Verify site ownership
Prove you own a site with Search Console, Cloudflare, a DNS TXT record, a homepage meta tag or a verification file, and what verification unlocks.
Any one proof verifies a site: a Google Search Console property, Cloudflare, a DNS TXT record, a homepage meta tag or a file at /.well-known/seofix-verify.txt. In the app, open the site page and pick a method on the card Unlock monitoring, Google's indexing data and agent fixing. Agents: get_verification then verify_site (MCP), or GET /v1/sites/{id}/verification then POST /v1/sites/{id}/verify.
What verification unlocks
Anyone can audit a public site, so SEOFix keeps the heavier features for sites whose owner has proved control.
| Feature | Unverified site | Verified site |
|---|---|---|
| Audit size | Up to 500 pages (larger requests: 409 site_not_verified) |
Up to your plan's page limit |
| Crawl speed | Up to 3 req/s | Up to 10 req/s (the site's max_rps) |
| Scheduled monitoring (weekly or daily) | Not available | Available on Starter and Growth |
| Google tab (Search Console data) | Not available | Available |
| IndexNow submissions | Not available | Available |
| Rechecks to verify fixes | Not available | Available |
Crawler secret header (X-SEOFix-Verify) |
Not sent | Sent, so your firewall can let SEOFixBot through |
Methods
The card lists the methods in this order. Each one has a Check now button (Search Console and Cloudflare verify as part of connecting).
| Method | What you do | Covers |
|---|---|---|
| Google Search Console | Connect the Google account that is Owner or Full user of a property covering the site | A domain property (sc-domain:example.com) covers the domain and every subdomain. A URL-prefix property covers that exact origin only. |
| Cloudflare | Paste an API token, or add the record and rule yourself | The registrable domain and every subdomain (it is the DNS TXT method) |
| Homepage tag | Add a <meta> tag to the homepage <head> |
That origin only |
| DNS record | Add one TXT record on the registrable domain | The domain and every subdomain |
| Verification file | Serve a small text file under /.well-known/ |
That origin only |
The verification token is public by design: it ends up in your DNS or your HTML. It is not the crawler secret, which stays private. See Let SEOFix through your firewall.
Google Search Console
Choose the Google Search Console method, then sign in with the Google account that owns the site in Search Console (Owner or Full user). SEOFix asks for read-only access. The same connection feeds the Google tab. Details: Connect Google Search Console.
A property only proves ownership with the permission level Owner or Full user. A URL-prefix property with a path (such as https://example.com/blog/) does not prove the whole site.
Cloudflare
If your DNS is on Cloudflare, either connect a scoped API token (SEOFix adds the TXT record and a firewall rule for you) or choose Do it myself (no API token) and add both by hand. Details: Connect Cloudflare.
DNS TXT record
Add one TXT record on your registrable domain (for blog.example.com, the record goes on example.com):
| Name | Type | Value |
|---|---|---|
example.com (often written @) |
TXT | seofix-verify=<verification token> |
The card detects your DNS host from the domain's nameservers and shows its steps. Hosts with their own steps: Cloudflare, GoDaddy, Namecheap, Vercel, Netlify DNS (including NS1), Amazon Route 53, Hostinger, Squarespace Domains, Google Cloud DNS, Porkbun, IONOS and DigitalOcean. Any other host gets generic steps.
Once the record is on screen, the card checks for it automatically every 2 minutes for 60 minutes while the page is open. DNS changes can take a few minutes, sometimes longer. You can also choose Check now.
A site whose address is an IP has no domain, so the DNS method is not available. Use the tag or the file.
Homepage meta tag
Add this tag inside the <head> of https://<your-host>/, deploy, then choose Check now:
<meta name="seofix-verification" content="<verification token>">
- The tag must be in the HTML your server sends, as a real element in the
<head>before any body content. A tag added by JavaScript after load is not seen. - SEOFix reads the first 256 KB of the homepage over HTTPS.
- It follows at most one redirect, and only to the same host or between
example.comandwww.example.com, over HTTPS.
Verification file
- Create a plain-text file at
https://<your-host>/.well-known/seofix-verify.txt. - Put exactly this line in it:
seofix-verify=<verification token>(trailing whitespace is fine). - Serve it with HTTP 200 directly (no redirects),
Content-Type: text/plain, at most 1 KB.
Ask your coding agent
The tag and file methods have Ask my agent to do it. It copies a one-paragraph prompt for Claude Code, Codex or Cursor: add the tag (or the file) in the site's codebase, deploy, then call verify_site with method: "meta" (or "file"). The prompt contains only the public verification token, never the crawler secret or an API key. The same prompt is methods.agent_prompt in GET /v1/sites/{id}/verification.
Verify through the API
Get every method and what to publish:
curl https://api.seofix.ai/v1/sites/42/verification \
-H "Authorization: Bearer $SEOFIX_API_KEY"
{
"verified": false,
"via": null,
"checked_at": null,
"lost_at": null,
"methods": {
"gsc": {"connected": false, "property": null},
"dns": {"name": "example.com", "type": "TXT", "value": "seofix-verify=…", "provider": {"provider": "cloudflare", "name": "Cloudflare", "steps": ["…"]}},
"meta": {"url": "https://example.com/", "tag": "<meta name=\"seofix-verification\" content=\"…\">"},
"file": {"url": "https://example.com/.well-known/seofix-verify.txt", "body": "seofix-verify=…"},
"cloudflare": {"connected": false, "zone": null, "token_link": "https://dash.cloudflare.com/…"},
"agent_prompt": "Verify ownership of https://example.com/ for SEOFix. …"
}
}
Then check:
curl -X POST https://api.seofix.ai/v1/sites/42/verify \
-H "Authorization: Bearer $SEOFIX_API_KEY" \
-H "Content-Type: application/json" \
-d '{"method": "meta"}'
methodis one ofgsc,dns,meta,file. Leave it out to try every method in this order: Search Console, DNS (Cloudflare counts as DNS), meta tag, file.- Success returns the site with
verified: true,verified_viaandchecked, the result of each method checked (match,mismatch,inconclusiveorn/a). - If no checked method matches, the answer is
422 verification_failedwith a message listing what to publish. - The endpoint allows 10 calls per minute.
MCP: get_verification, then verify_site with site_id and an optional method.
verified_via is gsc, dns, cloudflare, meta or file. It is cloudflare when the TXT record is the one SEOFix created through a Cloudflare connection.
Daily re-check
SEOFix re-checks ownership of every site once a day, so keep the proof in place. The verified card shows "Last checked" and a Re-check button that runs the check now.
Each method's check ends as one of:
- match: the proof is there.
- mismatch: the proof is gone or wrong (for example a 404 for the file, or a homepage without the tag).
- inconclusive: SEOFix could not tell. Examples: a network error or timeout, a 5xx or 429 answer, a 401 or 403 (often a firewall challenge), a redirect it does not follow, a DNS lookup that fails.
An inconclusive check never verifies a site, but it also does not take verification away right away: a site keeps its state while the method that verified it answers inconclusively.
The 14-day cap
For the DNS, meta tag and file methods, that grace period is capped. If the method that verified the site answers inconclusively on every check for more than 14 days, the site loses verification as if the proof had been removed. Any match resets the clock. Search Console is not capped, because a Google outage would affect every site at once.
If you use the file or the meta tag, make sure your firewall lets SEOFix read that path. A firewall challenge on the homepage or on /.well-known/seofix-verify.txt makes the check inconclusive.
When verification lapses
A site loses verification when the proof it was verified with no longer holds and no other proof matches, or after the 14-day cap. Then:
- The site card shows Ownership lost on (date).
- Scheduled monitoring is paused. SEOFix remembers the frequency you had.
- The Google sync is paused. Your reports are kept.
- New audits fall back to 500 pages and 3 req/s, and the crawler secret header is no longer sent.
- If the site has alert emails on, every team member gets an email.
Verify again with any method and SEOFix resumes: monitoring comes back at its earlier frequency if your plan includes monitoring.
Related
More in Sites & firewalls
Still stuck? Email [email protected] with your site and what you expected to see.