Domain Verification TXT Records: Add Them Safely, Clean Them Up
Where verification tokens go, which vendors require them to stay, what a crowded apex TXT set does to response size, and how to audit and remove old tokens.
DNS · HTTPS · custom domains
Hands-on guides and free browser tools for DNS records, custom domains, and certificates. Tested guides show real command output with the date it was captured, and every guide lists the primary sources it was checked against.
$ dig +nocmd and.guide A +noall +answerand.guide. 72 IN A 172.66.47.12and.guide. 72 IN A 172.66.44.244$ curl -sI https://www.and.guide/ | head -4HTTP/2 301date: Sat, 26 Sep 2026 14:42:20 GMTcontent-type: text/html; charset=UTF-8location: https://and.guide/ The questions people search for when a launch stalls, and the guide that answers each one.
“My new subdomain still returns NXDOMAIN.”
Why a New Subdomain Still Says NXDOMAIN: Negative Caching“Should this name be an A record or a CNAME?”
A Record or CNAME? Choosing the Right DNS Target“I changed DNS, but some people still reach the old server.”
How Long DNS Propagation Takes: TTLs and Caches, Measured“The browser says the certificate isn't valid for this name.”
Inspect a Site's TLS Certificate from the Command Line“Cloudflare shows a 52x error or the page redirects forever.”
Cloudflare 52x Errors and Redirect Loops: A Diagnosis Map“My host wants a CNAME, but this is the root domain.”
CNAME Flattening: What Resolvers See at a Flattened ApexThey run in your browser. DNS queries go straight to the public resolvers you choose; nothing is stored by and.guide.
Query any hostname through Cloudflare and Google DNS-over-HTTPS side by side and compare answers, TTLs, and DNSSEC status.
Validate a hostname against DNS label rules, spot risky or reserved labels, and see which wildcard certificates would cover it.
Turn your current TTL and planned change time into a dated timeline for lowering the TTL, switching the record, and raising it again.
Build CAA records for the certificate authorities you actually use, including wildcard policy and incident reporting.
How record types, aliases, caches, negative answers, and signatures decide what a resolver returns for your name.
Connecting a hostname to Cloudflare, Vercel, Netlify, and GitHub Pages, and choosing between the apex and www.
Certificate authorization, reading a certificate from the command line, HSTS, and the TLS errors that stop a launch.
Naming, rollout, cleanup, takeover prevention, email protection, and development workflows for names that must last.
Original research
A dated teardown of and.guide: DNS, DNSSEC, CAA, two certificates from two CAs, headers, redirects, and Markdown negotiation, plus what we would change.
Survey of 100 developer platforms' apex domains on 26 Sept 2026: CAA, DNSSEC, IPv6, HTTPS records, HSTS, apex vs www, certificate issuers, DMARC. CSV included.
Dates change only when a guide is materially revised or re-tested.
Where verification tokens go, which vendors require them to stay, what a crowded apex TXT set does to response size, and how to audit and remove old tokens.
The DNS records a sending domain needs for Google Workspace, Microsoft 365, or Amazon SES: SPF's 10-lookup limit, DKIM selectors, alignment, and RFC 9989 DMARC.
What Chrome's DNS error codes actually test, how NXDOMAIN, NODATA and SERVFAIL look in dig and curl, and which cache, resolver or record to check first.
An ordered runbook for moving DNS to Cloudflare: export the old zone, diff old and new nameservers, settle DNSSEC, and time the overlap by real NS TTLs.
A dated teardown of and.guide: DNS, DNSSEC, CAA, two certificates from two CAs, headers, redirects, and Markdown negotiation, plus what we would change.
01
Commands are run against live DNS and real endpoints. Output is pasted as returned and dated.
02
Platform behavior is checked against the vendor's current documentation or the relevant RFC, listed under every guide.
03
Corrections are welcome by email. A confirmed fix updates the guide and its visible date.
and.guide is published by 1990Company in South Korea. How we test · Editorial policy