> ## Documentation Index
> Fetch the complete documentation index at: https://docs.labelbox.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Domains

> Claim your company's email domain, prove it with DNS, and choose whether people at it can find and join your tenant.

Claiming your company's email domain lets colleagues who sign in with an address there find your tenant, instead of each starting in an empty tenant of their own. Verifying it with DNS proves your company controls the domain. That keeps any other tenant from taking it over, and it's required for [Enterprise SSO](/managed-agents/enterprise-sso).

<Note>
  You need the **Admin** or **Owner** tenant role, or be the tenant's primary owner. See [Organizations and roles](/managed-agents/organizations-and-roles). You can claim only the domain of your own verified email address: if you sign in as `ada@acme.com`, you can claim `acme.com`.
</Note>

## Claim a domain

<Steps>
  <Step title="Open the Domains card">
    In the [Recursion console](https://recursion.labelbox.com), open **Settings** and choose **General**. The **Domains** card lists your tenant's domains.
  </Step>

  <Step title="Add your domain">
    Under **Add a domain**, enter your domain, such as `acme.com`, and click **Add domain**.
  </Step>
</Steps>

A new claim is **Invite only**, so nothing changes for anyone until you choose who can join. Next, verify it with DNS.

<Accordion title="Which domains you can claim">
  * A claim covers that exact domain. Claiming `acme.com` doesn't cover `eu.acme.com`.
  * Addresses at free email providers, such as `gmail.com` or `outlook.com`, can't be claimed.
</Accordion>

## Verify it with DNS

Your verified address is enough to claim the domain, but until you verify it with DNS, another tenant whose admin has a verified address there can take it over by verifying it first. Verifying also unlocks **Anyone can join**, inviting people who already use Recursion, and Enterprise SSO.

<Steps>
  <Step title="Copy the TXT record">
    On the domain's row, the card shows a TXT record with a **Type**, **Name**, and **Value**. The name is `_recursion-verification.` followed by your domain, and the value starts with `recursion-domain-verification=`. Use the copy buttons, since the value is unique to your claim.
  </Step>

  <Step title="Add it at your DNS provider">
    Create a TXT record with that name and value wherever your domain's DNS is managed. It sits on its own name, so it doesn't affect your existing records, such as SPF.
  </Step>

  <Step title="Check it">
    Click **Check DNS record**. New records can take a while to appear. If the check doesn't find it yet, wait a few minutes and check again.
  </Step>
</Steps>

Once it's verified, the domain shows **Verified**, and no other tenant can take it over. Keep the record in place.

## Choose who can join

Each domain has its own join settings. Pick one under **Who can join**:

| **Who can join** | What happens |
| - | - |
| **Invite only** | Nobody joins through the domain. Invitations stay the only way in. |
| **Request to join** | People with a verified address at the domain can ask to join. An admin approves or denies each request in **Members › Requests**. |
| **Anyone can join** | People with a verified address at the domain join at once, without an invitation or approval. Needs the domain verified with DNS. |

**Default role** is the role people get when they join through the domain: **User** or **Developer**.

To invite everyone with an account at the domain, set **Invite people from your domain who already use Recursion** to **Automatically**. Each person accepts or declines the invitation in **Members › Invitations**. It needs the domain verified with DNS.

<Accordion title="How the default role applies">
  Admin, owner, and billing roles are only given by invitation or a role change. An admin approving a request can pick another role, and members who already joined keep theirs when you change the default.
</Accordion>

## Remove a domain

Click **Remove** on the domain's row and confirm. People at the domain no longer find or join your tenant through it. Members who already joined stay, and invitations already sent stay. Pending requests through the domain are closed.

## What can go wrong

The most common problems:

* **Check DNS record doesn't find the record.** It hasn't appeared yet, or its name or value differs from the one shown. Compare it with the card, copy both again if needed, wait a few minutes, and check again.
* **The domain shows Held by another tenant.** Another tenant claimed it first. Verify it with DNS: that takes the domain over and ends their claim, unless they already verified it.
* **Anyone can join can't be chosen.** The domain isn't verified with DNS. [Verify it with DNS](#verify-it-with-dns), then choose it.

<Accordion title="Every domain problem">
  | Symptom | Cause | Fix |
  | - | - | - |
  | **Check DNS record** doesn't find the record | The record hasn't appeared yet, or its name or value differs from the one shown. | Compare the record at your DNS provider with the card, copy both again if needed, wait a few minutes, and check again. |
  | The domain shows **Held by another tenant** | Another tenant claimed it first. | Verify it with DNS. Verifying takes the domain over and ends their claim, unless they already verified it. |
  | **Anyone can join** can't be chosen | The domain isn't verified with DNS. | [Verify it with DNS](#verify-it-with-dns), then choose it. |
  | You can't claim your company's domain | Your signed-in address is at another domain, or at a free email provider. | Sign in with your company address, then claim its domain. |
</Accordion>

## Next steps

<CardGroup cols={2}>
  <Card title="Enterprise SSO" href="/managed-agents/enterprise-sso">
    Let people at your verified domains sign in through your identity provider.
  </Card>

  <Card title="Organizations and roles" href="/managed-agents/organizations-and-roles">
    See what each role can do.
  </Card>
</CardGroup>
