Skip to main content
Claiming your company’s email domain lets colleagues who sign in with an address there find your tenant, instead of each starting in an empty tenant of their own. Verifying it with DNS proves your company controls the domain. That keeps any other tenant from taking it over, and it’s required for Enterprise SSO.

Before you begin

  • You need the Admin or Owner tenant role, or be the tenant’s primary owner. See Organizations and roles.
  • You can claim only the domain of your own verified email address. If you sign in as ada@acme.com, you can claim acme.com.
  • A claim covers that exact domain. Claiming acme.com doesn’t cover eu.acme.com.
  • Addresses at free email providers, such as gmail.com or outlook.com, can’t be claimed.

Claim a domain

1

Open the Domains card

In the Recursion console, open Settings and choose General. The Domains card lists your tenant’s domains.
2

Add your domain

Under Add a domain, enter your domain, such as acme.com, and click Add domain.
A new claim is Invite only, so nothing changes for anyone until you choose who can join.

Verify it with DNS

Your verified address is enough to claim the domain, but until you verify it with DNS, another tenant whose admin has a verified address there can take it over by verifying it first. Verifying also unlocks Anyone can join, inviting people who already use Recursion, and Enterprise SSO.
1

Copy the TXT record

On the domain’s row, the card shows a TXT record with a Type, Name, and Value. The name is _recursion-verification. followed by your domain, and the value starts with recursion-domain-verification=. Use the copy buttons, since the value is unique to your claim.
2

Add it at your DNS provider

Create a TXT record with that name and value wherever your domain’s DNS is managed. It sits on its own name, so it doesn’t affect your existing records, such as SPF.
3

Check it

Click Check DNS record. New records can take a while to appear. If the check doesn’t find it yet, wait a few minutes and check again.
Once it’s verified, the domain shows Verified with DNS, and no other tenant can take it over. Keep the record in place.

Choose who can join

Each domain has its own join settings. Default role is the role people get when they join through the domain: User or Developer. Admin, owner, and billing roles are only given by invitation or a role change. An admin approving a request can pick another role, and members who already joined keep theirs when you change the default. Invite people from your domain who already use Recursion sends an invitation to everyone with an account at the domain. Each person accepts or declines it in Members › Invitations. It needs the domain verified with DNS.

Remove a domain

Click the remove button on the domain’s row and confirm. People at the domain no longer find or join your tenant through it. Members who already joined stay, and invitations already sent stay. Pending requests through the domain are closed.

What can go wrong

Next steps

Enterprise SSO

Let people at your verified domains sign in through your identity provider.

Organizations and roles

See what each role can do.