Skip to main content

Zone records · Verification · 5 minutes per service

How to add txt records for verification — Why a Verification Record Saves Perfectly and Still Never Verifies

The panel accepts it, the row appears in the list, and the service asking for it never sees a thing.

The short answer

A verification TXT record only counts if it exists in the zone your domain actually delegates to — so before anything else, look up the name's nameservers and edit there, because a record saved in any other panel is invisible to the world.

After that there are two things to get right: the host field, which different panels interpret differently, and the value, which must be pasted exactly as the service issued it.

By the Hosting & Domains team · Reviewed 24 August 2026

Beginner

Level assumed

Quick

Budget for it

4

Stages, start to finish

24/7

Support, at any hour

This is a five-minute job that regularly takes an afternoon, and almost always for one of two reasons. Both are about where the record ends up rather than what it says.

The same procedure covers every service that asks: search consoles, mail platforms, business listings, certificate authorities and single sign-on providers all use the same mechanism.

The record has to land where the name delegates

Domains commonly have three parties in the picture: the registrar holding the registration, the provider answering DNS, and the host serving the website. Only the middle one matters here. Run an NS lookup on the domain and edit the zone at whichever provider comes back.

The failure is completely silent. The panel saves the record, shows it in the list, and reports no error — because the panel has no way of knowing that nothing in the world consults it. Meanwhile the service you are verifying with queries the real nameservers, finds nothing, and tells you verification failed.

The host field is where panels disagree

Some panels want @ for the root of the domain, some want the field left blank, some want the full name typed out, and some quietly append your domain to whatever you enter. That last behaviour produces yourdomain.com.yourdomain.com, which is a perfectly valid name that nothing on earth is asking about.

In cPanel's Zone Editor the safe approach is to enter the name as the panel displays existing records — look at how the current rows are written and match them. Then verify from outside: a TXT lookup shows you the name the record actually landed on, which settles the argument in seconds.

One name, many TXT records — with one exception

A domain can hold as many TXT records as it needs. Verification tokens from half a dozen services sit alongside each other without interfering, and resolvers simply return all of them for the querying service to sift through.

SPF is the exception, and it is a hard one: exactly one SPF record per name. Publishing a second does not merge the two, it invalidates both, and mail authentication fails for every sender you have listed. If you need to authorise another sending service, edit the existing record to include it rather than adding a new one.

Then wait a short while, and do not tidy up afterwards

TXT records move quickly on hosted DNS with sensible TTLs — minutes rather than hours. Leave it a few minutes, press verify, and try a second time before you start suspecting a real fault, because most services cache a failed check briefly.

Once it verifies, leave the record alone. Plenty of services re-check quietly on a schedule, so a token removed during a tidy-up un-verifies the domain weeks later with nothing obvious to connect it to. Keep a note beside the zone saying which service each token belongs to, and delete only what you can account for.

Checking whether the name is still free before somebody else asks

Where these instructions were checked

Every walkthrough in this library is checked against the panel your account actually opens — cPanel's Zone Editor, the client area's domain settings, the same defaults on the same screens.

A free certificate comes with every plan and reissues itself before the old one lapses, so the padlock is never a date you have to keep in a diary.

  • Registry, registrar and DNS host kept apart
  • The record named before you go looking for it
  • Delegation and zone edits on one screen
  • People on the desk at any hour a name misbehaves

Why Hosting & Domains

Standard on every plan

The right zone found before the edit

An NS lookup first, because a record in the wrong panel fails silently and looks exactly like a record that worked.

The host-field trap named

@, blank or the full name — and the panel behaviour that turns your domain into yourdomain.com.yourdomain.com.

The one-SPF rule spelled out

Unlimited TXT records, except SPF, where a second one breaks authentication for every sender you had listed.

Verified from outside

A TXT lookup shows the name the record actually landed on, which settles most disputes in seconds.

Old tokens left where they are

Services re-verify on a schedule, so the guide explains why tidying the zone is how integrations die.

The same five minutes every time

One procedure covering search consoles, mail platforms, listings and certificate authorities alike.

Quick Start

Order placed to site online

  1. 1

    Find out which nameservers answer for the name

    Run an NS lookup on the domain. Whichever provider comes back is the only place a record will ever be read. Editing anywhere else produces a row that saves without complaint and is never seen.

  2. 2

    Take the token exactly as issued

    Copy the whole string from the service's page, prefix included — google-site-verification= and the code, or whatever the equivalent is. No trimming, no retyping, no helpful capitalisation.

  3. 3

    Add the TXT record and match the panel's convention

    In Zone Editor, choose Add TXT and write the host the way the existing rows are written, usually @ or blank for the root. Paste the value and save, leaving the TTL low for now.

  4. 4

    Confirm it from outside, then press verify twice

    Query the TXT record with dig or an external lookup and read the exact name it came back on. Then verify at the service, and try once more a few minutes later before assuming something is wrong.

Built In

Fitted to every plan

  • Full zone control — A, CNAME, MX and TXT — from the panel
  • Free SSL on every plan, reissued before the old certificate lapses
  • Mailboxes that answer at the name you hold
  • Spam and virus screening in front of every mailbox at your name
  • cPanel, which is what most of the industry already runs
  • A daily copy, with restores you run yourself from the panel
  • People on the support desk every hour of every day
  • No set-up charge at any point, and no joining fee
  • PHP versions set per site from the control panel
  • Money back within 30 days on hosting plans, 7 on reseller

Frequently Asked

Questions we field again and again

Do I put the record on @, on blank, or on the full domain?

Whichever your panel uses for the records already in the zone — look at how the existing rows are written and match them. Then confirm with an external TXT lookup, which shows the name the record actually landed on and exposes any panel that has appended your domain a second time.

Can I have two SPF records if I use two mail services?

No. Exactly one SPF record per name: a second does not add to the first, it invalidates both and mail authentication then fails for every sender you had authorised. Add the second service into the existing record instead, using its published include mechanism.

How do I see what TXT records the rest of the world can read?

Query them directly — dig TXT yourdomain.com, nslookup -type=txt yourdomain.com, or any external lookup tool. That returns what the authoritative nameservers are publishing, which is the only view that matters. Your own panel shows what you intended, which is not the same thing.

The service still says unverified an hour later. What now?

Check two things in this order: that the zone you edited is the one the domain delegates to, and that the host field has not duplicated the domain name. Between them those account for nearly every case. If both are right, the record is visible and the service simply needs pressing again.

Keep reading

  • Plesk Reseller Hosting

    Reseller plans where each client's zone and verification records stay properly separated.

  • Secure Hosting

    Hardened hosting for names carrying data you would rather not explain losing.

Changing provider? Work through this checklist beforehand.

A straightforward running order for a migration your visitors never spot: which files travel first, how to bring the mail across without dropping a single message, the right moment to repoint DNS, and the two errors that sit behind almost every outage we get called in to fix.

You get the checklist, followed now and then by a note on keeping a site responsive. Unsubscribe whenever you want; the privacy policy covers the rest.

Records that the world can actually see.

Free SSL, a free migration, full zone control from the panel, and support that answers while the change is still landing.

View Plesk Reseller Hosting plans