Verify a domain
/v1/email/domains/{domain_id}/verifyconst domain = await bird.domains.verify("dom_01krdgeqcxet5s7t44vh8rt9mg");
console.log(domain.status); // "verified" once DNS is in placedomain = client.domains.verify("dom_01krdgeqcxet5s7t44vh8rt9mg")
print(domain.status)domain, err := client.Domains.Verify(context.Background(), "dom_123")
if err != nil {
log.Fatal(err)
}
fmt.Println(*domain.Status)$domain = $bird->domains->verify('dom_01krdgeqcxet5s7t44vh8rt9mg');
echo $domain->getStatus(); // "verified" once DNS is in placebird email domains verify <domain-id>curl -X POST "https://us1.platform.bird.com/v1/email/domains/{domain_id}/verify" \
-H "Authorization: Bearer $TOKEN"{
"id": "dom_01krdgeqcxet5s7t44vh8rt9mg",
"workspace_id": "ws_01krdgeqcxet5s7t44vh8rt9mg",
"domain": "mail.acme.com",
"vendor": "other",
"status": "pending",
"next": [
{
"kind": "operation"
}
],
"dkim": {
"mode": "txt",
"selector": "bird1",
"key_size": 2048
},
"capabilities": {
"sending": {
"status": "verified",
"pending": {
"domain": "rp.mail.acme.com",
"status": "pending"
}
},
"return_path": {
"status": "verified",
"pending": {
"domain": "rp.mail.acme.com",
"status": "pending"
}
},
"dmarc": {
"status": "verified",
"pending": {
"domain": "rp.mail.acme.com",
"status": "pending"
}
},
"tracking": {
"status": "verified",
"pending": {
"domain": "rp.mail.acme.com",
"status": "pending"
}
},
"inbound": {
"status": "verified",
"pending": {
"domain": "rp.mail.acme.com",
"status": "pending"
}
}
},
"dns_records": [
{
"type": "TXT",
"purpose": "dkim",
"state": "active",
"status": "pending"
}
]
}
Runs a fresh DNS check across the domain's records (DKIM, return path, DMARC, tracking, inbound MX, and any staged changes) and returns the updated domain. Use it for an immediate result after publishing or correcting records. Get a sending domain only reports the last stored result. Published records are also re-checked for you automatically in the background.
A 200 with records still pending is not a failure: the records were
not found yet, which is normal while DNS propagates (minutes to hours).
Recently verified records are not re-queried, so the call is safe to
repeat while you wait.
Parameter
domain_idstringID of the domain to verify.
Antwort-Payload
idworkspace_iddomainThe sending domain name. Set at creation and immutable.
vendorThe DNS provider hosting this domain's nameservers, so you know which provider's dashboard to manage the required DNS records in. Returns other when the provider has not been detected or is not recognized.
Possible values: other, cloudflare, route53, godaddy, namecheap, google, azure, digitalocean, squarespace
statusDomain ownership verification, proven by the DKIM record. Readiness to
send or track is reported separately per capability under
capabilities.*.status.
pending: the DKIM record has not been published yet.verified: the DKIM record is in place; ownership is confirmed.failed: a DKIM record exists but does not match the expected value (for example a stale record from an earlier setup), or a previously verified record was removed. Correct the record to recover.temporary_failure: DNS resolution failed transiently, such as from a timeout or unreachable nameserver. Verification retries automatically; do not change the DNS records unless they are incorrect.rejected: the domain was refused for policy reasons and cannot be used for sending. Contact support if you believe this is an error.
Possible values: pending, verified, failed, temporary_failure, rejected
settingsPer-domain behavior toggles. Changes apply immediately to new sends.
nextWhat to do next about this domain, given the state it is in. Each entry names one action and says why it is worth taking, so you can act on this response without working out the order yourself. Present on reads that compute it: an empty list means there is nothing to do, and the field is absent entirely on responses that do not report next actions.
This answers whether you own the domain, which is what status reports. What each
capability still needs before it can send or receive is reported separately under
capabilities, so an empty list here does not on its own mean the domain is ready.
dkimActive DKIM signing configuration for the domain.
capabilitiesdns_recordsThe domain's DNS records and their individual verification state, returned in full on both the list and single-domain responses. This is the complete set to publish across DKIM, return-path, DMARC, tracking, and inbound; records for a staged change carry state: pending. Inbound MX records are always included as a regional reference, even while receiving is off and capabilities.inbound.status is not_configured. Their presence alone does not mean receiving is enabled; see DomainUpdate.inbound.
Untergeordnete Attribute anzeigen
dns_records.typeThe DNS record type to publish, determined by purpose.
TXT: used for thedkimanddmarcpurposes.CNAME: used for thereturn_pathandtrackingpurposes.MX: used for theinbound_mxpurpose.
Possible values: TXT, CNAME, MX
dns_records.nameThe record name: the part you enter in your DNS provider's Name or Host field, relative to the DNS zone the record belongs in (your registered domain). For a sending domain mail.acme.com the DKIM record name is bird1._domainkey.mail, entered in the acme.com zone. @ for records at the zone apex.
dns_records.hostThe fully qualified hostname for this record (for example, bird1._domainkey.mail.acme.com).
dns_records.valueThe value to publish, as entered in your DNS provider's Value or Content field. For TXT, enter the full record content. For CNAME, enter the target hostname. For MX, enter the priority followed by the mail server hostname.
dns_records.purposeWhat this record is for.
dkim: signs outbound mail and proves domain ownership.return_path: identifies the return-path (bounce) CNAME for sending.tracking: identifies the optional branded open/click tracking CNAME.inbound_mx: identifies the MX record routing mail to us for receiving. Always present wherever inbound is available, as a regional reference, regardless of whether receiving is enabled; publishing it does not enable receiving on its own: seeDomainUpdate.inbound. It isoptionaluntil receiving is enabled, and publishing it before then is destructive: on a domain at the zone apex it replaces the MX records that carry the domain's existing mail.dmarc: identifies the DMARC policy record required for sending.
Possible values: dkim, return_path, tracking, inbound_mx, dmarc
dns_records.stateLifecycle state of this record.
active: the record backs the domain's current configuration.pending: the record belongs to a staged configuration change; publish it to complete the change.deprecated: the record belonged to a previous configuration. Keep it in DNS untilsafe_to_removeistrue; in-flight mail and previously sent tracked links may still resolve through it.
Possible values: active, pending, deprecated
dns_records.optionalWhether this record can be skipped. An optional record enables extra functionality (branded tracking, or receiving) rather than sending, so publish one only when you want what it enables. The inbound_mx records are optional until you enable receiving on the domain, and publishing one before then changes where mail to the domain is delivered.
dns_records.statusVerification status of this record's most recent DNS check.
pending: the record has not verified yet; publish it (or correct it) and it verifies on the next check.verified: the most recent check matched the expected value.warning: the record verified before and a recent check no longer matched, but it is still within the grace period. Sending is not yet affected; fix the record before the grace period ends to avoid it being blocked.failed: the record verified before but later checks kept failing past the grace period; the configuration has regressed and needs attention.
Possible values: pending, verified, warning, failed
dns_records.errorHuman-readable detail for a check that did not pass on this record: what was found in DNS and why it did not match. Also set while pending when the record is published but does not match the expected value, which is the case you can act on. null when the record is verified, when nothing is published at this name yet, or before the first check.
dns_records.safe_to_removeOnly set on deprecated records: true once the record is no longer referenced by in-flight mail or live tracked links and can be deleted from your DNS. null on active and pending records.
last_checked_atWhen we last checked this domain's DNS records, whether or not the outcome changed. Updated on every verification: your manual refresh and the periodic automatic re-checks alike. null if the domain has never been checked.
verified_atWhen the domain's ownership was confirmed: the moment status became verified via the DKIM record. Unchanged by later re-checks while it stays verified. null if the domain has never been verified.
created_atWhen the domain was added.
updated_atWhen the domain's configuration was last changed (such as a settings or return-path change). Verification re-checks do not change this; see last_checked_at and verified_at for verification timing.
Verwandte Ressourcen
Weiter mit der Dokumentation, Anleitungen und Beispielen zu diesem Thema.