Claim and verify an email domain
Prove a team owns an email domain by DNS, then use that proof to enforce a login method and auto-join new members.
Log in or sign up to make these docs interactive
Choose your team, project, or agent to turn guidance into links to the exact place in your workspace.
Claiming a domain is the first step toward enforcing single sign-on and auto-joining teammates by email domain. Claiming alone does nothing — a claimed, unverified domain has no effect on who can sign in or how.
Quick steps
- Open the team's SSO tab and choose Claim a domain.
- Enter the domain. The wizard hands you a TXT record: name
_delegate-verify.<domain>, valuedelegate-domain-verification=<48 hex characters>. - Publish that exact record with your DNS provider, then choose Verify.
- If the check fails right after publishing, wait for DNS to propagate and check again — this is normal, not a sign the record is wrong.
- Once verified, turn on auto-join for the domain if you want new sign-ins there to join the team automatically, and pick the role they receive.
- Grant Domains to whoever should be able to claim, verify, re-check, or remove a domain, and Single sign-on to whoever sets the login method or break-glass exceptions.
1. Claim the domain
A team claims a domain from its SSO tab. Claiming requires a paid plan — a team on a free plan cannot claim a domain at all. A public email provider (gmail.com and similar) cannot be claimed by any team.
Claiming is inert by itself: nothing reads a pending claim, and no login behavior changes until the domain is verified.
2. Publish the TXT record and verify
The wizard gives you the exact record to publish: host
_delegate-verify.<domain>, value
delegate-domain-verification=<48 hex characters>. Add it with your DNS
provider, then choose Verify (or Check now on an already-verified
domain) to re-run the lookup.
DNS propagation is not instant. A failed check moments after publishing the record is expected — wait a few minutes and check again before assuming the value is wrong. Re-checking is always safe to repeat.
Only one team can hold a domain verified at a time. A second team can claim the same domain, but cannot verify it while the first team holds it — the first team's claim has to be removed first.
3. Know what happens if verification starts failing
Once verified, the domain's DNS record is re-checked automatically, once a day. If a scheduled check fails:
- Day one is silent — nothing is sent, nothing changes.
- From day two, everyone who holds Manage on Domains for the team is emailed once a day, naming the domain, how long the check has been failing, the exact record to republish, and the date verification will be removed if it is not fixed.
- After seven consecutive days of failure, verification is removed automatically. This stops enforced login and auto-join for everyone at that domain — logins fall back to whatever methods are otherwise permitted.
If you get one of these emails: republish the TXT record exactly as given, then check the domain from the SSO tab. A successful check clears the failure streak and, if verification was already removed, restores it — there is no separate re-claim step.
4. Turn on auto-join
Auto-join is opt-in per verified domain. When it's on, someone who authenticates with a verified email at that domain and isn't already a member is added automatically, with the team role you choose when you turn it on.
Auto-join will not re-add someone. If a member was deliberately removed from the team, they stay out even if they sign in again with an email at the auto-join domain — removal sticks.
5. Grant the right permissions
Domain claiming, verifying, re-checking, removing, and auto-join are all governed by the Domains permission. The login method and break-glass exceptions are governed by Single sign-on — a separate permission, because owning a domain and deciding how people sign in with it are different responsibilities. Domains is grantable at View or Manage only; there is no separate edit level for it.
Administrators hold both by default. Give Domains (and, if they'll also manage login methods, Single sign-on) to whoever should own this from the team's Roles page.
What good looks like
The domain shows Verified on the SSO tab, the scheduled check keeps passing day over day, and auto-join (if enabled) is adding the right people to the right role. Nobody is surprised by a removal notice because the write holders who'd see it are the people actually able to fix it.