Skip to main content
Claiming a domain gives you a token and exactly one record to create. Three fields: The token looks like ownsi_v1_9f3a2c8d1e4b7a6053c21f8e4d7b0a95. It is yours, it is random, and it is never reused across accounts or across claims.
The record card in ownsi, listing Type TXT, Host _ownsi-challenge, the token as the Value, and TTL Auto, each with a copy button.

Each value copies with one click. When ownsi recognises your provider, the field labels change to the ones that provider uses.

Put only the label in the Host field

This is where nearly everyone loses twenty minutes, so it is worth being explicit. The record’s full name is _ownsi-challenge.acme.com. But almost every DNS panel adds your domain to whatever you type in the Host field, which means typing the full name gets you _ownsi-challenge.acme.com.acme.com — a real record, in the wrong place, that no check will ever find.
Type _ownsi-challenge and nothing else. If your panel is one of the few that wants the full name, it will say so, and ownsi shows you that form too.
It has its own named failure, domain_appended, precisely because it is so common — the diagnosis names the record you actually created rather than reporting that nothing was found.

The value has to be exact

No quotes around it, no spaces before or after, nothing appended. Some panels wrap TXT values in quotes when they save. That is common enough to have its own name, value_formatted, rather than being reported as “not found” — the record is there, it just does not carry what you meant it to. The fix is to retype the value.

Why the name starts with an underscore

An underscore is not legal in a hostname (RFC 1123), so _ownsi-challenge cannot collide with anything. No web server, mail record or CDN target will ever want that name. That is the point: the record can stay in your zone forever without getting in the way. ownsi never asks you to remove it, and you can if you want to.
One exception. A name holding a CNAME can hold nothing else (RFC 1034). If _ownsi-challenge is already a CNAME — some platforms create one for their own verification — your TXT record will silently not exist. That is cname_conflict.

Other records on that name are fine

_ownsi-challenge can carry several TXT records and ownsi looks for its token among them. It never asks you to delete anything. If the name has records but none of them is your token, that is no_matching_record, and the diagnosis tells you how many are there.

The token does not change under you

For as long as the claim is open, the token you were first shown is the token that verifies. Re-checking never rotates it.
It does not outlive the claim, though. A claim ends when it is proved, cancelled, or when its seven-day window closes, and an ended claim’s token stops being accepted. Prove the same domain again later and you get a new token. That is not a reason to delete the old record. The next check finds the previous token sitting there and says so — expired_token — so starting again means changing one value in a record that is already in the right place, not working out where it goes from scratch.

After you are proved

Nothing depends on the record any more. Leave it or delete it; the proof keeps its date either way, and nothing is re-checked. Leaving it is slightly kinder to your future self, for the reason above. That holds even if you later sell the name — selling asks nothing of you either.