Skip to content
BriefCatch
Esc
navigateopen⌘Jpreview
On this page

Verified domains and automatic membership

Prove your organization owns an email domain with a DNS record, then use it for automatic membership and SSO discovery.

Goal: prove your organization controls an email domain. Domain proof is the foundation the rest of identity management is built on — it is shared by automatic membership and by enterprise SSO discovery.

Step 1: Review prerequisites

  • Your role is admin or owner.
  • You can add a DNS TXT record for the domain, or you have someone who can. Verification is a DNS challenge, so this usually means whoever administers your domain’s DNS.

Step 2: Add the domain

Go to Settings → Security → Domain and add your company domain. It moves straight to a DNS pending state with a challenge attached.

Step 3: Publish the DNS record

BriefCatch gives you a record name and a value to publish as a TXT record. Use Copy record name rather than retyping it.

Publish the record with your DNS provider, then return to BriefCatch and select Check verification. DNS changes are not instant. If the check fails immediately after you publish, wait for propagation and check again rather than assuming the record is wrong.

While the challenge is outstanding you will see “The DNS proof could not be verified. The domain remains pending.” That is the normal state before propagation completes, not an error you need to report.

If a challenge goes stale, Replace challenge issues a fresh one. You then publish the new value in place of the old.

Step 4: Use the verified domain

Once verified, the domain becomes available to the features that depend on it:

Feature What the verified domain does
Automatic membership People with an email address at your domain can join your organization directly, instead of waiting for an individual invitation
Enterprise SSO Sign-in discovery routes your domain’s users to your identity provider. Verify the domain before configuring SSO — the SSO screen prompts you to

Automatic membership is governed by a membership policy on the same screen. Turning a domain on does not by itself hand your organization to anyone who registers an address at it — review the policy before enabling it, and remember that new members consume licensed seats. See Teams and organizations and Plans and licenses.

Removing a domain

A verified domain can be disabled. Disabling one that SSO relies on affects how your people sign in, so check what depends on it first. See Set up single sign-on.

If a domain will not verify

  • The check fails right after publishing. Wait for DNS propagation and check again.
  • The record is published but not found. Confirm you published it at the exact record name BriefCatch gave you, as a TXT record, on the same domain you added.
  • “This domain conflicts with an existing verified claim. Contact BriefCatch support if your organization controls it.” Another organization already holds a verified claim on that domain. BriefCatch will not let two organizations claim the same one, so support is the intended route rather than a workaround.
  • “Enter a valid company domain.” The address was rejected as malformed.
  • “The domain could not be added. If your organization controls it, contact BriefCatch support.” The general failure message, shown when the cause is not one of the specific cases above.

Was this page helpful?