SSO Domain Verification
Add the DNS TXT record Guard checks to prove you own a domain before it turns on SSO.
Before you add an SSO provider, prove that you own your email domain by adding a DNS TXT record.
Add the TXT record
- In Guard, go to Settings → Organization and click Add Provider in the Single Sign-On section.
- The Add SSO Provider dialog shows the value to add:
chariot=followed by your account's verification ID. Copy it. - In your DNS provider, add a TXT record at the root of your domain (@) with that value.
For example, for YourDomain.com:
Check the record
Run dig +short TXT YourDomain.com on macOS or Linux, or nslookup -type=TXT YourDomain.com on Windows, and look for your record in the output. DNS changes can take up to 48 hours to propagate, though they usually take effect within a few hours.
If verification fails, check that the record value matches the one in the Add SSO Provider dialog exactly.
Next steps
Finish the setup with the guide for your identity provider: Okta, Azure, or PingID.
You can remove the TXT record after setup, but add it back before you change the SSO configuration.
If you need help, contact support@praetorian.com.
Still need help? Ask the team