Skip to main content
You created the TXT record, you came back, and the screen still does not say proved. There are only two reasons for that, and ownsi always tells you which one you are in.

You are early

Nothing is wrong. The record is correct and the internet has not caught up with it. There is nothing to fix and nothing to press.

Something needs changing

The record exists, but not in the way a check can find it. This always comes with a named reason and one specific thing to change.
Telling those two apart is the whole job. Being told to fix a record that is already correct is the most common way these flows waste a day.
The ownership verification panel in ownsi: DNS connected, TXT not found, Token, above a message explaining that the nameservers answer but do not serve the record yet.

The rail says which of the three questions failed. The message under it names the cause and the one thing to change.

If you are early

DNS is not one system, it is thousands of caches, and a new record reaches them at different times. ownsi shows you a wait with a real number on it rather than “up to 72 hours”, because the two things you are waiting on can both be measured: The second one surprises people. It is the reason a record you can see in your panel, and even see with dig against your own nameservers, still comes back missing everywhere else. Nothing is broken. The clock is the fix, and ownsi tells you how much of it is left.
Pressing “check again” does not make DNS answer sooner. ownsi already knows when the wait ends and schedules itself for then.

If something needs changing

Then ownsi names it. Every problem it can recognise has a code, one sentence saying what is actually true right now, and one sentence saying what to change — with your domain and your token in them, not a generic template. For example:
The token is on acme.com itself, not on _ownsi-challenge.acme.com. Move the record to the _ownsi-challenge host and leave the records on acme.com alone.
There are thirteen of these. The full list, with the cause and the fix for each, is here.

They fall into three families

The record needs an edit

domain_appended · record_at_apex · value_formatted · record_on_www · no_matching_record · record_absent · cname_conflict · expired_tokenSomething you can fix in your panel in under a minute.

Nothing to do but wait

negative_cache · not_publishedThe record is right. These are the two waits above, named.

Not about your record

servfail · lame_delegation · foreign_tokenA real problem, but with your DNS provider or with another account. Retyping the record will not help.

The one that catches almost everyone

domain_appended. You typed the full name into the Host field, and your panel added the domain to it again, so the record landed on _ownsi-challenge.acme.com.acme.com. Nearly every DNS panel does this. Put only _ownsi-challenge in the Host field and let the panel add the rest — more about the record and the fields it goes in.

The wording changes, the codes do not

The sentences on these pages are product copy and we improve them. The code beside each one is an identifier and will not be reworded, so if you are keeping notes or writing anything that reacts to a case, key it off the code. Building against this? Diagnosis Payload has the field shapes.