DOMAIN CONTROL VERIFICATION · FOR AGENTS

Prove control of a domain.
Receive a machine‑verifiable proof.

Publish a challenge as a DNS TXT record or an HTTPS /.well-known file. We check it on the public Internet and return an Ed25519-signed proof any service can validate offline. Works with every registrar and DNS host.

0.019 USDC per proofx402 on BaseFailed checks are free
POST /api/v1/verifications/…/verify → 200
{
  "status": "verified",
  "proof": {
    "proof_version": "1",
    "domain": "example.com",
    "verification_method": "dns_txt",
    "audience": "marketplace.example",
    "nonce": "7f3a…c91e",
    "verified_at": "2026-09-29T14:02:11Z",
    "valid_until": "2026-10-06T14:02:11Z",
    "issuer": "domainnameproof.online",
    "evidence": { record, nameservers, match: "exact" },
    "signature_algorithm": "Ed25519",
    "signature": "q0Zk…Vw"
  }
}

Four steps, no registrar integration

The public Internet is the verification surface. GoDaddy, Cloudflare, Route 53, a national registrar or your own nameservers: if you can publish a record, you can prove control.

Request a challenge

POST /api/v1/verifications with a domain and a method. Free, instant, bound to that exact domain.

Publish it

A TXT record at _domain-name-proof.<domain>, or a file at /.well-known/domain-name-proof/….

Verify

We query the authoritative nameservers or fetch over HTTPS with SSRF protection. Not found yet? Free, retry later.

Receive a signed proof

When found, pay 0.019 USDC via x402 in the same call and get the Ed25519-signed proof.

Precise about what it proves

A proof is a statement about control at one moment, not about ownership or identity.

A proof says

  • This exact domain's DNS zone or web server served our challenge
  • Using this method, observed at this time
  • For this audience and nonce, if the relying party asked for them
  • Signed by our published Ed25519 key; any change breaks the signature

A proof does not say

  • Legal ownership of the domain
  • Identity of the registrant, person or company
  • Authorization beyond control of the verification surface (DNS zone or web server)
  • Legitimacy, reputation or trustworthiness of the domain
  • That the same party still controls the domain after verified_at
  • Control of any other name: the apex, subdomains and www are separate domains

For relying parties

A marketplace, referral program or SaaS onboarding flow asks a seller agent to prove control of its domain here, with your audience and a fresh nonce. You receive a proof and validate it with the public key — no database call, no registrar logic, no account with us.

Integration guide
relying-party.ts
// Validate offline with the published JWK Set
const keys = await fetch(KEYS_URL).then(r => r.json());
const result = validateProof(proof, {
  keys: keys.keys,
  expected_domain: 'seller.example',
  expected_audience: 'marketplace.example',
  expected_nonce: nonce,
  max_age_seconds: 3600,
});
// result.valid, result.cryptographically_valid,
// result.within_validity_period, result.errors[]

Built to be read by agents

Everything an autonomous agent needs to discover, pay for and validate a proof is published in machine-readable form.