DocsYour apps

Confirm your domain

Pick your DNS provider: approve one record there, or add it yourself in three steps.

Needs an accountUpdated
On this page

In short

  • One TXT record on your domain proves the app is yours. With a paid plan, the app then gets the close watch: reachability every five minutes instead of once a day.
  • You pick where your domain's DNS is managed. Where that provider has approved Vallit, you allow the record on its own page with one click. Everywhere else, you add it by hand in three steps.
  • It needs an account and access to your domain's DNS settings.

Where in the app

Until the domain is confirmed, the app's page lists Confirm you own and the address under Needs you. Confirm now in that row opens the Connect your DNS panel in place.

An app's page with the Confirm you own example.org row open under Needs you, and the Connect your DNS panel below it ringed.

Step by step

Steps 3, 4 and 5 are three ways to add the same record. Follow the one the panel offers you.

The Connect your DNS panel with the record added by hand: the provider tiles (2), the record to copy (4), the Cloudflare token option (5) and the Look for the record button (6). The one-click button (3) appears only for a provider that supports it.

One click turns on provider by provider. Vallit can offer it at Cloudflare, GoDaddy, IONOS and Vercel, each once that provider approves Vallit. As of September 2026, none has approved yet, so every domain gets step 4, or step 5 at Cloudflare. At Namecheap, Netlify, Strato, Hetzner and other providers, you add the record by hand.

  1. Open the panel

    On Home, while no incident is open, the panel is the Next card, titled Confirm you own and the address. On the app's page, click Confirm now in the Confirm you own row under Needs you. The Connect your DNS panel opens under the row, and the button now reads Close. Add the record in the Inbox opens the app's page with the panel already open.

  2. Pick where your DNS is managed

    Vallit looks up your domain's DNS provider and selects its tile. The tile is marked One click where one click works, and Your DNS everywhere else. If no tile or the wrong one is selected, click the right one. For a provider not listed, click Somewhere else.

  3. Approve the record at your provider

    If the selected tile says One click, the panel shows a card with a button that names your provider, such as Continue to GoDaddy. Click it, and the button reads Opening GoDaddy until your provider's page opens and asks you to allow one record. Approve it, and you are back on the app's page, where Vallit looks the record up.

  4. Or add the record by hand

    Otherwise, the panel lists three lines for your provider. For a listed provider, a button such as Open Namecheap opens its DNS settings. On the one-click card, Add it by hand instead shows the same lines.

    Add a record of type TXT. Copy the name and Value from the table with the copy buttons beside them, and save. The name's label is your provider's own word for the field, listed below. For Somewhere else, the steps also give the whole name, for forms that want it.

    Pointing at a copy button shows what it copies, to its left. When you press it, the second sheet of its icon slides off the first. The button then turns green with a check, and the value you copied lights up green for a moment. If your browser does not let the page copy, a line under the table starts with Not copied. The text is selected for you: copy it with your keyboard.

    ProviderWhere to add the recordThe name field is called
    CloudflareYour domain → DNS → Records → Add recordName
    GoDaddyYour domain → DNS → Add new record. The TTL can stay.Name
    IONOSYour domain → DNS → Add recordHost name
    VercelDomains → your domain → add a recordName
    NamecheapManage → Advanced DNS → Add new record, then save all changesHost
    NetlifyDomains → your domain → Add new recordName
    StratoDomains → your domain → DNS settings → TXT recordsPrefix
    HetznerThe zone of your domain → Add recordName
    Somewhere elseWherever your domain is managed, its DNS recordsName, or the whole name

    Once the record is saved at your provider, go on to step 6.

  5. Or let Vallit add it at Cloudflare

    With Cloudflare selected, open Or let Vallit add it with a Cloudflare token under the record. Create a token opens Cloudflare's token page with DNS Edit already ticked. Create the token for your domain's zone, Cloudflare's word for a domain, and copy it.

    Paste it into Cloudflare API token and click Add the record. Vallit adds the record and looks it up straight away. If the record needs a moment, the panel says Record added at Cloudflare. It usually shows up within a minute; checking again.

  6. Look for the record

    Click Look for the record at the bottom of the panel. The button reads Looking while Vallit looks the record up, and if it is not there yet, the panel says why. While the one-click card shows, the button stays hidden. It appears once your provider sends you back with the record added.

    After steps 3 and 5, Vallit checks by itself, and once more a few seconds later if the record needs a moment.

  7. See the result

    Once the record is found, the row and its panel leave Needs you, and the page shows Domain confirmed. once. The line under it says whether the close watch is on, or that a plan turns it on. In the Settings card, Domain now reads Confirmed by DNS record, with the date.

What happens behind the scenes

  • The record is a TXT record named _vallit in front of your app's address, for example _vallit.myapp.com. Its value starts with vallit-verification=, followed by a code made for this app.
  • For an app on a subdomain, the name keeps the subdomain. For shop.myapp.com, the provider form wants _vallit.shop.
  • To confirm the domain, Vallit looks up that one name in public DNS and compares the value with the code.
  • To select a tile, Vallit reads which name servers answer for your domain. It also asks that provider's public Domain Connect service, the open standard behind one click, whether it knows Vallit. Neither changes anything.
  • Netlify's name servers are shared with other companies, so Vallit never selects Netlify for you. Pick its tile yourself.
  • One click sends you to your provider with a signed request for the one record in Vallit's published template. Vallit never signs in to your provider, and the provider adds the record only after you approve it.
  • The request lasts 15 minutes and belongs to your Vallit sign-in in that browser. Coming back confirms nothing by itself: Vallit looks the record up in public DNS, as Look for the record does.
  • With a Cloudflare token, Vallit makes three calls: it checks the token, finds the zone and adds the one record. The record carries the comment Vallit domain verification.
  • The token is used only for those three calls. It is not stored, not logged and never shown back.
  • Once the domain is confirmed, it stays confirmed. Vallit does not look the record up again.

Confirming the domain changes these things for the app:

  • Findings of the targeted checks show where they sit, what they let a person do and how to fix them, on every report of the app at once. Before, they show only their severity, category and title.
  • The daily full check of an app on Free includes the targeted checks, such as the search for left-over backup files and open folders. On Watch and Care it ran them already.
  • With a paid plan, reachability is checked every five minutes instead of once a day, and the response-time chart in the Guardian card fills in. The guardian has the full schedule.
  • The app can show as Healthy on Home once a report with every check scores 85 or more. Until the next daily check has run the targeted checks, such a score shows as Partly checked. The report's line under the waiting checks then says Waiting: the domain is confirmed now, so the next check runs these.

Give the Cloudflare token access to this one zone only. Vallit does not keep it, so you can delete it at Cloudflare once the domain is confirmed.

If something goes wrong

When you copy the record

What you seeWhat it meansWhat to do
Not copied. The text is selected: copy it with your keyboard.Your browser did not let the page copy, for example in a window that blocks it.Press Cmd+C on a Mac or Ctrl+C elsewhere, then paste the text at your provider.

After your provider's page

What you seeWhat it meansWhat to do
Record addedYour provider says it added the record, but public DNS does not show it yet.The panel checks once more by itself. If the record still does not show, click Look for the record in a few minutes.
Nothing was changedYou declined the record on your provider's page.Click the button to your provider again when you are ready, or click Add it by hand instead.
That took too longThe record Vallit asked for no longer matches the app, for example because its address changed.Start the connection again from the panel.
Your DNS provider did not finishYour provider sent you back with an error, or Vallit could not look the record up afterwards.Try again, or click Add it by hand instead.
Your DNS provider did not answer. Try again, or add the record manually.When you clicked the button to your provider, the provider did not reply to Vallit in time.Wait a minute and click again, or click Add it by hand instead.
Automatic connection is not available for this domain yet. You can add the DNS record manually.When you clicked, your provider no longer offered one click for this domain.Click Add it by hand instead and follow step 4.
Sign in again to connect your domain.Vallit could not read your sign-in when you clicked the button to your provider.Sign in again, open the app and click the button once more.

If more than 15 minutes pass before you approve, or you sign in to Vallit again in between, you come back to Home instead of the app's page. Your provider may still have added the record, so open the app and click Look for the record.

When Vallit looks the record up

What you seeWhat it meansWhat to do
We could not find a … record on … yet.No _vallit record answers yet. The message adds that DNS changes can take up to an hour to travel.If you added it just now, wait a few minutes and click Look for the record again. Otherwise, check the record's name.
We could not read the DNS records for …The DNS lookup failed, for example because the domain's name servers did not answer.Check that the app's address is spelled correctly, then click Look for the record again.
We found a Vallit record on …, but it holds a different code. Replace it with the one shown here.The record exists, but its value is an older or different code.Replace the value with the one in the panel's table, then click Look for the record.
We found records on …, but none of them is the Vallit one. Check you copied the whole value.A record with that name exists, but its value does not start with vallit-verification=.Copy the whole Value with its button and paste it again.
That did not go through. Check your connection and try again.Your browser lost the connection to Vallit before the answer came back.Check your internet connection, then click the same button again.
That app is not on your account.The app belongs to another company, or it was removed.Sign in with the account of the company that holds the app.

With a Cloudflare token

What you seeWhat it meansWhat to do
That does not look like a Cloudflare API token.The pasted text is not shaped like a token, for example because it holds spaces.Copy the token itself, which Cloudflare shows once after you create it.
Cloudflare did not accept that token. Create a new one and try again.Cloudflare does not know the token, or the token is no longer active.Create a new token with Create a token and paste it.
That token cannot see …The token has no access to the zone of your domain.Create a new token with DNS Edit for that zone.
Cloudflare refused the record …Cloudflare returned an error, which the message names.Fix what the message says, or add the record by hand with the lines above the token field.
Cloudflare did not answer. Try again in a moment.Cloudflare did not reply in time.Wait a minute, then click Add the record again.
The record is already at Cloudflare. Waiting for it to show up; checking again.The record is there from an earlier try, but public DNS does not show it yet.The panel checks again by itself. If it still does not show, click Look for the record later.