Skip to main content
Domain verification is a part of the Single Sign-On(SSO) configuration process. It lets your organization claim ownership of a domain, such as example.com. After a domain is verified, Profound can trust it for features that need a higher level of security, starting with Single Sign-On (SSO). Verification is self-serve. You add a single DNS TXT record containing a token that Profound generates for your organization. Profound checks your DNS for the record and marks the domain as Verified when it finds it. You don’t need to change your website, mail setup, or other DNS records.

How it works

  1. You enter the domain you want to verify in the SSO configuration portal.
  2. Profound generates a unique verification token for that domain and shows you the TXT record to add. When it recognizes your DNS provider, it also shows provider-specific instructions.
  3. You add the TXT record in your DNS provider’s console, alongside any records already on the host.
  4. Profound looks up the domain’s TXT records. When it finds the token, the domain becomes Verified and you can continue with the rest of your SSO configuration.
The token proves ownership because only someone with control over the domain’s DNS can publish it. Profound compares the email domain of each user who signs in with SSO against your verified domains, so verification also confirms which users belong to your organization.

Before you start

You’ll need:
  • The Admin role in your Profound organization
  • Access to the DNS records for the domain you want to verify (or an IT contact who has it)
  • The domain that appears in your users’ email addresses. For example, if your team signs in with name@example.com, verify example.com, even if your identity provider runs at example.myidp.com

Verify a domain

1

Open the SSO configuration portal

  1. In Profound, select your organization name at the top left of the screen, then select Settings.
  2. Select Enterprise Setup under Organization in the left navigation sidebar. The Single Sign-On card lists your domains and their verification status.
  3. Select Add domain, and the SSO configuration portal opens on the domain verification step. Enterprise Setup page screenshot showing the Single Sign-On card with the Add domain button highlighted
2

Enter your domain

Enter the domain you want to verify and select Continue.Verify your organization domain screen in the portal with the Enter your domain field and Continue buttonThe portal detects your DNS provider and takes you to the setup instructions specific to it.Add DNS records screen in the portal showing provider-specific instructions for Cloudflare, starting with signing in to the Cloudflare dashboard
3

Get the TXT record from the portal

The portal generates a verification token and shows the TXT record to add: the Host (or Name) and the Value that contains the token.TXT record details in the portal: type TXT, host @, and a value beginning with profound-, each with a copy button
4

Add the TXT record in your DNS provider

Sign in to your DNS provider (for example, Cloudflare, GoDaddy, Route 53, or Squarespace Domains) and create a new TXT record with the host and value shown in the portal. Leave the time to live (TTL) at your provider’s default.Keep any existing TXT records on the same host, such as the Sender Policy Framework (SPF) record, or other verification records from other services. Add the new record next to them instead of replacing them.If someone else manages your DNS, copy the host and value from the portal and send them to that person. They don’t need a Profound account to add the record.
5

Wait for Profound to detect the record

Return to the SSO configuration portal and select the option to check the record, or select Check status on the Enterprise Setup page. When Profound finds the token, the domain status changes to Verified.Enterprise Setup page screenshot showing the domain marked Verified and the Check status button highlightedDNS changes usually appear within 15 to 30 minutes and can take up to 48 hours to take effect. If the domain still appears as Pending on the Single Sign-On card in Profound, leave the record in place and check back later.
After the domain is verified, continue with the Configure SSO guide to connect your identity provider.

Verify multiple domains

Each domain gets its own verification token, so repeat the domain verification steps for every domain your users sign in with. Add each TXT record to the domain it was issued for. For example, a record issued for www.example.com belongs on www.example.com, and example.com needs the separate record issued for example.com. Each subdomain needs its own verification. Verifying example.com doesn’t verify mail.example.com, and each subdomain also needs its own SSO connection.

Keep the record in place

Keep the verification TXT record in your DNS for as long as you use SSO with that domain. Profound rechecks the record periodically. If the record is removed or changed, the domain returns to Pending and sign-in through your identity provider stops working until the record is restored.

Troubleshooting

Confirm you added the record as a TXT record on the correct host and that the value matches the token in the portal, including any prefix. Then allow up to 48 hours for DNS propagation and select Check status again. If after 48 hours your domain verification is still pending, contact customer support.
in many DNS consoles, the Host or Name field is relative to your domain, so entering example.com there creates a record for example.com.example.com. When the portal asks for a host of example.com, enter @ or leave the field blank instead. Both mean the domain itself.
If the domain verification token has changed, remove the old TXT record from your DNS provider, and add the new one as instructed in the domain verification guide above.