How to Validate Your Domain with a DNS TXT Record
· Guide
DNS TXT validation is one of three ways to prove to a Certificate Authority (CA) that you actually control a domain when purchasing an SSL certificate. At PekiSSL you can choose this method at checkout for DV, OV, and EV certificates alike.
Why DNS TXT?
- You don't need a special role mailbox like admin@ on your domain — just access to your DNS panel.
- No file upload or server access required.
- Once added, it's verified automatically — no further manual steps.
- It's effectively the only option for wildcard certificates (*.example.com) — email and HTTP validation cannot validate a wildcard.
Step 1 — View the Record
After completing your order, go to Panel > My Certificates > the relevant certificate page. You'll see a card titled "Domain Validation Pending" listing the record type, host name, and value the CA generated for you, each with a copy button. Important: the Type field is usually TXT, but depending on the CA it can sometimes be CNAME instead — whichever one is shown, use that exact type; the steps below apply the same way to both.
Step 2 — Add It to Your DNS Panel
Log in to wherever you manage DNS for your domain and create a new record using the type shown in the card (TXT or CNAME). The example below is written for TXT — if your card shows CNAME, just pick CNAME as the type and fill in the host/value the same way:
Type: TXT (or CNAME, if that's what your card shows)
Host: _dnsauth.example.com
Value: (the random validation token provided by the CA)
TTL: 300 (or the lowest value your panel allows)
Be careful with the host field: some panels automatically append your domain name. If you type "_dnsauth.example.com" in a panel that already appends the domain, you may end up with an incorrect "_dnsauth.example.com.example.com" record. Check your panel's preview before saving.
How to Add It on Popular DNS Providers
- Cloudflare: DNS > Records > Add record. Make sure Proxy status is "DNS only" (grey cloud) — proxied (orange cloud) records can cause issues with TXT/CNAME validation.
- GoDaddy: DNS Management > Add > whichever type your card shows (TXT or CNAME).
- Namecheap: Advanced DNS > Add New Record > TXT Record or CNAME Record, matching your card.
- Route 53 / Google Domains: Create record > select the type shown on your card.
How Long Does It Take?
DNS propagation usually takes a few minutes but can take up to 24 hours depending on your provider and the previous TTL. PekiSSL checks automatically on a regular interval — the moment your record propagates, your certificate activates and you receive an email. No need to keep refreshing the page.
Verify It Yourself
After adding the record, you can check propagation from a terminal, using the type shown on your card:
For TXT: nslookup -type=TXT _dnsauth.example.com
For CNAME: nslookup -type=CNAME _dnsauth.example.com
Or use a tool like https://dnschecker.org to see propagation status from multiple regions.
Common Issues
- The domain name may have been duplicated in the host field — check your panel's preview.
- A record left "Proxied" (orange cloud) in Cloudflare should be switched to DNS only.
- You may have added a TXT record when the card showed CNAME (or vice versa) — double-check the "Type" field on the card.
- An old cached record may still be showing — wait a few minutes.
- The record may have been added to the wrong zone (subdomain vs. apex domain).
If you run into trouble, contact our support team or re-check your order from the Panel.