DoReply
Get things done

Claim and verify an email domain

Prove a team owns an email domain by DNS, then use that proof to enforce a login method and auto-join new members.

Claiming a domain is the first step toward enforcing single sign-on and auto-joining teammates by email domain. Claiming alone does nothing — a claimed, unverified domain has no effect on who can sign in or how.

Quick steps

1. Claim the domain

A team claims a domain from its SSO tab. Claiming requires a paid plan — a team on a free plan cannot claim a domain at all. A public email provider (gmail.com and similar) cannot be claimed by any team.

Claiming is inert by itself: nothing reads a pending claim, and no login behavior changes until the domain is verified.

2. Publish the TXT record and verify

The wizard gives you the exact record to publish: host _delegate-verify.<domain>, value delegate-domain-verification=<48 hex characters>. Add it with your DNS provider, then choose Verify (or Check now on an already-verified domain) to re-run the lookup.

DNS propagation is not instant. A failed check moments after publishing the record is expected — wait a few minutes and check again before assuming the value is wrong. Re-checking is always safe to repeat.

Only one team can hold a domain verified at a time. A second team can claim the same domain, but cannot verify it while the first team holds it — the first team's claim has to be removed first.

3. Know what happens if verification starts failing

Once verified, the domain's DNS record is re-checked automatically, once a day. If a scheduled check fails:

If you get one of these emails: republish the TXT record exactly as given, then check the domain from the SSO tab. A successful check clears the failure streak and, if verification was already removed, restores it — there is no separate re-claim step.

4. Turn on auto-join

Auto-join is opt-in per verified domain. When it's on, someone who authenticates with a verified email at that domain and isn't already a member is added automatically, with the team role you choose when you turn it on.

Auto-join will not re-add someone. If a member was deliberately removed from the team, they stay out even if they sign in again with an email at the auto-join domain — removal sticks.

5. Grant the right permissions

Domain claiming, verifying, re-checking, removing, and auto-join are all governed by the Domains permission. The login method and break-glass exceptions are governed by Single sign-on — a separate permission, because owning a domain and deciding how people sign in with it are different responsibilities. Domains is grantable at View or Manage only; there is no separate edit level for it.

Administrators hold both by default. Give Domains (and, if they'll also manage login methods, Single sign-on) to whoever should own this from the team's Roles page.

What good looks like

The domain shows Verified on the SSO tab, the scheduled check keeps passing day over day, and auto-join (if enabled) is adding the right people to the right role. Nobody is surprised by a removal notice because the write holders who'd see it are the people actually able to fix it.

Next steps