Platform

Verify domain ownership

The first step for all four services. Publish one TXT record to prove you own the domain, and find out where your domain comes from.

All four services start with exactly one thing: proving you own the domain with one TXT record. Only then do you get each service's own configuration records.

Before you verify

  • Permission to edit DNS records for the domain
  • An administrator account on the CloudFly console

Where your domain comes from

ServiceWhere the domain comes fromCan you add one
Email BusinessYou give it when you sign up; CloudFly creates itNo
Email SecurityYou give it when you sign up; CloudFly creates itNo
Email APIYou add it yourself in the consoleYes, within your plan's limit
Email RelayYou add it yourself in the consoleYes, within your plan's limit
  • Email Business and Email Security — the page has no add button. An empty page is not something you did wrong; contact support to have it configured.
  • Email API and Email Relay — click + Add domain, type the domain, click Add. One domain works for both services.

Open the domain page

ServiceConsole section
Email BusinessDomains
Email SecurityRouting configuration
Email APISending domains
Email RelaySending domains

Email Business domain setup and activation page: a Check DNS button top right, and two status cards, Step 1 Verify ownership and Email DNS configuration, both showing a green tick

All four pages follow the same two-step frame:

ItemStep 1Step 2
What you doVerify domain ownershipPublish the service's configuration records
ButtonVerify ownershipCheck DNS

This page covers step 1. For step 2, see the last section.

Publish the TXT record

Copy the token

The domain page in the Waiting for ownership verification state: a row of domains with the selected one carrying an amber dot plus an add-domain button, a blue Verify ownership button top right, two cards for Step 1 and Step 2 with Step 1 highlighted, and an Ownership verification record table holding one TXT row named _cloudfly dot the domain, content cloudfly-verify followed by a hex string, status Pending check

The picture is taken in Email API, hence the + Add domain button; the record table is identical across all four services.

Use the copy button in the Content cell, do not retype: the token is long, case-sensitive, and one wrong character still produces "record not found".

Pending check means the platform is waiting, not an error.

Create the record at your DNS provider

This record is identical across all four services.

FieldValue
TypeTXT
Name / Host_cloudfly
Valuecloudfly-verify=<token copied from the console>
TTLleave at default

Because it is shared, this record stays valid when you enable another service on the same domain — do not delete it.

Check the Name / Host field

Every DNS provider handles this field differently.

The record must sit at _cloudfly.example.com, not _cloudfly.example.com.example.com. If the field appends the domain for you, enter only _cloudfly; if not, enter the full name.

Wait for the check

Check your work

In the console

Verification is done when all three of these appear together:

  1. The Step 1: Verify ownership card turns green
  2. The step 2 record table appears below it — that table only appears once infrastructure has been provisioned, so seeing it means this step is certainly complete
  3. The Last checked line shows a recent time

From your own machine

dig +short TXT _cloudfly.example.com
dig +short TXT _cloudfly.example.com @8.8.8.8

Both must return a cloudfly-verify=... string matching the console. If only the first returns a result, the record has not reached public DNS servers yet.

When the check reports nothing found

Match what dig returns against the table below.

dig returnsCauseFix
NothingThe record was not saved, or was saved on the wrong domainCheck your DNS control panel
A string different from the consoleAn old record left over from an earlier attempt — with several _cloudfly records at once the check cannot tell which to trustDelete the extra one
The right value, but the console still reports nothingIntermediate DNS resolvers still hold the old record in cacheWait out the previous record's TTL and check again

Keep the TXT record after verification

The platform re-checks on a schedule. A domain that loses its verification record can be returned to the pending state, and the services on it stop working.

Next step

ServiceWhat step 2 publishesGuide
Email BusinessMX, SPF, DKIM, DMARC — receive and send on CloudFly infrastructurePublish the four mail DNS records
Email SecurityMX only — inbound mail goes through the filter, then on to your own serverPoint MX through the filtering gateway
Email APISigning records and a feedback path — sending onlyPublish the sending domain records
Email RelayThe same records as Email API, but added and activated separatelyPublish the relay sending domain records

Only Email Business points your root MX at CloudFly

Email Security also changes MX, but the destination is the filtering gateway and mail continues on to your own mail server. Email API and Email Relay never touch your root MX — they only send; your mailboxes stay exactly where they are.