What You Will Learn
- A Domain property covers all subdomains, http, and https variations under one unified dashboard using DNS verification.
- Adding a DNS TXT record at your domain registrar or DNS host confirms administrative ownership across your entire site.
- Retaining the DNS verification record permanently is essential, as Search Console periodically rechecks ownership status.
How to Verify a Search Console Domain Property With DNS
Verifying a Domain property in Google Search Console gives you a complete view of your website performance. Unlike a URL-prefix property, which tracks only one specific folder or protocol (such as https://example.com), a Domain property aggregates data across every protocol (http and https) and all subdomains (such as blog.example.com or shop.example.com). This tutorial guides you through the DNS verification process step by step, showing you how to add the required record, avoid common lookup delays, and keep your property active.
To verify a Domain property, Google requires you to prove ownership at the domain name system (DNS) level. The DNS acts like the address book of the internet, pointing human-readable domain names to server IP addresses. When you add a unique verification string provided by Google to your DNS records, Google confirms that you control the entire domain.
Prerequisites Before You Start
Let us make sure you have everything ready before opening any dashboards. You will need:
- A Google account: The email address you want to use to manage Google Search Console.
- Administrative access to your DNS host: Login credentials for the platform where your domain nameservers are managed. This could be your domain registrar (such as GoDaddy, Namecheap, or Google Domains) or a third-party DNS provider (such as Cloudflare).
- A clean domain name: Your apex domain (for example,
example.com) without any prefixes likehttps://orwww..
Step 1: Confirm Where Your DNS Is Managed
A frequent point of confusion is knowing where to edit DNS records. Your domain registrar sells you the domain name, but your DNS provider manages the actual traffic records. Often, the registrar and DNS provider are the exact same company. However, if you use a third-party host or a content delivery network (CDN) like Cloudflare, your active DNS records live with that service.
Before adding records, check your domain nameservers:
- If your nameservers point to your hosting provider, manage your DNS in your web hosting control panel (such as cPanel).
- If your nameservers point to a CDN or managed DNS platform, log in to that platform's control panel.
- If your nameservers point to default registrar servers, manage your DNS inside your registrar dashboard.
Adding a record in the wrong management panel will result in a failed verification because Google checks only the authoritative nameservers.
Step 2: Start Property Creation in Search Console
Open Google Search Console in your browser. Make sure you are signed in with the Google account you intend to use for reporting.
- In the left navigation bar, open the property selector dropdown and select Add property.
- You will see two property types: Domain on the left and URL prefix on the right.
- Select the Domain option.
- Enter your bare domain name. For instance, enter
example.comwithouthttp://,https://, or trailing slashes. - Click Continue.
Step 3: Copy the DNS Verification Value
Once you click Continue, Search Console displays a modal window titled "Verify domain ownership via DNS record". Google provides an account-specific TXT token. This token is a random string of characters that proves your specific Google account has administrative rights to this domain.
In this window:
- Keep the record type set to TXT (this is the recommended and default format). Some providers also support CNAME records, but a TXT record is simpler and does not interfere with standard web routing.
- Click the Copy button next to the value field. The copied string will resemble
google-site-verification=AbCdEfGhIjKlMnOpQrStUvWxYz1234567890. - Leave this Search Console browser tab open while you update your DNS records.
Step 4: Add the TXT Record in Your DNS Manager
Now, open a new browser tab and navigate to your DNS management dashboard. Locate the section named DNS Management, Zone Editor, or DNS Records.
Create a new DNS record with the following settings:
- Type: Select
TXT. - Name / Host / Hostname: Enter
@or leave it blank, depending on your provider. In DNS terminology, the@symbol represents the root domain (example.com). Some registrars require you to type your full root domain instead. Check your provider instructions if it rejects@. - Value / Content / Target: Paste the exact verification token you copied from Search Console. Make sure there are no accidental spaces before or after the string.
- TTL (Time to Live): Leave this at the default value (often 3600 seconds or Automatic). If your provider lets you choose, selecting a lower value like 300 seconds (5 minutes) helps changes propagate faster during testing.
Save or add the record to confirm the changes.
An Illustrative Example: Adding the Record
Let us look at a concrete example so you know exactly what your entries should look like in your dashboard.
Example Scenario:
Suppose your site is learnmysite.com.
- Search Console Domain Property Input:
learnmysite.com - Generated Verification Token:
google-site-verification=z8XkP19mQv7-T9wLmK298ExampleToken
In your DNS control panel, your new record row will look like this:
| Field | Value to Enter | Meaning |
|---|---|---|
| Record Type | TXT |
Specifies a text record readable by validation crawlers |
| Host / Name | @ |
Applies the record to the apex domain learnmysite.com |
| Content / Value | google-site-verification=z8XkP19mQv7... |
The unique verification key assigned to your Google account |
| TTL | Automatic or 3600 |
Defines cache lifespan in seconds across DNS resolvers |
Step 5: Verify After DNS Propagation
DNS records do not always update worldwide in an instant. This delay is known as DNS propagation. Modern cloud DNS providers often update within a couple of minutes, but some hosting systems can take an hour or more.
Return to the Search Console tab where you opened the verification box:
- Click the Verify button.
- If the record has propagated and Google finds your token, a green success message reading "Ownership verified" will appear.
- If verification fails immediately, do not worry. Leave the window open or click Verify later. Wait 15 to 30 minutes, then return to the property and click Verify again.
How to Verify Your Result Independently
If Search Console returns an error stating that your verification record was not found, verify whether the public internet can see your new record before trying again. You can do this without guessing:
- Use a public DNS lookup tool: Open a free web-based DNS lookup utility (such as Google Admin Toolbox Dig or any public DNS checker). Enter your root domain and inspect the TXT records.
- Check the output: Look through the listed TXT answers. If you do not see your
google-site-verification=...string, your DNS changes have not yet reached public recursive resolvers. - Verify via command line: If you are comfortable using your operating system terminal, run:
nslookup -type=TXT yourdomain.com
ordig yourdomain.com TXT
Confirm that your Google token appears in the response block.
Once you see the token appear in public lookups, return to Search Console and click Verify. The check will succeed immediately.
Retaining the Ownership Record
A crucial rule of Search Console verification is that ownership is not a one-time check. Google periodically re-evaluates the verification tokens of all active properties. If you delete the TXT record from your DNS zone after seeing the success screen, Google will eventually lose contact with your verification evidence.
When Google cannot re-verify your DNS record:
- Your access to the property's performance data will be suspended.
- Associated email alerts regarding security or indexing issues will stop.
- Other users granted access through your account may lose their property permissions.
Always leave your verification TXT record in your DNS settings permanently. If you migrate to a new hosting company or change your DNS provider in the future, remember to copy this TXT record over to your new provider's DNS zone file alongside your mail and web records.
Common Mistakes to Avoid
If you run into issues during verification, check for these frequent configuration errors:
- Adding the record to a subdomain by mistake: When filling out the Host field, typing
wwworsubdomaininstead of@places the TXT record onwww.example.comrather than the root domain. Google verifies Domain properties strictly at the root level. - Duplicate quotes: Some DNS editors automatically wrap TXT values in quotation marks. If you paste a token that already has quotation marks, the record may save with double quotes (such as
""google-site-verification=...""), which causes validation to fail. - Modifying an inactive DNS zone: If your domain nameservers point to Cloudflare or a web host, editing records at your original domain registrar will have no effect. Always update records where your nameservers are currently hosted.
- Impatience with propagation: Clicking "Verify" repeatedly within 10 seconds of saving your DNS record often leads to failure. Give your DNS servers at least a few minutes to publish changes.
Limitations and Access Rules
While Domain properties provide the most comprehensive reporting, there are specific limitations and operational boundaries you should understand:
- No alternative verification methods: A Domain property requires DNS verification. You cannot verify a Domain property using HTML file upload, an HTML meta tag, Google Analytics, or Google Tag Manager. Those methods only work for URL-prefix properties.
- Shared ownership: If multiple team members need owner access, each user can add their own unique TXT record to the DNS zone without overwriting existing records. A DNS zone can contain multiple TXT records at the same root level.
- Data history timeline: Search Console begins recording data for a newly created property from the moment it is created. It does not pull historical search analytics from before the property existed. Once verified, you can monitor performance reports How Are You Performing on Google?.
Next Steps: Put Your Verified Property to Work
Now that your Domain property is verified and active, your next steps focus on monitoring and health checks:
- Submit your sitemap: Help Google discover your site structure by submitting your primary XML sitemap directly through the Sitemaps tool Search Console Sitemaps Report.
- Review URL indexability: Use the URL Inspection tool to confirm whether key pages are properly fetched and indexed by Googlebot URL Inspection Tool. If you notice problems with page visibility, consult our guide on How to Find and Fix Indexing Errors in Search Console.
- Audit user permissions: Go to Settings > Users and permissions in Search Console. Document who has owner or restricted permissions, and keep a record of your DNS entries in your internal site maintenance log.
Frequently Asked Questions
Can I verify a Search Console Domain property using an HTML tag or Google Analytics?
No. Google requires DNS verification for Domain properties because they encompass all protocols and subdomains. Methods like HTML tags, file uploads, Google Tag Manager, and Google Analytics are only supported for URL-prefix properties.
What should I do if my DNS provider does not accept @ as the host name?
Some DNS providers do not use the @ symbol for root domains. In those panels, leave the Host or Name field completely blank, or type your bare domain name without prefixes (such as example.com). Refer to your provider's DNS documentation for their preferred apex syntax.
Can multiple people add separate Google verification TXT records to the same domain?
Yes. DNS zones support multiple TXT records on the root domain simultaneously. Each verified owner can add their unique Google verification string to the DNS settings without overwriting or interfering with other owners' verification records.
Post a Comment