Verified domains and automatic membership
Prove your organization owns an email domain with a DNS record, then use it for automatic membership and SSO discovery.
Goal: prove your organization controls an email domain. Domain proof is the foundation the rest of identity management is built on — it is shared by automatic membership and by enterprise SSO discovery.
Step 1: Review prerequisites
- Your role is admin or owner.
- You can add a DNS TXT record for the domain, or you have someone who can. Verification is a DNS challenge, so this usually means whoever administers your domain’s DNS.
Step 2: Add the domain
Go to Settings → Security → Domain and add your company domain. It moves straight to a DNS pending state with a challenge attached.
Step 3: Publish the DNS record
BriefCatch gives you a record name and a value to publish as a TXT record. Use Copy record name rather than retyping it.
Publish the record with your DNS provider, then return to BriefCatch and select Check verification. DNS changes are not instant. If the check fails immediately after you publish, wait for propagation and check again rather than assuming the record is wrong.
While the challenge is outstanding you will see “The DNS proof could not be verified. The domain remains pending.” That is the normal state before propagation completes, not an error you need to report.
If a challenge goes stale, Replace challenge issues a fresh one. You then publish the new value in place of the old.
Step 4: Use the verified domain
Once verified, the domain becomes available to the features that depend on it:
| Feature | What the verified domain does |
|---|---|
| Automatic membership | People with an email address at your domain can join your organization directly, instead of waiting for an individual invitation |
| Enterprise SSO | Sign-in discovery routes your domain’s users to your identity provider. Verify the domain before configuring SSO — the SSO screen prompts you to |
Automatic membership is governed by a membership policy on the same screen. Turning a domain on does not by itself hand your organization to anyone who registers an address at it — review the policy before enabling it, and remember that new members consume licensed seats. See Teams and organizations and Plans and licenses.
Removing a domain
A verified domain can be disabled. Disabling one that SSO relies on affects how your people sign in, so check what depends on it first. See Set up single sign-on.
If a domain will not verify
- The check fails right after publishing. Wait for DNS propagation and check again.
- The record is published but not found. Confirm you published it at the exact record name BriefCatch gave you, as a TXT record, on the same domain you added.
- “This domain conflicts with an existing verified claim. Contact BriefCatch support if your organization controls it.” Another organization already holds a verified claim on that domain. BriefCatch will not let two organizations claim the same one, so support is the intended route rather than a workaround.
- “Enter a valid company domain.” The address was rejected as malformed.
- “The domain could not be added. If your organization controls it, contact BriefCatch support.” The general failure message, shown when the cause is not one of the specific cases above.
Related
- Set up single sign-on — the feature that requires this
- Teams and organizations — invitations and membership
- Identity management — how the three features fit together