Domain verification

Understanding Attestations

attestationsevidenceauditdomainverificationcompliance

What an attestation is

An attestation is a signed, timestamped record proving you are authorized to monitor a domain. It is what makes your SSL and DNS evidence audit-ready: each attestation records who attested, when, and for which domain. You attest a domain once; the record then stands behind your ongoing monitoring.

Types

  • Owner — you prove control of your own domain.
  • Authorized agent — you attest on a client's behalf (common for agencies).
  • Client authorized — your end-customer grants you permission to monitor.

Creating one

Go to Attestations → New (/app/attestations/new/), pick the asset, and choose a verification method. The wizard shows a one-time challenge token:

  • DNS TXT — add a _merlonix-verify.<host> TXT record with the token (valid 24 hours).
  • HTTP file — publish the token at https://<host>/.well-known/merlonix-<token>.txt over HTTPS (valid 24 hours).
  • Admin email — receive a link at a standard admin mailbox (admin@, administrator@, hostmaster@, webmaster@, postmaster@) and click it (valid 72 hours).

Full step-by-step instructions are in "Verifying a Domain You Monitor".

Managing attestations

The Attestations list (/app/attestations/) shows each record's domain, type, status (signed or revoked), and signed date. Open one to read its full statement, or Revoke it to mark it inactive. The IP address and browser used at creation are recorded for the audit trail.

More in Domain verification

Try it on your own sites

Point Merlonix at your client domains and watch SSL, DNS, uptime, and vendor status from one dashboard. Start the full workspace free, no credit card.