Configure Tencent Cloud CDN domain name verification
If you’re searching for “Configure Tencent Cloud CDN domain name verification”, you likely hit one of these pain points: you already have (or are buying) a Tencent Cloud account, you enabled CDN, and now the console asks you to verify domain ownership—but you’re unsure what exactly to configure, how long it takes, and why your account might get blocked after changes. Below is the workflow I use in real operations, plus the verification types, common failure causes, and what it means for account funding/renewal, KYC, and risk control.
1) Before touching CDN: confirm your account is “clean” enough for domain verification
In many projects, domain verification fails not because of DNS, but because the account is in a restricted state. Tencent Cloud’s verification and subsequent CDN enablement can behave differently depending on whether your account is fully verified and whether your purchase history triggers risk controls.
Quick checklist (do this first)
- Identity verification (KYC) status: Ensure the account has completed real-name authentication (and enterprise verification if applicable). If you’re using a newly created or recently upgraded account, expect stricter checks on “new domain + new service usage”.
- Risk control signals: If you recently changed payment methods, attempted multiple payouts/renewals, or created multiple accounts from the same identity/card, you may see verification delays or “verification failed” loops.
- Billing readiness: Some CDN operations (especially enabling HTTPS/WAF-related bundles) will require active billing permissions. If your account balance is insufficient or a renewal payment fails, the console may still let you create verification records, but the final “CDN status” won’t progress.
Practical tip: If you’re doing domain verification right after KYC, wait a short period (often 15–60 minutes, sometimes longer in busy hours) before retrying. I’ve seen cases where the console UI accepts the TXT/CNAME record but verification doesn’t complete until backend state syncs.
2) What “domain name verification” typically means in Tencent Cloud CDN
Tencent Cloud may request different proof methods depending on your zone, selected CDN settings, and whether you’re enabling advanced features. In practice, the verification you’ll configure is usually one of the following:
- DNS TXT verification (most common): add a TXT record under your domain/host in your DNS provider.
- DNS CNAME verification: less common; points a verification hostname to a Tencent Cloud target.
- File/HTTP-based validation: occasionally used for non-standard DNS setups (less common for CDN domain verification).
The console will show the exact host name (often _xxx or something like verify) and the exact TXT value you must set.
Treat that string as case-sensitive and whitespace-sensitive.
Scenario-based guidance (what you should configure)
A) Your domain DNS is managed at Tencent Cloud DNS
- You can add the verification record directly in the DNS console (TXT under the corresponding zone). This reduces propagation variance.
-
If you’re using subdomain verification (like
www.example.com), ensure you edit the correct zone and host. A frequent mistake is adding the record at the apex when Tencent asks for the subdomain, or vice versa.
B) Your domain DNS is at Cloudflare / AliDNS / Godaddy / registrar DNS
- Add the TXT record with the exact host and value Tencent provides. For TXT records, some providers show “Value” without quotes; others require quotes. Use Tencent’s value exactly as shown.
- For Cloudflare in particular: confirm whether you’re adding a record at the correct “zone” and not under a different host scope. Also verify no “flattening / synthetic records” are affecting your requested host.
C) You use a CDN/forwarding platform already (risk of “verification works, CDN won’t”)
If your domain is currently behind another proxy (e.g., a provider that masks DNS), keep in mind that domain verification must still be validated through DNS resolution. Don’t assume because your site is reachable through a proxy that TXT validation will pass.
3) Step-by-step: configure DNS record for verification (hands-on workflow)
The exact UI labels differ by console version, but the sequence is consistent. Here’s how I’d do it in a migration project for a team that needs speed and low failure rate.
Step 1: Start domain verification in Tencent Cloud CDN
- Go to CDN → domain management (or the “add domain” flow).
- Select the domain name and required protocol settings (HTTP/HTTPS, origin settings).
- When prompted, copy the verification requirement: Record Type (TXT/CNAME), Host, Value/Target, and sometimes TTL.
Step 2: Add DNS record in your DNS provider
- Create a new record of the requested type. Use the provided host name exactly.
- For TXT: ensure it matches the full string. If Tencent provides multiple segments, keep them exactly (don’t split manually unless Tencent tells you to).
- Set a practical TTL (I often set 60s–300s during verification to speed retries). Later you can revert to your normal TTL after confirmation.
Step 3: Confirm propagation before submitting again
Tencent Cloud
Don’t submit verification immediately if your DNS provider has higher propagation delays.
Use a DNS query tool (or dig) to confirm that the authoritative DNS returns the record.
- Tencent Cloud Check the host value exactly (some records require
_verify-style host prefixes). - Confirm TXT record presence and exact value match.
Operational note: I usually wait until the record is visible on authoritative or at least consistent across multiple resolvers. If the verification keeps failing, it’s almost always a host mismatch or value mismatch—not random delays.
Step 4: Submit verification and watch the state
- Return to Tencent console and click “Verify/Confirm”.
- If it succeeds, proceed to origin configuration and caching rules.
- If it fails, don’t immediately re-add duplicates. Remove the wrong record and retry once you’ve confirmed the authoritative response.
4) Common verification failure reasons (and what to do)
Failure #1: You added TXT at the wrong host/subdomain
Example: Tencent asks for TXT under _tencentcdn.example.com, but you add it under example.com apex.
Result: verification fails even though “a TXT record exists”.
Fix: Align host/subdomain exactly with what Tencent shows.
Failure #2: Wrong TXT value (quotes/whitespace/partial copy)
Users often copy the value from the console and accidentally add extra spaces or remove required characters. Some DNS UIs automatically wrap quotes.
Fix: Paste the value carefully and compare character-by-character. Use one final verification copy-paste from Tencent.
Tencent Cloud Failure #3: Multiple TXT records but only one matches (or you used an old value)
If you’ve tested multiple times, your DNS may contain several TXT records for the same host. Tencent’s check typically expects the exact current token.
Fix: Keep only the latest verification record. Remove older TXT tokens for that host.
Failure #4: DNS provider “proxying” or custom record transformations
Some platforms can modify DNS behavior for certain record types. Especially when using dashboard templates or “synthetic records”, TXT can behave unexpectedly.
Fix: Temporarily disable proxy/special record features for that host until verification completes.
Failure #5: Verification done, but CDN domain stays “pending”
Tencent Cloud In real deployments, I’ve seen “verification completed” but the domain doesn’t fully activate due to: billing permission, account restrictions, or incomplete enterprise onboarding.
- Balance insufficient or renewal not active
- HTTPS certificate order pending while identity is not verified for that operation
- Tencent Cloud Risk control review triggered by rapid changes (domain + payment + service enablement in a short time window)
Fix: Check account billing status first, then retry CDN enablement steps.
5) Identity verification (KYC) and enterprise verification: how it affects CDN operations
CDN domain verification itself is DNS-based, but the next steps (especially HTTPS and certain security add-ons) depend heavily on verification completeness.
What typically requires KYC beyond DNS verification
- Purchasing CDN usage (top-up/subscription)
- Enabling HTTPS with managed certificates
- Any feature that triggers additional compliance review
Scenario: consumer vs enterprise account
- If you’re using an enterprise domain and need invoices, you’ll likely need enterprise verification. Some regions also tighten checks for commercial traffic sources.
- If you’re using a personal account to test quickly, verification might pass but later operations can be limited when trying to scale.
Hands-on advice: If your team is doing a production rollout, don’t postpone enterprise verification until after CDN is configured. That “last-minute verification” pattern causes delays because DNS verification completion doesn’t guarantee service activation.
6) Account purchasing & funding/renewals: what changes when you buy CDN through Tencent Cloud
When users search for CDN domain verification, they often already tried purchasing CDN or a certificate. The operational reality: payment and renewal settings can block progression even after DNS verification succeeded.
Payment method differences that matter for verification-related workflows
I’ll keep this practical—what matters is how quickly your account becomes “active” for subsequent enablement.
- Balance/top-up (prepaid-style): typically faster for small pilots. If your balance is low, CDN enablement or add-ons can stall.
- Subscription/renewal (recurring): renewal failures can lead to “service paused” states later. DNS remains set, but traffic won’t be accelerated.
- Postpaid arrangements (where available): can pass DNS verification but may require additional approval for invoice/billing settings.
Common “I verified DNS but billing won’t proceed” causes
- Payment method expired or bank verification pending
- Account funding succeeded but the specific resource is still under risk control review
- Using an account in a restricted state due to too many failed payment attempts
Fix: In the console, check both “account/billing status” and the specific product order status. Don’t assume one implies the other.
7) Risk control and compliance review: what to avoid during CDN domain verification
In real operations, risk control is triggered more often than teams expect when they combine: new account + new domain + rapid enablement + multiple payment changes.
Behavior patterns that trigger extra checks
- Creating multiple CDN domain records repeatedly with different tokens
- Switching payment methods mid-process
- Re-trying verification dozens of times in a short period
- Using domains that conflict with account verification details (e.g., mismatch between business scope and domain usage)
Practical mitigation
- Verify DNS once after a record is confirmed by DNS query.
- Make only one change set (DNS record, then verification submit; avoid changing TLS/origin in parallel).
- If you’re doing a migration with multiple domains, batch them with gaps (e.g., 1–3 domains per cycle) rather than all at once.
8) Cost comparisons (what it looks like around verification + activation)
Domain verification itself doesn’t usually have a direct cost, but the choices you make after verification heavily affect spend. The most common cost traps are HTTPS/certificate and add-on services that are initiated after domain verification.
What costs usually appear after verification
- CDN traffic / request fees (depends on region and billing model)
- HTTPS certificate fees (if managed certificates are used; sometimes there are options)
- Extra security features (WAF, bot protection, rules) if you enable them
Cost-driven decision you can make today
- Tencent Cloud For a pilot: configure CDN first with HTTP, confirm caching behavior, and postpone HTTPS add-ons until billing verification is stable.
- For production: enable HTTPS early but ensure enterprise verification and billing are fully ready to avoid delayed certificate issuance.
Real-world observation: Teams often underestimate that failed verification/activation retries can cause multiple certificate order attempts or extra service states. The money loss isn’t from TXT records; it’s from follow-on features created during repeated operational loops.
9) FAQ (the questions users ask right before they hit “Verify”)
Q1: How long does Tencent Cloud CDN domain verification take?
DNS propagation is usually the limiting factor. If your TXT record is in a stable DNS provider and TTL is low, verification can complete in minutes. If your DNS TTL is high or using a slower provider, it can take hours. If it fails after you’ve confirmed authoritative DNS, wait 30–60 minutes before retrying—backend token sync matters.
Q2: Can I verify a subdomain (like www) instead of the apex?
Yes, but you must follow the host Tencent gives you in the verification panel. “www verification” is not the same as “apex verification”, and mixing them is a top failure reason.
Q3: I changed DNS records—why does Tencent still say “not verified”?
Most of the time, it’s because the record hasn’t propagated to authoritative resolvers, or you changed the record at the wrong host. Also check if older TXT records still exist for the same host and confuse the matcher (remove old tokens and leave only the current one).
Q4: Does Tencent Cloud require KYC to verify the domain name?
Domain verification is DNS-based, so the TXT/CNAME step can be attempted without friction. However, KYC strongly affects subsequent steps like activating services and ordering HTTPS/security features. In practice, it’s safer to complete KYC/enterprise verification before you finalize the rollout.
Q5: What if my Tencent Cloud account is newly created—can I still verify?
Yes, you can usually set DNS records and attempt verification, but new accounts are more likely to trigger risk control checks during billing or certificate issuance. If you see “verification succeeded but domain activation stuck”, check billing status and risk control messages in your account center.
Q6: Should I set TTL to 60 seconds to speed up verification?
During verification, it helps. After the domain is verified and stable, you can adjust TTL back to your preferred value. Just avoid frequent record edits that create extra risk signals.
10) Troubleshooting playbook (use this when you’re under deadline)
- Confirm the host and TXT/CNAME target exactly match Tencent’s panel (copy the string into a note and compare character counts).
- Check authoritative DNS using a DNS query tool. Don’t rely only on browser cache.
- Tencent Cloud Remove old verification tokens for the same host to prevent mismatches.
- Verify account/billing status (balance, renewal, product order state).
- Avoid rapid retries. If you failed multiple times, pause 30–60 minutes after the DNS is confirmed.
- If activation is stuck, review whether KYC/enterprise verification is complete and whether there’s a compliance/risk review notice.
11) A practical mini-case: “TXT is correct, still fails”
In one migration for a mid-sized e-commerce team, the engineer copied the correct TXT value but configured it under the wrong host in their DNS provider:
Tencent asked for _cdnverify.example.com, while they added _cdnverify.www.example.com.
Browser-based DNS tests looked “close enough”, and the team kept retrying.
After switching to an authoritative DNS query and aligning the host precisely, verification succeeded within 10 minutes. Only then did they enable HTTPS; because enterprise verification was already done and billing was active, activation proceeded smoothly.
What I need from you to tailor the exact verification instructions
If you share the following, I can tell you the exact record type/host/value you should set and where teams most commonly make mistakes:
- Your domain (or just the structure, e.g.,
www.example.comvsexample.com) - Your DNS provider (Tencent DNS / AliDNS / Cloudflare / registrar DNS)
- Whether Tencent’s panel shows TXT or CNAME verification
- What error message you see after clicking Verify
- Your account type (personal or enterprise) and whether KYC is completed

