# Verify site ownership

> Prove you own a site with Search Console, Cloudflare, a DNS TXT record, a homepage meta tag or a verification file, and what verification unlocks.

Source: https://seofix.ai/help/verifying-site-ownership · Category: Sites & firewalls · Updated: 2026-10-08

Any one proof verifies a site: a Google Search Console property, Cloudflare, a DNS TXT record, a homepage meta tag or a file at `/.well-known/seofix-verify.txt`. In the app, open the site page and pick a method on the card **Unlock monitoring, Google's indexing data and agent fixing**. Agents: `get_verification` then `verify_site` (MCP), or `GET /v1/sites/{id}/verification` then `POST /v1/sites/{id}/verify`.

## What verification unlocks

Anyone can audit a public site, so SEOFix keeps the heavier features for sites whose owner has proved control.

| Feature | Unverified site | Verified site |
|---|---|---|
| Audit size | Up to 500 pages (larger requests: `409 site_not_verified`) | Up to your plan's page limit |
| Crawl speed | Up to 3 req/s | Up to 10 req/s (the site's `max_rps`) |
| Scheduled monitoring (weekly or daily) | Not available | Available on Starter and Growth |
| Google tab (Search Console data) | Not available | Available |
| IndexNow submissions | Not available | Available |
| Rechecks to verify fixes | Not available | Available |
| Crawler secret header (`X-SEOFix-Verify`) | Not sent | Sent, so your firewall can let SEOFixBot through |

## Methods

The card lists the methods in this order. Each one has a **Check now** button (Search Console and Cloudflare verify as part of connecting).

| Method | What you do | Covers |
|---|---|---|
| Google Search Console | Connect the Google account that is Owner or Full user of a property covering the site | A domain property (`sc-domain:example.com`) covers the domain and every subdomain. A URL-prefix property covers that exact origin only. |
| Cloudflare | Paste an API token, or add the record and rule yourself | The registrable domain and every subdomain (it is the DNS TXT method) |
| Homepage tag | Add a `<meta>` tag to the homepage `<head>` | That origin only |
| DNS record | Add one TXT record on the registrable domain | The domain and every subdomain |
| Verification file | Serve a small text file under `/.well-known/` | That origin only |

The verification token is public by design: it ends up in your DNS or your HTML. It is not the crawler secret, which stays private. See [Let SEOFix through your firewall](https://seofix.ai/help/firewall-allowlisting.md).

### Google Search Console

Choose the **Google Search Console** method, then sign in with the Google account that owns the site in Search Console (Owner or Full user). SEOFix asks for read-only access. The same connection feeds the Google tab. Details: [Connect Google Search Console](https://seofix.ai/help/connect-google-search-console.md).

A property only proves ownership with the permission level Owner or Full user. A URL-prefix property with a path (such as `https://example.com/blog/`) does not prove the whole site.

### Cloudflare

If your DNS is on Cloudflare, either connect a scoped API token (SEOFix adds the TXT record and a firewall rule for you) or choose **Do it myself (no API token)** and add both by hand. Details: [Connect Cloudflare](https://seofix.ai/help/connect-cloudflare.md).

### DNS TXT record

Add one TXT record on your registrable domain (for `blog.example.com`, the record goes on `example.com`):

| Name | Type | Value |
|---|---|---|
| `example.com` (often written `@`) | TXT | `seofix-verify=<verification token>` |

The card detects your DNS host from the domain's nameservers and shows its steps. Hosts with their own steps: Cloudflare, GoDaddy, Namecheap, Vercel, Netlify DNS (including NS1), Amazon Route 53, Hostinger, Squarespace Domains, Google Cloud DNS, Porkbun, IONOS and DigitalOcean. Any other host gets generic steps.

Once the record is on screen, the card checks for it automatically every 2 minutes for 60 minutes while the page is open. DNS changes can take a few minutes, sometimes longer. You can also choose **Check now**.

A site whose address is an IP has no domain, so the DNS method is not available. Use the tag or the file.

### Homepage meta tag

Add this tag inside the `<head>` of `https://<your-host>/`, deploy, then choose **Check now**:

```html
<meta name="seofix-verification" content="<verification token>">
```

- The tag must be in the HTML your server sends, as a real element in the `<head>` before any body content. A tag added by JavaScript after load is not seen.
- SEOFix reads the first 256 KB of the homepage over HTTPS.
- It follows at most one redirect, and only to the same host or between `example.com` and `www.example.com`, over HTTPS.

### Verification file

1. Create a plain-text file at `https://<your-host>/.well-known/seofix-verify.txt`.
2. Put exactly this line in it: `seofix-verify=<verification token>` (trailing whitespace is fine).
3. Serve it with HTTP 200 directly (no redirects), `Content-Type: text/plain`, at most 1 KB.

### Ask your coding agent

The tag and file methods have **Ask my agent to do it**. It copies a one-paragraph prompt for Claude Code, Codex or Cursor: add the tag (or the file) in the site's codebase, deploy, then call `verify_site` with `method: "meta"` (or `"file"`). The prompt contains only the public verification token, never the crawler secret or an API key. The same prompt is `methods.agent_prompt` in `GET /v1/sites/{id}/verification`.

## Verify through the API

Get every method and what to publish:

```bash
curl https://api.seofix.ai/v1/sites/42/verification \
  -H "Authorization: Bearer $SEOFIX_API_KEY"
```

```json
{
  "verified": false,
  "via": null,
  "checked_at": null,
  "lost_at": null,
  "methods": {
    "gsc": {"connected": false, "property": null},
    "dns": {"name": "example.com", "type": "TXT", "value": "seofix-verify=…", "provider": {"provider": "cloudflare", "name": "Cloudflare", "steps": ["…"]}},
    "meta": {"url": "https://example.com/", "tag": "<meta name=\"seofix-verification\" content=\"…\">"},
    "file": {"url": "https://example.com/.well-known/seofix-verify.txt", "body": "seofix-verify=…"},
    "cloudflare": {"connected": false, "zone": null, "token_link": "https://dash.cloudflare.com/…"},
    "agent_prompt": "Verify ownership of https://example.com/ for SEOFix. …"
  }
}
```

Then check:

```bash
curl -X POST https://api.seofix.ai/v1/sites/42/verify \
  -H "Authorization: Bearer $SEOFIX_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"method": "meta"}'
```

- `method` is one of `gsc`, `dns`, `meta`, `file`. Leave it out to try every method in this order: Search Console, DNS (Cloudflare counts as DNS), meta tag, file.
- Success returns the site with `verified: true`, `verified_via` and `checked`, the result of each method checked (`match`, `mismatch`, `inconclusive` or `n/a`).
- If no checked method matches, the answer is `422 verification_failed` with a message listing what to publish.
- The endpoint allows 10 calls per minute.

MCP: `get_verification`, then `verify_site` with `site_id` and an optional `method`.

`verified_via` is `gsc`, `dns`, `cloudflare`, `meta` or `file`. It is `cloudflare` when the TXT record is the one SEOFix created through a Cloudflare connection.

## Daily re-check

SEOFix re-checks ownership of every site once a day, so keep the proof in place. The verified card shows "Last checked" and a **Re-check** button that runs the check now.

Each method's check ends as one of:

- **match**: the proof is there.
- **mismatch**: the proof is gone or wrong (for example a 404 for the file, or a homepage without the tag).
- **inconclusive**: SEOFix could not tell. Examples: a network error or timeout, a 5xx or 429 answer, a 401 or 403 (often a firewall challenge), a redirect it does not follow, a DNS lookup that fails.

An inconclusive check never verifies a site, but it also does not take verification away right away: a site keeps its state while the method that verified it answers inconclusively.

### The 14-day cap

For the DNS, meta tag and file methods, that grace period is capped. If the method that verified the site answers inconclusively on every check for more than 14 days, the site loses verification as if the proof had been removed. Any match resets the clock. Search Console is not capped, because a Google outage would affect every site at once.

If you use the file or the meta tag, make sure your firewall lets SEOFix read that path. A firewall challenge on the homepage or on `/.well-known/seofix-verify.txt` makes the check inconclusive.

## When verification lapses

A site loses verification when the proof it was verified with no longer holds and no other proof matches, or after the 14-day cap. Then:

- The site card shows **Ownership lost on (date)**.
- Scheduled monitoring is paused. SEOFix remembers the frequency you had.
- The Google sync is paused. Your reports are kept.
- New audits fall back to 500 pages and 3 req/s, and the crawler secret header is no longer sent.
- If the site has alert emails on, every team member gets an email.

Verify again with any method and SEOFix resumes: monitoring comes back at its earlier frequency if your plan includes monitoring.

## Related

- [Connect Cloudflare](https://seofix.ai/help/connect-cloudflare.md)
- [Connect Google Search Console](https://seofix.ai/help/connect-google-search-console.md)
- [Let SEOFix through your firewall](https://seofix.ai/help/firewall-allowlisting.md)
- [Add and remove sites](https://seofix.ai/help/adding-sites.md)
