Does the record give Ottom access to my DNS or my store?
No. We only read it, the way anybody on the internet can. It proves that whoever controls the domain agreed, and nothing else.
A store’s owner proves the store is theirs by publishing a TXT record we issue at the store’s domain and asking us to check it. A proved store can change how our agent treats it, such as what it does with a cookie banner. This page gives the steps, how long a record lasts and what to do when a check does not find it.
Open the store in your dashboard and press "Get the record" under How we measure this store. You see a host, the type TXT and a value that starts ottom-verification=. If we emailed you a record, that one works too.
Where your domain’s DNS is managed, add a TXT record. For a store on its own domain, such as example.com or www.example.com, the host or name is @. For a store on a subdomain, such as shop.example.com, the host is that subdomain: shop. Paste the whole value, ottom-verification= included, with nothing added before or after it.
A new record usually reaches the rest of the internet within minutes. Some providers take a few hours. Nothing breaks while you wait.
Back on the store’s page, press "Check now". We look the record up, and once it matches the store is verified. You can delete the record after that.
Only the store’s owner: the account that first added or scanned it. Somebody else in your workspace, or the account paying for the plan, sees the store but is not offered the record. If somebody else holds a store that is yours, write to us rather than publishing a record.
A record is valid for 14 days from when we issue it. Publish it and check within that time. After it, ask for a new one.
Asking for a new record cancels the one before it. If you have already published a record, check that one first rather than asking again, or replace it with the new value.
A store on a platform’s shared domain, such as a myshopify.com address, has no DNS zone of its own to publish in, so it cannot be proved this way. On Shopify, installing our Shopify app proves the store instead. Otherwise, add the store by its own domain and prove that.
An agency adding a client’s store to a workspace by DNS uses the same kind of record, published the same way. That record adds the store to the workspace. It does not make anybody the store’s owner. How a store joins a workspace is on the workspaces page.
It may not have propagated yet. Wait and press "Check now" again. You can also look it up yourself with a public DNS lookup tool for TXT records on the store’s host.
Some providers split a long TXT value into quoted chunks. That is fine: we join them before comparing. What matters is that nothing is missing and nothing extra was added.
A provider that adds your domain to whatever you type turns example.com into example.com.example.com. Use @ for the domain itself and only the subdomain part for a subdomain.
After 14 days a record no longer counts. Get a new one from the dashboard, replace the old value with it, and check again.
No. We only read it, the way anybody on the internet can. It proves that whoever controls the domain agreed, and nothing else.
Yes. Verification is recorded when the check succeeds and does not depend on the record staying there.
No. Scans, reports and alerts work the same without it. Proving the store only lets you change how our agent treats it.
Your stores and their records are on your dashboard.