Skip to main content
Your proof is private until you decide otherwise. Proving a domain publishes nothing, and your list of domains is yours. The only thing that ever reaches a stranger is a link you chose to hand them.

Publishing one

You get a short link like ownsi.dev/p/8f2k91mx4c. Anyone with it can open it; nobody without it can find it. The link has its own random slug. It is never your DNS token — that stays between your account and your zone, and on an ended claim it proves nothing anyway. Ask for a link twice and you get the same one back rather than collecting duplicates. There is one address per proof, and it stays that address.

What the person sees

What is on the page

The domain, the date it was proved, the masked address of the account that earned it (m•••@acme.com), the DNS provider, and the token that was found.

What it does not do

It runs no DNS query when someone opens it. It reads one stored row and prints what that row says — so it states the same thing today as the day you published it.
A published ownsi proof page showing the domain acme.demo.ownsi.dev, the masked account that holds it, the date it was proved, the provider, the token, a QR code, and the dig command that reads the same record.

What opens on the other end. The address under the QR code is the link itself.

That last part is the whole idea. The proof is a fact about a moment, so the record that earned it may well be gone by the time somebody reads the page, and nothing about the page changes when it is. Whoever you send it to can check the DNS themselves if they want. The page shows them the exact command. The page also says whether a later proof of the same name exists — a fact about the name, not about your proof, and it takes nothing away from it. There is a badge too, at /p/:slug/badge.svg, for a README. Once published, it resolves until you take it back. Nothing about it expires on a clock. Expiry belongs to the other side of the claim: a claim that was never proved in time expires, because it was a question with a deadline. A proof answers the question, and the answer is about a moment that has already happened. A timer on the share would say nothing about the proof, so there is not one. That is what makes the address safe to paste somewhere permanent — a README, a site footer, an email signature.

Taking one back

Revoking a link stops that slug resolving, immediately. What it does not do:
  • your proof keeps its date, and your domain still reads as proved;
  • you can publish a new link a second later, and it gets its own slug;
  • the old slug stays dead, permanently.
Someone opening a revoked link is told the link is no longer available, and nothing about the domain behind it. A slug nobody ever published looks the same as one that never existed.
Every link you have published is listed, the revoked ones included. What has been shared is part of the record, and hiding it from you would not un-share it.
Archiving the domain revokes every link published from it, in the same act. Saying “I am not working on this name any more” and leaving its address resolving for strangers are two different things, and archiving means the first. The proof is untouched — the claim keeps its state and its date — and putting the domain back does not bring the old slug back. Publish a new link, and it gets its own. Deleting the domain is the eraser: the domain, its claims and every link hanging off them go, permanently, and no record of what was shared survives it. Neither rests on a revocation having landed. The page reads the claim behind the slug on every open, so a link cannot outlive the decision to publish it — one that escaped its revocation reads as taken back all the same. A page already served is cached for five minutes, which is the longest a revoked link can still be on a reader’s screen.