types](/en/documentation/platform/edge-dns/record-types.md#txt): The format and rules of a TXT value.
- [Migrate nameservers to Azion](/en/documentation/guides/platform/migration/migrate-ns-to-azion.md): Delegate the domain so the service can read the record.
- [Query a zone with dig](/en/documentation/guides/application-security/dns/run-the-dig-command.md): Compare the answer of Azion's nameservers with a public resolver.
