The token looks like
ownsi_v1_9f3a2c8d1e4b7a6053c21f8e4d7b0a95. It is yours, it is random, and it
is never reused across accounts or across claims.

Each value copies with one click. When ownsi recognises your provider, the field labels change to the ones that provider uses.
Put only the label in the Host field
This is where nearly everyone loses twenty minutes, so it is worth being explicit. The record’s full name is_ownsi-challenge.acme.com. But almost every DNS panel adds your domain
to whatever you type in the Host field, which means typing the full name gets you
_ownsi-challenge.acme.com.acme.com — a real record, in the wrong place, that no check will ever
find.
It has its own named failure, domain_appended, precisely
because it is so common — the diagnosis names the record you actually created rather than reporting
that nothing was found.
The value has to be exact
No quotes around it, no spaces before or after, nothing appended. Some panels wrap TXT values in quotes when they save. That is common enough to have its own name,value_formatted, rather than being reported as “not
found” — the record is there, it just does not carry what you meant it to. The fix is to retype the
value.
Why the name starts with an underscore
An underscore is not legal in a hostname (RFC 1123), so_ownsi-challenge cannot collide with
anything. No web server, mail record or CDN target will ever want that name.
That is the point: the record can stay in your zone forever without getting in the way. ownsi
never asks you to remove it, and you can if you want to.
Other records on that name are fine
_ownsi-challenge can carry several TXT records and ownsi looks for its token among them. It never
asks you to delete anything.
If the name has records but none of them is your token, that is
no_matching_record, and the diagnosis tells you how
many are there.
The token does not change under you
For as long as the claim is open, the token you were first shown is the token that verifies.
Re-checking never rotates it.
expired_token — so starting again means
changing one value in a record that is already in the right place, not working out where it goes
from scratch.