XiaTools

What Is a TXT Record and How to Validate It

Updated 30 Sept 2026

A TXT (text) record is a type of resource record in the Domain Name System that allows domain administrators to insert arbitrary text into the DNS. It is primarily used for human-readable notes, domain ownership verification, and critical email security protocols like SPF, DKIM, and DMARC.

Understanding the Basics of DNS TXT Records

When the Domain Name System was originally designed, its main purpose was straightforward: map human-readable domain names like example.com to numerical IP addresses. However, as the internet grew, administrators needed a standardized way to associate machine-readable or human-readable text strings with a domain without breaking existing protocol structures.

This led to the creation of the TXT record. A TXT record has no rigid structural formatting enforced by the core DNS protocol itself. Instead, the applications that query the DNS—such as email servers, certificate authorities, and cloud hosting providers—interpret the string inside the record according to their own specific rules.

Common Use Cases for TXT Records

While you can technically put any string into a TXT record, they are practically used for a few well-defined purposes:

  • Domain Ownership Verification: Services like Google Workspace, Microsoft 365, and certificate authorities like Let's Encrypt require you to add a unique TXT record to prove you control the domain.
  • Sender Policy Framework (SPF): Defines which mail servers are authorized to send email on behalf of your domain.
  • DomainKeys Identified Mail (DKIM): Publishes the public cryptographic key used by receiving mail servers to verify the digital signature on your outgoing emails.
  • Domain-based Message Authentication, Reporting, and Conformance (DMARC): Tells receiving mail servers what to do if an email fails SPF or DKIM checks.

The Anatomy of a TXT Record

When you log into your DNS hosting provider, you will typically see four main fields when creating a new record:

  1. Type: Set to TXT.
  2. Host / Name: The subdomain or root domain the record applies to. For example, @ or blank for the root domain example.com, or _dmarc for a DMARC record.
  3. TTL (Time to Live): How long caching nameservers should store the record before querying again (e.g., 3600 seconds).
  4. Value / Content: The actual text string enclosed in quotes.

For example, a basic SPF record looks like this in your DNS zone file:

example.com. IN TXT "v=spf1 include:_spf.google.com ~all"

Step-by-Step Guide to Adding a TXT Record

Adding a TXT record is a straightforward process, but it requires access to the DNS management console of the registrar or hosting provider where your domain's nameservers are hosted.

Step 1: Access Your DNS Management Panel

Log into your domain registrar or third-party DNS provider (such as Cloudflare, AWS Route 53, or cPanel). Navigate to the DNS management, DNS zone editor, or advanced DNS settings page for your target domain.

Step 2: Create a New Record

Select the option to add a new record. Change the record type from A or CNAME to TXT.

Step 3: Enter the Host and Value Fields

Depending on what you are configuring, enter the appropriate host name and value string. For instance, if you are setting up Google Workspace verification, the interface might look like this:

  • Type: TXT
  • Name / Host: @ (or leave empty for example.com)
  • Value: google-site-verification=rX9kL2mN5pQ8sT1vW4yZ6aB3dF7hJ0kL

Step 4: Save the Record

Click save or add record. If your DNS provider uses zone file syntax, ensure your value is wrapped in double quotes if required by their parser.

How to Validate Your TXT Records

Once you publish a DNS change, it does not become globally available instantly. You must wait for global DNS propagation, which is governed by the TTL value you set on the previous record and the caching policies of intermediate nameservers.

To ensure your records are correctly published and readable across the global internet, you should perform a manual validation check. You can quickly inspect your domain configuration using a real-time txt lookup tool to see the exact text records currently visible to public recursive resolvers.

Validating via Command Line

If you prefer using terminal tools, you can query TXT records directly using dig or nslookup.

Using dig on Linux or macOS:

dig TXT example.com +short

Using nslookup on Windows:

nslookup -type=TXT example.com

If your provider has propagated the change, the terminal will output the exact text string you saved in your DNS zone.

Troubleshooting Common TXT Record Issues

Even experienced engineers occasionally run into configuration errors with TXT records. Here are the most frequent issues and how to fix them:

1. Syntax Errors and Quotation Marks

Many DNS control panels automatically handle quotation marks, while others require you to include them. If your record fails validation, check whether your string contains unescaped special characters, unclosed quotes, or exceeds the traditional 255-character limit per string block. Modern DNS servers handle longer strings by splitting them into multiple character strings, but formatting errors can still break email authentication protocols like SPF.

2. Multiple SPF Records

A common mistake is creating multiple TXT records for SPF on the same domain. A domain must only have one SPF record. If you have multiple services sending mail, combine them into a single string like so:

"v=spf1 include:_spf.google.com include:mail.example.com ~all"

3. Propagation Delays

If you just added or updated a record and validation fails, wait 10 to 15 minutes. Global DNS propagation can take time depending on your TTL settings and the caching behavior of public DNS resolvers like 8.8.8.8 or 1.1.1.1.

Summary Checklist for TXT Records

  • Confirm you have selected TXT as the record type in your DNS panel.
  • Ensure the host field matches the requirement (e.g., @ for root, _dmarc for DMARC).
  • Verify that text strings are properly formatted without conflicting characters.
  • Check that you only have a single SPF record if configuring email authentication.
  • Run a remote query to confirm public visibility and successful propagation.

Frequently asked questions

What is a DNS TXT record used for?

A TXT record allows domain owners to associate arbitrary text with their domain. It is primarily used for domain ownership verification by third-party services and for implementing critical email security frameworks like SPF, DKIM, and DMARC.

How long does it take for a TXT record to update?

DNS changes typically take anywhere from a few minutes to 24 hours to propagate globally. The exact time depends on the TTL value you assigned to the record and how long intermediate caching nameservers hold onto the previous lookup results.

Can I have multiple TXT records on the same domain?

Yes, you can have multiple TXT records on the same domain or subdomain for different services, such as separate verification codes for Google and Microsoft. However, you must never have more than one SPF record per domain.

Why is my SPF TXT record failing validation?

SPF validation usually fails due to syntax typos, exceeding the maximum DNS lookup limit of 10 DNS-mechanisms, or having multiple SPF records defined on the root domain instead of a single merged record.

How do I check if my TXT record is set up correctly?

You can verify your configuration by using a command-line tool like dig or nslookup, or by using an online DNS lookup utility to check what public nameservers currently return for your domain.

Related articles

Free tools