Domain verification
Understanding Attestations
What an attestation is
An attestation is a signed, timestamped record proving you are authorized to monitor a domain. It is what makes your SSL and DNS evidence audit-ready: each attestation records who attested, when, and for which domain. You attest a domain once; the record then stands behind your ongoing monitoring.
Types
- Owner — you prove control of your own domain.
- Authorized agent — you attest on a client's behalf (common for agencies).
- Client authorized — your end-customer grants you permission to monitor.
Creating one
Go to Attestations → New (/app/attestations/new/), pick the asset, and choose a verification method. The wizard shows a one-time challenge token:
- DNS TXT — add a
_merlonix-verify.<host>TXT record with the token (valid 24 hours). - HTTP file — publish the token at
https://<host>/.well-known/merlonix-<token>.txtover HTTPS (valid 24 hours). - Admin email — receive a link at a standard admin mailbox (admin@, administrator@, hostmaster@, webmaster@, postmaster@) and click it (valid 72 hours).
Full step-by-step instructions are in "Verifying a Domain You Monitor".
Managing attestations
The Attestations list (/app/attestations/) shows each record's domain, type, status (signed or revoked), and signed date. Open one to read its full statement, or Revoke it to mark it inactive. The IP address and browser used at creation are recorded for the audit trail.
More in Domain verification
Try it on your own sites
Point Merlonix at your client domains and watch SSL, DNS, uptime, and vendor status from one dashboard. Start the full workspace free, no credit card.