How to Validate Your Domain with a DNS TXT Record

· Guide

DNS TXT validation is one of three ways to prove to a Certificate Authority (CA) that you actually control a domain when purchasing an SSL certificate. At PekiSSL you can choose this method at checkout for DV, OV, and EV certificates alike.

Why DNS TXT?

Step 1 — View the Record

After completing your order, go to Panel > My Certificates > the relevant certificate page. You'll see a card titled "Domain Validation Pending" listing the record type, host name, and value the CA generated for you, each with a copy button. Important: the Type field is usually TXT, but depending on the CA it can sometimes be CNAME instead — whichever one is shown, use that exact type; the steps below apply the same way to both.

Step 2 — Add It to Your DNS Panel

Log in to wherever you manage DNS for your domain and create a new record using the type shown in the card (TXT or CNAME). The example below is written for TXT — if your card shows CNAME, just pick CNAME as the type and fill in the host/value the same way:

Type: TXT (or CNAME, if that's what your card shows)
Host: _dnsauth.example.com
Value: (the random validation token provided by the CA)
TTL: 300 (or the lowest value your panel allows)

Be careful with the host field: some panels automatically append your domain name. If you type "_dnsauth.example.com" in a panel that already appends the domain, you may end up with an incorrect "_dnsauth.example.com.example.com" record. Check your panel's preview before saving.

How to Add It on Popular DNS Providers

How Long Does It Take?

DNS propagation usually takes a few minutes but can take up to 24 hours depending on your provider and the previous TTL. PekiSSL checks automatically on a regular interval — the moment your record propagates, your certificate activates and you receive an email. No need to keep refreshing the page.

Verify It Yourself

After adding the record, you can check propagation from a terminal, using the type shown on your card:

For TXT: nslookup -type=TXT _dnsauth.example.com
For CNAME: nslookup -type=CNAME _dnsauth.example.com

Or use a tool like https://dnschecker.org to see propagation status from multiple regions.

Common Issues

If you run into trouble, contact our support team or re-check your order from the Panel.

All blog posts