Skip to main content
Five steps. Four of them are yours and take about three minutes; the last one is DNS, and how long it takes is not up to either of us.

Type your domain

You do not need an account for this part. ownsi reads your zone straight away and tells you who answers for the name — Cloudflare, Route 53, GoDaddy, whoever — so the instructions you get next use your panel’s own wording instead of generic ones.Type it however you have it. HTTPS://WWW.Acme.com/pricing becomes acme.com, and ownsi says what it changed rather than quietly reading something else.More about what it reads before you sign in.

Sign in

A magic link to your email, or Google.No token exists before this point, on purpose. A token belongs to an account, so nothing is ever issued that you might have to redo once you sign in.

Create the record

ownsi gives you exactly one record to create:
Put only _ownsi-challenge in the Host field. Almost every panel adds your domain to whatever you type, so entering the full name produces _ownsi-challenge.acme.com.acme.com — the single most common mistake, and its own named failure, domain_appended.
No quotes around the value, no trailing spaces. If your panel adds quotes when it saves, that has a name too, and the fix is to retype it: value_formatted.More about the record, and why it is safe to leave in place.

Wait

Nothing else is asked of you. ownsi checks on its own schedule, derived from your provider and from your zone, and it keeps checking until it finds the token or the window closes.While it waits, the screen says one of two things and never both: how much longer the wait should be, or what is wrong with the record. If you are looking at it now and it does not say proved, start here.

Proved

You get a dated attestation: “on 15 June, this account demonstrated control of acme.com’s DNS zone.”It is yours and it is private. Nothing about it is public until you publish a link, and you can take that link back afterwards.You can delete the TXT record now if you want to. The proof does not depend on it — here is why.

How long it should take

Usually minutes. Two things are running:
  • Your provider publishing the edit to its own nameservers. Cloudflare is often under a minute; some registrars take longer.
  • Resolvers forgetting that the name did not exist. If anything asked for that name before you created it — including ownsi’s own first check — the “does not exist” answer is cached for a set time and repeated until it expires.
ownsi reads both numbers off your zone and shows you the real one instead of “up to 72 hours”.
A claim stays open for seven days. If it closes without a proof, nothing is lost: claim the domain again and, because the record is already in the right place, you change one value rather than starting over. Expiry and starting again.

Doing this from code

The whole flow is four HTTP calls, and they are documented — but the API is not open yet, so today they answer only the product’s own session. The four calls, in order.