Loading the board
Loading the board
A DNS TXT record or a file on the site, what each one costs you, and the four mistakes that make a check fail.
Guides · published 28 September 2026
Anyone can type your domain into a form. A verification asks for something only a person with control of the domain can do: put a string somewhere on it that a stranger cannot. There are two usual places, and the choice between them is about who on your team can act today.
You add a TXT record at a name the service gives you, holding a token it generated. On this site that is _oust.yourdomain.com, holding a value that starts with oust-verify=.
DNS is the stronger proof, because adding a record means access to the registrar or the DNS host rather than to the website. It is also the slower one. A new record can take up to an hour to be visible everywhere, and nothing you do speeds that up. Add it, then come back.
You serve the token as plain text at a fixed path. Here it is https://yourdomain.com/.well-known/oust-verify, containing the token and nothing else.
This is the faster route and the one to pick when you can deploy but cannot reach DNS. It proves control of the website rather than the domain, which is a slightly weaker claim, and it is enough for most listings.
A check that fails almost always fails for one of these, and three of them look fine in a browser.
The file redirects. A framework that sends every unknown path to a pretty 404, or forces www, turns the token into a redirect. A proof has no reason to move, so a redirect is refused rather than followed.
The file is HTML. Serving the token inside a page means the response contains a document that happens to mention it. The check wants the token and nothing else.
The record is on the wrong name. Some DNS panels append the domain to whatever you type, so _oust.yourdomain.com becomes _oust.yourdomain.com.yourdomain.com. Enter _oust alone and let the panel complete it.
The token expired. Tokens are short-lived, 48 hours here. A record added a week later proves control of the domain against a string nobody is looking for any more. Start again and use the new token.
Domains change hands, so a proof is re-checked rather than kept forever. Here it holds for 90 days, after which the record has to still be there. Leaving it in place is the whole maintenance, and a TXT record costs nothing to keep. Deleting it after a successful check is the most common reason a listing quietly stops being verified.
On this board, proving ownership is free and separate from paying. It lets you correct your listing’s details, change its category and set a defence ceiling. It never changes what the listing has paid or where it ranks. Start at verify ownership.