A domain in EnterraMon stays unmonitored until you prove you control it. There are three ways to do that, and you only need one.
Open the domain from Sites or Site and choose Verify domain. The dialog shows your verification code and the three methods.
The three methods
Pick whichever suits your setup. All three prove the same thing, and none of them is faster than the others in any way that matters.
DNS TXT record
Add a TXT record at the host _enterramon under the domain, with the code as its value.
_enterramon.example.com. TXT "enterramon-verify-XXXXXXXXXXXXXX"
This is the method to use when you control DNS but not the website, which is the common case for a domain whose hosting is managed by somebody else. It is also the one that needs patience, because a TXT record is subject to the TTL on the zone.
If your DNS provider keeps the zone behind a proxy, the record still needs to be publicly resolvable. The DNS lookup tool reads a record from five regions at once, so you can see whether the value is out before you ask EnterraMon to look.
HTML meta tag
EnterraMon gives you a tag to place in the <head> of the home page.
<meta name="enterramon-verify" content="XXXXXXXXXXXXXX" />
The value has to match character for character, and it has to be in the HTML the server sends. This method catches people out more than the other two, because a tag injected by JavaScript in the browser is not in the response, and a check that reads the raw response will never find it.
If you are not sure what your server is sending, the server check fetches the page and reports the status, the headers and the timing, which is usually enough to tell a tag that is missing from a tag that is present but wrong.
Text file
Download the KEY.txt file the dialog offers, upload it to the domain root, and leave its contents alone.
The file has to be reachable at the root of the domain. If your site is served from a subdirectory, or a rewrite sends unknown paths to an application, the file will not be found even though it is on disk.
Running the check
Choose a method, add the record or file, then press Verify now. EnterraMon re-checks the domain and moves it to active if it passes.
Nothing is cached from an earlier attempt. Each press is a fresh look, so pressing it again after a DNS change is the correct move rather than a hopeful one.
When it does not verify yet
The failure message names the record it looked for. The commonest one is that a TXT record was not found, or was found with a value that does not match.
DNS changes take time to reach every resolver, and the delay is the TTL on the record you are replacing plus however long your provider takes to publish. Fifteen minutes is typical. An hour is not unusual. The domain keeps its pending status the whole time and you can press verify as often as you like.
Two other causes are worth ruling out. A record added on www when the apex was needed, or the reverse, fails in a way that looks identical to propagation. And a wildcard record on the zone can answer for a hostname that has no record of its own, so the lookup succeeds while the value is wrong.
How DNS propagation works covers the caching behaviour behind this, and it is the article to read if a record is right in your provider’s panel and wrong everywhere else.
Changing the method later
The method that verified a domain is recorded, and it is the one that has to keep working. If you remove the TXT record after verifying, the next check may mark the domain unverified and stop monitoring it.
So leave the record in place. A stray TXT record costs nothing and removing it can silently take a site out of monitoring, which is the kind of failure you discover during the outage you wanted to be told about.
EnterraHost