How it works
One call, one approval. Then we watch until it answers.
What happens between your API call and a verified domain: who we ask, what your customer sees, how often we check, and every state a setup can be in.
You create a setup
Your server posts the domain and the records it needs, with your API key. The call returns straight away with a token that is safe to hand to a browser. Nothing waits on DNS.
Your customer approves it
The widget works out who runs their DNS. Where the provider supports Domain Connect, approving the change is the whole task. Everywhere else, it shows the exact records to add.
You hear when it goes live
We check public DNS on a schedule until the records answer, then mark the setup verified. The widget calls onSuccess and your webhook is told.
Detection
Who runs their DNS? Three lookups decide it.
One click is only offered when the provider says, in public DNS, that it supports the browser flow. Nothing is guessed from a brand name. When the answer is no, the setup moves to the records path, which works at every provider.
- 1
Find the zone
An NS lookup walks up from the domain until it reaches the zone that holds it.
NS acme.com
- 2
Ask the provider
A TXT lookup on the zone asks whether the provider speaks Domain Connect, and where.
TXT _domainconnect.acme.com
- 3
Check for the browser flow
The provider's settings must offer the flow your customer approves in. If they do, it is one click.
GET /v2/acme.com/settings
Statuses
Seven states. Every setup is in exactly one.
- createdThe setup exists. Detection starts at once.
- awaiting_authorizationThe provider supports one click. Waiting for your customer to approve.
- manual_requiredNo one click here. The widget shows the records to copy.
- verifyingRecords are written or added. Checking public DNS until they answer.
- verifiedEvery record answers. onSuccess fires and your webhook is sent.
- expiredThe attempts ran out, or the setup passed its expiry, before the records answered.
- failedThe setup could not start, for example because it has no records.
The status arrives in onStatusChange, in GET /v1/dns-sessions/:id, and in webhook payloads.
Verification
Quick at first. Then patient.
DNS usually answers within minutes, sometimes hours. So checks start close together and spread out, rather than hammering resolvers or giving up early.
- 30s1st check
- 1m2nd
- 2m3rd
- 5m4th
- 10mthen every
12 attempts by default
Set maxVerificationAttempts from 1 to 100. At the default, the last check runs about an hour and a half in.
Checked when they say so
"I have added the records" in the widget runs a check at once. It uses one attempt from the same budget.
Nothing left stalled
Every ten minutes, any check that has gone quiet for twenty is picked up again.
Afterwards
What stays, and what is cleaned up.
Verified
The domain keeps working.
The records stay in place for as long as the domain is connected. Removing a setup with DELETE /v1/dns-sessions/:id takes our side down first.
Never verified
Nothing is left behind.
Once a setup passes its expiry, a daily job removes what we published for it. Thirty days later the setup itself is deleted.
Get started
Try it on one domain. Nothing is charged until one connects in one click.
- 1Create an accountAn email and a password
- 2Make a project and an API keyThe key is shown once
- 3Connect your first domainOne call from your server
- The account and the key take about a minute.