Verify a domain with a TXT record
Add the TXT record a service asks for to an Edge DNS zone in Azion Console, the Azion CLI, or the API, then check it at Azion's nameservers.
You can verify a domain with a TXT record in Edge DNS from Azion Console, the Azion CLI, or the Azion API. A service that asks you to prove control of a domain gives you a value, then reads it back from the domain’s DNS. To validate a certificate that Azion requests for a workload, refer to Issuance and renewal instead.
Select your interface once. The prerequisites and the task below show only that path.
Prerequisites
- A zone in Edge DNS for the domain. To create one, refer to Create, edit, or delete a zone.
- The value the service asks you to publish, and the record name if it gives one.
- The domain delegated to Azion’s nameservers, so the service can read the record. Refer to Migrate nameservers to Azion.
- Access to Azion Console. To sign in, refer to Access Azion Console.
Add the TXT record
Add the record at @, the root domain, unless the service names another record. Record names are relative to the zone: for <name>.example.com, enter only <name>. The example below adds the value verification-token-abc123 at @; replace it with the value the service gave you.
To add the record with the Azion CLI, save the record as txt.json:
Then create the record from the file. Replace <zone-id> with the ID of your zone:
The command prints the ID of the record:
The zone holds the TXT record. The file keeps the value intact: --rdata reads its argument as a comma-separated list, so pass a value through --rdata only when it contains neither a comma nor a double quote.
A TXT value holds up to 1,000 characters. If the name already holds a TXT record, a second one is refused with 19004 Record Already Exists. Add the value as another line of the existing record instead, as in Add, edit, or delete a record. For every TXT rule, refer to Record types.
Check the record at Azion’s nameservers
Before the service checks the domain, ask Azion’s nameserver directly, without your resolver’s cache. This check needs no interface choice.
To query ns1.aziondns.net for the TXT record at @, replace example.com with your domain:
The nameserver returns each value of the record in double quotes:
If the command prints nothing, wait a few minutes and run it again. A change to an existing record can take a few minutes to reach every nameserver. If the name was queried before its record existed, the nameserver can return an empty answer or NXDOMAIN for up to one hour. For that case, refer to A new record returns NXDOMAIN.
When ns1.aziondns.net returns your value, ask the service to check the domain. Until the registrar delegates the domain to Azion’s nameservers, a public resolver finds no delegation to Azion, and the service cannot read the record.