如何通过DNS验证域名所有权?ZeroSSL SSL证书申请验证求助
Hey there, I’ve walked countless people through ZeroSSL’s DNS verification process, so let’s get this sorted for you now that your reference blog steps are out of date. Here’s a straightforward, up-to-date breakdown:
1. Log into your domain’s DNS management dashboard
First, access the control panel of your DNS provider—whether that’s Cloudflare, GoDaddy, Alibaba Cloud, Namecheap, or any other service that hosts your domain’s DNS settings. This is where you normally edit your domain’s DNS records.
2. Create the required TXT records
ZeroSSL requires two separate TXT records to verify domain ownership. Fill in these details for each record:
- Record Type: Select
TXTfrom the dropdown menu - Host/Prefix: Enter
_acme-challenge(most providers automatically append your main domainexample.comto this, so the full record name becomes_acme-challenge.example.com—no need to type the full domain unless your provider explicitly requires it) - Record Value: Use one of the strings ZeroSSL provided for each record: first add
string_removed_here, then create a second TXT record withanother string here - TTL: Set this to the smallest possible value (like 60 seconds) to speed up record propagation across the internet
3. Verify the records are active
ZeroSSL mentions a 15-20 minute wait, but sometimes propagation happens faster. To check if the records are live, open your terminal (Command Prompt on Windows, Terminal on Mac/Linux) and run this command:
nslookup -q=TXT _acme-challenge.example.com
If the output includes both of your TXT values, the records are ready. If not, double-check your inputs and wait a bit longer for propagation.
4. Finalize verification on ZeroSSL
Once you confirm the records are active, go back to your ZeroSSL certificate application page and click the "Verify" button. The platform will scan your DNS records, and once it detects the correct TXT entries, it’ll proceed to issue your SSL certificate.
Quick troubleshooting tips
- If you’re using Cloudflare or another CDN, make sure the cloud icon next to your TXT record is gray (proxy mode disabled)—ZeroSSL can’t detect records that are proxied through a CDN.
- Double-check for typos in the host prefix or record values—even a single extra space can break verification.
- If propagation takes way longer than 20 minutes, reach out to your DNS provider to confirm there’s no delay on their end.
内容的提问来源于stack exchange,提问作者Black Mamba

