Verify site ownership

Prove you own a site with Search Console, Cloudflare, a DNS TXT record, a homepage meta tag or a verification file, and what verification unlocks.

Updated 8 October 2026View as Markdown

Any one proof verifies a site: a Google Search Console property, Cloudflare, a DNS TXT record, a homepage meta tag or a file at /.well-known/seofix-verify.txt. In the app, open the site page and pick a method on the card Unlock monitoring, Google's indexing data and agent fixing. Agents: get_verification then verify_site (MCP), or GET /v1/sites/{id}/verification then POST /v1/sites/{id}/verify.

What verification unlocks

Anyone can audit a public site, so SEOFix keeps the heavier features for sites whose owner has proved control.

Feature Unverified site Verified site
Audit size Up to 500 pages (larger requests: 409 site_not_verified) Up to your plan's page limit
Crawl speed Up to 3 req/s Up to 10 req/s (the site's max_rps)
Scheduled monitoring (weekly or daily) Not available Available on Starter and Growth
Google tab (Search Console data) Not available Available
IndexNow submissions Not available Available
Rechecks to verify fixes Not available Available
Crawler secret header (X-SEOFix-Verify) Not sent Sent, so your firewall can let SEOFixBot through

Methods

The card lists the methods in this order. Each one has a Check now button (Search Console and Cloudflare verify as part of connecting).

Method What you do Covers
Google Search Console Connect the Google account that is Owner or Full user of a property covering the site A domain property (sc-domain:example.com) covers the domain and every subdomain. A URL-prefix property covers that exact origin only.
Cloudflare Paste an API token, or add the record and rule yourself The registrable domain and every subdomain (it is the DNS TXT method)
Homepage tag Add a <meta> tag to the homepage <head> That origin only
DNS record Add one TXT record on the registrable domain The domain and every subdomain
Verification file Serve a small text file under /.well-known/ That origin only

The verification token is public by design: it ends up in your DNS or your HTML. It is not the crawler secret, which stays private. See Let SEOFix through your firewall.

Google Search Console

Choose the Google Search Console method, then sign in with the Google account that owns the site in Search Console (Owner or Full user). SEOFix asks for read-only access. The same connection feeds the Google tab. Details: Connect Google Search Console.

A property only proves ownership with the permission level Owner or Full user. A URL-prefix property with a path (such as https://example.com/blog/) does not prove the whole site.

Cloudflare

If your DNS is on Cloudflare, either connect a scoped API token (SEOFix adds the TXT record and a firewall rule for you) or choose Do it myself (no API token) and add both by hand. Details: Connect Cloudflare.

DNS TXT record

Add one TXT record on your registrable domain (for blog.example.com, the record goes on example.com):

Name Type Value
example.com (often written @) TXT seofix-verify=<verification token>

The card detects your DNS host from the domain's nameservers and shows its steps. Hosts with their own steps: Cloudflare, GoDaddy, Namecheap, Vercel, Netlify DNS (including NS1), Amazon Route 53, Hostinger, Squarespace Domains, Google Cloud DNS, Porkbun, IONOS and DigitalOcean. Any other host gets generic steps.

Once the record is on screen, the card checks for it automatically every 2 minutes for 60 minutes while the page is open. DNS changes can take a few minutes, sometimes longer. You can also choose Check now.

A site whose address is an IP has no domain, so the DNS method is not available. Use the tag or the file.

Homepage meta tag

Add this tag inside the <head> of https://<your-host>/, deploy, then choose Check now:

<meta name="seofix-verification" content="<verification token>">
  • The tag must be in the HTML your server sends, as a real element in the <head> before any body content. A tag added by JavaScript after load is not seen.
  • SEOFix reads the first 256 KB of the homepage over HTTPS.
  • It follows at most one redirect, and only to the same host or between example.com and www.example.com, over HTTPS.

Verification file

  1. Create a plain-text file at https://<your-host>/.well-known/seofix-verify.txt.
  2. Put exactly this line in it: seofix-verify=<verification token> (trailing whitespace is fine).
  3. Serve it with HTTP 200 directly (no redirects), Content-Type: text/plain, at most 1 KB.

Ask your coding agent

The tag and file methods have Ask my agent to do it. It copies a one-paragraph prompt for Claude Code, Codex or Cursor: add the tag (or the file) in the site's codebase, deploy, then call verify_site with method: "meta" (or "file"). The prompt contains only the public verification token, never the crawler secret or an API key. The same prompt is methods.agent_prompt in GET /v1/sites/{id}/verification.

Verify through the API

Get every method and what to publish:

curl https://api.seofix.ai/v1/sites/42/verification \
  -H "Authorization: Bearer $SEOFIX_API_KEY"
{
  "verified": false,
  "via": null,
  "checked_at": null,
  "lost_at": null,
  "methods": {
    "gsc": {"connected": false, "property": null},
    "dns": {"name": "example.com", "type": "TXT", "value": "seofix-verify=…", "provider": {"provider": "cloudflare", "name": "Cloudflare", "steps": ["…"]}},
    "meta": {"url": "https://example.com/", "tag": "<meta name=\"seofix-verification\" content=\"…\">"},
    "file": {"url": "https://example.com/.well-known/seofix-verify.txt", "body": "seofix-verify=…"},
    "cloudflare": {"connected": false, "zone": null, "token_link": "https://dash.cloudflare.com/…"},
    "agent_prompt": "Verify ownership of https://example.com/ for SEOFix. …"
  }
}

Then check:

curl -X POST https://api.seofix.ai/v1/sites/42/verify \
  -H "Authorization: Bearer $SEOFIX_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"method": "meta"}'
  • method is one of gsc, dns, meta, file. Leave it out to try every method in this order: Search Console, DNS (Cloudflare counts as DNS), meta tag, file.
  • Success returns the site with verified: true, verified_via and checked, the result of each method checked (match, mismatch, inconclusive or n/a).
  • If no checked method matches, the answer is 422 verification_failed with a message listing what to publish.
  • The endpoint allows 10 calls per minute.

MCP: get_verification, then verify_site with site_id and an optional method.

verified_via is gsc, dns, cloudflare, meta or file. It is cloudflare when the TXT record is the one SEOFix created through a Cloudflare connection.

Daily re-check

SEOFix re-checks ownership of every site once a day, so keep the proof in place. The verified card shows "Last checked" and a Re-check button that runs the check now.

Each method's check ends as one of:

  • match: the proof is there.
  • mismatch: the proof is gone or wrong (for example a 404 for the file, or a homepage without the tag).
  • inconclusive: SEOFix could not tell. Examples: a network error or timeout, a 5xx or 429 answer, a 401 or 403 (often a firewall challenge), a redirect it does not follow, a DNS lookup that fails.

An inconclusive check never verifies a site, but it also does not take verification away right away: a site keeps its state while the method that verified it answers inconclusively.

The 14-day cap

For the DNS, meta tag and file methods, that grace period is capped. If the method that verified the site answers inconclusively on every check for more than 14 days, the site loses verification as if the proof had been removed. Any match resets the clock. Search Console is not capped, because a Google outage would affect every site at once.

If you use the file or the meta tag, make sure your firewall lets SEOFix read that path. A firewall challenge on the homepage or on /.well-known/seofix-verify.txt makes the check inconclusive.

When verification lapses

A site loses verification when the proof it was verified with no longer holds and no other proof matches, or after the 14-day cap. Then:

  • The site card shows Ownership lost on (date).
  • Scheduled monitoring is paused. SEOFix remembers the frequency you had.
  • The Google sync is paused. Your reports are kept.
  • New audits fall back to 500 pages and 3 req/s, and the crawler secret header is no longer sent.
  • If the site has alert emails on, every team member gets an email.

Verify again with any method and SEOFix resumes: monitoring comes back at its earlier frequency if your plan includes monitoring.

More in Sites & firewalls

Still stuck? Email [email protected] with your site and what you expected to see.