Facebook domain verification is how you claim a website as an asset of your business portfolio in Meta Business Suite, the thing most people still call Facebook. It is free, it is not the same thing as business verification, and on WordPress it needs no theme code at all.
Most guides on this are out of date in one specific way, which is covered below, because it changes whether you need to do it at all.
Where you do it
Meta Business Suite, then Settings, then Brand safety, then Domains. Add the domain, choose a method, and verify.
The three methods, and you only need one
Meta offers a meta tag, an uploaded HTML file, and a DNS TXT record. Pick whichever suits you. Meta's own wording is that you only need to use one.
The meta tag
Meta hands you a tag in this shape.
<meta name="facebook-domain-verification" content="..." />
It goes in the head of the home page, and the value has to match what Meta issued, character for character. The detail that catches people out is that Meta's crawler does not run JavaScript, so a tag injected by a script in the browser is never seen. It has to be in the HTML the server sends.
If you are unsure what the crawler is getting, Meta's Sharing Debugger shows the scraped version of the page, and Scrape Again forces a fresh fetch.
The HTML file
Download the file, upload it to the domain root, and do not edit it. The contents have to stay exactly as they came.
The DNS TXT record
Add the record at your registrar. Meta says this usually takes minutes and can take up to 72 hours, so check it with a TXT lookup before pressing verify.
Doing it on WordPress without touching theme files
WordPress has no core field for arbitrary head HTML. The Custom HTML block is a content block, so whatever you put in it lands in the page body, and the body is not where Meta looks.
The routes that work are a snippet plugin or an SEO plugin with a custom tag field.
WPCode, formerly Insert Headers and Footers, is free and exists for exactly this, adding code to the head without editing theme files. Rank Math has a Custom Webmaster Tags field that takes any platform's meta tag, one per line. SEOPress has a custom tracking code area. Header and Footer Scripts, and the similarly named plugin from WP Brigade, do the same job.
One caveat applies to all of them. The tag stops being output if the plugin is deactivated, and a page cache or a minifier can serve a version of the HTML without it. Load the live page and view the source after adding it, before you press verify.
What Facebook domain verification is for now
This is where most guides are wrong. Older articles say a verified domain is required for the Meta Pixel and for Aggregated Event Measurement. Neither is true today.
The Pixel's own setup requirements are the base code and nothing else, and domain verification is not among them. Meta now states that you are not required to verify your domains for event configuration, and the Aggregated Event Measurement tab has been removed from Events Manager, along with the eight-event prioritisation and the conversion domain step at campaign level.
Search for this and you will find the old instructions everywhere. They describe a requirement that no longer exists.
What verification is still used for, per Meta, is narrower. Editing permissions for ad links and organic links, registering a news Page in the index, selling through Facebook commerce, managing many Pages without Open Graph markup, and one route inside business verification when a business has no phone or email on record.
Three things people confuse
Domain verification claims an asset and costs nothing. Business verification is a reviewed process in Security Center that can take up to 14 business days. Meta Verified for businesses is a paid subscription with a badge. They are separate, and completing one does not give you another.
What goes wrong
Subdomains cannot be verified, only the root domain, and a subdomain or a path is rejected outright. Verifying the root covers everything underneath it, with the exception that Facebook commerce can occasionally want one verified separately.
The entry has to be the bare root, which means just the domain, with no www prefix, no https scheme and no trailing slash. Content has to match exactly as well, both the tag value and the uploaded file, which must carry nothing else. That file has to sit at the root too, and only two redirect shapes are tolerated, the apex to www and http to https.
An expired certificate will stop the crawler, and Meta's own troubleshooting says so. If the tag is in place and verification still fails, check the certificate before anything else with our server check.
The one that wastes the most time is the domain already being verified by someone else. A domain can be verified by one business only, so if another business holds it, they have to share it with you, and the Request access route in the verify flow is where that begins. It happens often after a site changes hands.
Should the tag stay in place
Meta's two documents disagree. The Help Center says you can remove the meta tags, DNS records and HTML file once the domain is verified and it will not affect your status. The developer documentation says to leave the tag on the home page because it may be checked periodically for verification purposes.
Leave it. It costs nothing to keep, and when two documents from the same company disagree, the cheap option is the safe one.
If you are setting the domain up in the first place, the nameservers and the records live in the same panel as everything else, which is the domain manager.
EnterraHost