DNS Verification

Prove you control a domain with a DNS record or a file. Required before live-app testing, which is not open yet.

Edit on GitHub

LaunchSafe will test a live app only after your organization has proven it controls the domain, in the same way Google Search Console verifies domains.

Add and prove a domain

Owners and admins add a domain under Settings → Domains. LaunchSafe gives you a random token. Publish it in one of two ways:

MethodWhat to publishCovers
DNS record (default)A TXT record at _launchsafe-challenge.<domain> with the value launchsafe-verify=<token>The domain and every host under it
FileA file at https://<domain>/.well-known/launchsafe-verification.txt containing that same lineThat exact host only

Then choose Verify. The check runs from LaunchSafe's servers.

Shared hosting

Public suffixes such as co.uk, vercel.app, github.io and netlify.app cannot be proven, because the platform controls DNS above you. On shared hosting, prove the exact host with the file method instead.

Keeping it proven

LaunchSafe re-checks verified domains daily. If the proof goes missing, a 72-hour grace period starts, since a DNS change or a deploy can briefly drop it. If the proof is still missing when the grace period ends, the domain lapses and live targets under it are blocked until you restore the proof and check again.

Targets

A target is a live URL in a project. Its readiness comes from your verified domains: ready, unverified or lapsed. You can save a target's scope and safety settings (allowed hosts, excluded paths, test windows, safe mode, request rate). These apply when live testing opens. Loosening a safety setting needs the right to approve live-app scans, which owners and admins hold.

On this page