Add your DNS verification record
Before Scannd scans a domain, we need proof that you control it — otherwise anyone could point our scanner at anyone else's website. The proof is one TXT record added to your domain's DNS. It has two fields, it takes a few minutes, and once it is published you never have to think about it again.
The record
This is one record with two fields. Enter both. Its type is TXT.
_scannd-verify.example.com
scannd-verify=<your token>
Those are the shapes, not your values. Your actual record — with example.com replaced by your domain and a 40-character token in place of the placeholder — is shown on the target in your Scannd dashboard, and is repeated in the email that sent you here. Copy it from one of those rather than retyping it.
If you added a subdomain — shop.example.com rather than example.com — then the name is _scannd-verify.shop.example.com. The prefix attaches to the exact hostname you gave us, whatever it is.
Where to put it, by provider
Add the record wherever your domain's DNS is hosted, which is not always where you bought the domain — see the troubleshooting note below if you are not sure which one that is. The step that catches people out is the name field, because panels disagree about whether it wants the full name or only the relative part; each provider below says which, and the rule behind it is written out in full further down.
Cloudflare
- Open the target in your Scannd dashboard, or the email that sent you here, and keep the record's two values in front of you.
- In the Cloudflare dashboard, pick your domain, then open DNS › Records and choose Add record.
- Set Type to TXT.
- In Name, type the relative form — the full name with your zone's own name removed from the end. In the example.com zone that is _scannd-verify for the target example.com, or _scannd-verify.shop for the target shop.example.com. Cloudflare prints the finished name beneath the box as you type: it must end in your domain exactly once.
- Put the value in Content, pasted whole — scannd-verify=<your token>, with your real 40-character token.
- Leave TTL on Auto and leave the rest of the form alone.
- Click Save, then see After you save it.
The orange-cloud proxy toggle does not appear for TXT records and has no bearing on this.
Labels are as of writing. If one does not match what you see — the name field above all — use the five-second test.
GoDaddy
- Open the target in your Scannd dashboard, or the email that sent you here, and keep the record's two values in front of you.
- From My Products, find the domain and open its DNS / Manage DNS page.
- Choose Add New Record.
- Set Type to TXT.
- In Name, type the relative form — the full name with your zone's own name removed from the end. In the example.com zone that is _scannd-verify for the target example.com, or _scannd-verify.shop for the target shop.example.com. It is not @ — that would put the record on the domain itself.
- Put the value in Value, pasted whole — scannd-verify=<your token>, with your real 40-character token.
- Leave TTL at its default.
- Click Save, then see After you save it.
Labels are as of writing. If one does not match what you see — the name field above all — use the five-second test.
Namecheap
- Open the target in your Scannd dashboard, or the email that sent you here, and keep the record's two values in front of you.
- Go to Domain List and click Manage on your domain.
- Open the Advanced DNS tab and choose Add New Record.
- Choose TXT Record.
- In the column headed Host, type the relative form — the full name with your zone's own name removed from the end. In the example.com zone that is _scannd-verify for the target example.com, or _scannd-verify.shop for the target shop.example.com.
- Put the value under Value, pasted whole — scannd-verify=<your token>, with your real 40-character token.
- Leave TTL on Automatic.
- Click the tick to save the row, then see After you save it.
This only applies if Namecheap is also your DNS host — if the domain's nameservers point elsewhere, the Advanced DNS tab is not the zone being answered from.
Labels are as of writing. If one does not match what you see — the name field above all — use the five-second test.
Squarespace (formerly Google Domains)
Google Domains registrations moved to Squarespace, so this is where they live now.
- Open the target in your Scannd dashboard, or the email that sent you here, and keep the record's two values in front of you.
- Open Domains and pick the domain.
- Open DNS / DNS Settings and scroll to the custom records table.
- Add a record and set its type to TXT.
- In the Host column, type the relative form — the full name with your zone's own name removed from the end. In the example.com zone that is _scannd-verify for the target example.com, or _scannd-verify.shop for the target shop.example.com.
- Put the value in Data, pasted whole — scannd-verify=<your token>, with your real 40-character token.
- Leave TTL at its default.
- Save, then see After you save it.
Labels are as of writing. If one does not match what you see — the name field above all — use the five-second test.
AWS Route 53
- Open the target in your Scannd dashboard, or the email that sent you here, and keep the record's two values in front of you.
- In the Route 53 console open Hosted zones and click the zone for your domain. Check it is the public zone before you go on.
- Choose Create record.
- Set Record type to TXT.
- In Record name, type the relative form only — the full name with your zone's own name removed from the end; Route 53 prints the zone name alongside the box. In the example.com zone that is _scannd-verify for the target example.com, or _scannd-verify.shop for the target shop.example.com.
- In Value, enter the value in quotes — Route 53 expects TXT values quoted: "scannd-verify=<your token>", with your real 40-character token.
- Leave TTL at its default and set Routing policy to Simple.
- Choose Create records, then see After you save it.
Make sure you are editing the public hosted zone. A private zone with the same name is only answered inside your VPC, so nothing on the internet — us included — can see it.
Labels are as of writing. If one does not match what you see — the name field above all — use the five-second test.
Wix
- Open the target in your Scannd dashboard, or the email that sent you here, and keep the record's two values in front of you.
- Open your Wix account's Domains page and pick the domain.
- Open Advanced / Edit DNS.
- Find the TXT section and choose Add Record.
- In Host Name, type the relative form — the full name with your zone's own name removed from the end. In the example.com zone that is _scannd-verify for the target example.com, or _scannd-verify.shop for the target shop.example.com.
- Put the value in Value, pasted whole — scannd-verify=<your token>, with your real 40-character token.
- Leave TTL at its default.
- Save, then see After you save it.
Editing DNS at Wix only works if the domain is connected to Wix by nameservers. If you connected it by pointing method instead, your DNS still lives at your original registrar and the record belongs there.
Labels are as of writing. If one does not match what you see — the name field above all — use the five-second test.
Shopify
This applies to domains bought through Shopify.
- Open the target in your Scannd dashboard, or the email that sent you here, and keep the record's two values in front of you.
- In the Shopify admin go to Settings › Domains and click the domain.
- Open DNS settings and choose Add custom record.
- Choose TXT.
- In Name, type the relative form — the full name with your zone's own name removed from the end. In the example.com zone that is _scannd-verify for the target example.com, or _scannd-verify.shop for the target shop.example.com.
- Put the value in Value / Target, pasted whole — scannd-verify=<your token>, with your real 40-character token.
- Leave TTL at its default.
- Confirm, then see After you save it.
A domain you bought elsewhere and merely connected to Shopify is not managed here — add the record at whoever hosts its DNS.
Labels are as of writing. If one does not match what you see — the name field above all — use the five-second test.
Any other provider
The wording varies but the shape does not.
- Open the target in your Scannd dashboard, or the email that sent you here, and keep the record's two values in front of you.
- Find the DNS, zone or nameserver settings for your domain and choose to add a new record.
- Set the type to TXT — never CNAME, A or ALIAS.
- Fill in the name field — it may be labelled Name, Host, Hostname, Record name, Subdomain or Prefix. Which form it wants is the one thing that varies: apply the five-second test. The full name is _scannd-verify.example.com for the target example.com; the relative form is that with your zone's own name removed from the end, so _scannd-verify in the example.com zone, or _scannd-verify.shop for the target shop.example.com.
- Paste the value whole into the value field — it may be labelled Value, Content, Data, Text or Target. It is scannd-verify=<your token>, with your real 40-character token.
- Accept whatever TTL it offers by default.
- Save, then see After you save it.
If the panel edits a raw zone file rather than offering fields, use the full name with a trailing dot: _scannd-verify.example.com. IN TXT "scannd-verify=<your token>".
Stuck? Reply to the email that sent you here, or write to reports@scannd.com, and we will look at it with you.
Full name or relative name — the rule
DNS control panels disagree about what belongs in the name field. Some want the full name, _scannd-verify.example.com. Most want only the relative part, because they add your domain on for you. Getting this wrong is the single most common way a person who did everything else correctly still fails verification — and the panel will show no error at all, because what you created is a perfectly valid record at the wrong name.
The five-second test. Look at the name field as you type in it. If the panel shows your domain appended after the box — a greyed-out .example.com, or a live preview of the finished name underneath — then it is adding the domain for you, and you want the relative form. If it shows nothing, enter the full name.
The relative form is just the full name with your zone's own name removed from the end:
Zone example.com, target example.com
full
_scannd-verify.example.com
relative
_scannd-verify
Zone example.com, target shop.example.com
full
_scannd-verify.shop.example.com
relative
_scannd-verify.shop
How to tell you got it wrong. Save the record, then look
at how your panel lists it. If it reads
_scannd-verify.example.com.example.com — your
domain appearing twice — you entered the full name into a field that wanted the relative one. Edit the
record and remove the trailing domain. That doubled suffix is the fingerprint of this mistake, and it is
the first thing to check whenever a record looks right but will not verify.
After you save it
Most DNS changes are live within a minute. Some take longer, and a few providers are slow enough that it is worth walking away and coming back. Nothing is wrong if it is not instant.
You do not have to sit and watch it. We keep checking for your record automatically, and we will email you the moment it verifies. If you would rather not wait, open the target in your dashboard and click Check now — that runs exactly the same lookup, immediately.
Once the domain is verified you can scan it, and the record can stay where it is. Leave it published — we may re-check ownership later, and removing the record is the one thing that could cost you your verified status.
Published it, still not verifying
Your domain appears twice in the name
By far the most common cause. If the saved record reads _scannd-verify.example.com.example.com, the field wanted the relative form and got the full one. Fix it as described in Full name or relative name.
You edited the wrong zone
Where you bought a domain and where its DNS is answered are often two different companies. If the domain's nameservers were ever pointed at a host, a CDN or a site builder, that is the zone that counts, and records added at the registrar are ignored by the whole internet. Check your domain's current nameservers, then add the record wherever they point.
The value is not complete
We compare the whole value exactly. It must be scannd-verify= followed by your full 40-character token, with nothing added, nothing trimmed and no line break in the middle. A double-click selects only part of it in some browsers, so copy it from the dashboard rather than selecting it by hand.
Quotes — usually not the problem
Some panels wrap TXT values in "straight double quotes", and several require it. That is fine: we strip them before comparing. What does break is a “curly quote”, which is a different character and arrives when the value has been pasted through a word processor, a chat client or a notes app. Paste from the dashboard or the email directly into the DNS field, with no stop in between.
TTL is not the problem either
TTL does not control whether a record works, only how long resolvers may reuse an answer before asking again. Any value your provider offers is fine, including the default. It matters in one situation only: if you saved the record wrong, corrected it, and a long TTL is now keeping the old answer alive somewhere.
It was checked before it existed
A resolver that was asked for the record before you published it can remember the "no such record" answer for a while. If you checked early, give it a few minutes and check again — this clears itself.
The record type or the leading underscore got changed
The name begins with an underscore, and a few control panels quietly strip it, reject it, or save the record as the wrong type. Re-open the saved record and read it back rather than trusting the form you submitted.
Still stuck
Reply to the email that sent you here, or write to reports@scannd.com. Tell us the domain and we will look up what we can see from our side.