Verify your domain in AYAsec using GoDaddy
Before AYAsec scans a domain, you need to prove you control it. In GoDaddy that is one TXT record - though GoDaddy can take a few minutes longer than other providers to publish it.
Why we ask. Verification is what stops AYAsec from being pointed at infrastructure you do not own. A scanner that will check any domain on request is a reconnaissance tool for whoever asks, which is why the source of an asset list matters. Requiring proof of ownership is what separates a security product from a reconnaissance service.
You verify each asset once. Verifying an apex domain automatically verifies its subdomains, so verifying example.com covers api.example.com, www.example.com and the rest. New subdomains added later do not need their own record. Re-verify only if you edit the hostname or delete and re-add the asset, because the new asset has a new UUID token.
After successful verification, you can remove the record. AYAsec checks it once and does not read it again. You can leave it in place if you prefer, but re-verification after recreating the asset requires the new token AYAsec gives you.
Before you start
- Access to the GoDaddy account holding the domain
- Your verification token from AYAsec
- The Analyst role or higher in your AYAsec workspace
If someone else manages your DNS, skip to Don't have access? - there is a message you can forward.
Step 1 · Copy your token from AYAsec
Open Assets Discovery in AYAsec and open the Assets tab, or open the asset's detail page. Start verification from the Not verified pill, Verify now in the card menu, or Verify domain in the asset context menu. In the dialog titled Verify asset - <host>, select DNS Record. Copy the two values shown:
- Record name:
_ayasec-verified.yourdomain.com - Record value:
ayasec-verified-<asset UUID>
Keep the tab open.
Verifying a whole asset group? Open Assets Discovery > Asset Groups and then open the group. Use Verify domain for a group with a source apex or Verify unverified for one without. The dialog is titledVerify domain - <apex>and saysVerifying <apex> covers all N targets in this group; its action is Verify now. Useayasec-verified-group-<group UUID>as a separate TXT record at the same name - do not replace an existing asset token.
Step 2 · Add the record
- Sign in to GoDaddy and open My Products.
- Find your domain and open its DNS management.
- Click Add or Add New Record.
- Fill in:
| Field | What to enter |
|---|---|
| Type | TXT |
| Name | _ayasec-verified - GoDaddy appends your domain |
| Value | Your token |
| TTL | Leave the default |
- Save.
If the menu does not look like this, you are not lost - GoDaddy moves DNS management between account layouts more often than other providers. Look for DNS management on the domain itself rather than in account-level settings; the fields are the same wherever it has been put this year.
Step 3 · Wait a few minutes, then verify
This is where GoDaddy differs in practice. Other providers usually serve a new record within seconds. GoDaddy can take several minutes.
Go back to AYAsec and click Verify Now. It shows Verifying… while the check runs.
If verification fails on the first attempt, wait five minutes and try again before changing anything. Editing a record that was simply not published yet is the most common way people turn a two-minute task into an hour - each edit resets the clock, and the record was correct all along.
Check the record yourself
dig TXT _ayasec-verified.yourdomain.com +shortOn Windows:
nslookup -type=TXT _ayasec-verified.yourdomain.comIf your token appears here but AYAsec still cannot see it, wait a little longer - different resolvers pick up the change at different times.
If verification fails
| What you see | What it usually means | Fix |
|---|---|---|
| Record not found, and the record looks correct | GoDaddy has not published it yet | Wait five minutes and retry. Do not edit it |
| Record not found, and the name looks wrong | Name typed with the full domain appended twice | It should read _ayasec-verified, not _ayasec-verified.yourdomain.com |
| Token doesn't match | Extra characters in the value | Re-copy from AYAsec. Check for a trailing space |
| Domain unreachable | Nameservers point elsewhere | If DNS is hosted somewhere else, add the record there instead |
Don't have access?
Most people verifying a domain do not administer its DNS. Forward this:
Hi - I'm setting up AYAsec to monitor our external attack surface, and it needs proof that we control the domain before it will scan anything.
Could you add one DNS record in GoDaddy?
Type: TXT
Name:_ayasec-verified
Value:ayasec-verified-<paste token>
TTL: default
It's read-only proof of ownership - it doesn't change how the domain behaves and doesn't affect mail or the website. It can be removed after AYAsec verifies it - AYAsec checks it once and does not read it again. You can leave it in place if you prefer, but re-verification after recreating the asset requires the new token AYAsec gives you. Thanks.
Other ways to verify
If you cannot edit DNS, AYAsec accepts two alternatives:
- File upload - a text file containing your token at
https://yourdomain.com/.well-known/ayasec-verified.txt - Meta tag -
<meta name="ayasec-verified" content="your-token">on your homepage
Both prove the same thing. If you can deploy to the website but not to DNS, the meta tag is usually quickest - and it avoids the waiting described above.
Using a different DNS provider?
The record is identical everywhere; only the interface changes. See the guides for Cloudflare, AWS Route 53, Azure DNS, Google Cloud DNS, DigitalOcean, Hetzner and Contabo.
Once the domain is verified, Discovery and the first scan take a few minutes.