Skip to content

Verify your domain

Domain verification proves, with a DNS TXT record, that your team owns an email domain. Use it so accounts created by SSO or SCIM for people on your domain are ready without email confirmation, and so those people can't sign up or sign in without SSO.

For users whose email address is on a verified domain:

  • Accounts created by their first SSO sign-in or by SCIM are ready to use without email confirmation.
  • You can require them to sign up and sign in with SSO only.

Applies to

  • Jump Desktop for Teams Enterprise plan.
  • Team administrators.
  • A team with single sign-on set up. The Domain Verification section doesn't appear until it is.
  • Access to add DNS records for the domain.

Add and verify a domain

  1. In the Teams dashboard, open your team and click Security.

    Team page with Security under Admin

  2. In Domain Verification, click Add Domain.

    Domain Verification section with Add Domain button

  3. Enter the domain, for example example.com, and click Add Domain. The domain appears with status Pending.

    Add Domain dialog with example.com entered

  4. Click the value in the Txt Record column to copy it. It looks like jumpdesktop= followed by letters and numbers.

    Domain table with example.com Pending and Click to copy on the Txt Record value

  5. At your DNS provider, add a TXT record with the copied value on the domain itself (the root, often entered as @).

  6. After the record is published, click Request Verification (the icon next to the status).

    Request Verification icon next to the Pending status

The status changes to Verified when the record is found. If it shows Pending or Failed, wait for DNS to propagate and try again.

Keep the TXT record in place. Jump Desktop rechecks domains periodically, so a status can change on its own. A verified domain whose record is gone changes to Failed.

Require SSO for the domain

These switches apply only while the domain is Verified.

Switch Effect on users with an email address on the domain
Enforce SSO Signup Can't create a Jump Desktop account with other methods. They must use SSO.
Require SSO Login Can't sign in with other methods. They must use SSO. Entering their email on the Jump Desktop web sign-in page sends them to your identity provider.

To require SSO for all team members instead, see Require SSO.

Add verified users to the team

Verification doesn't add anyone to your team. Add users yourself, or select Add new users to the team automatically in Team Single Sign On.

For how SCIM provisions users on verified and unverified domains, see Provision users with SCIM.

Remove a domain

Select the domain, click Remove Domain, and confirm. The domain's SSO requirements stop applying.

Limitations

  • A domain is matched exactly. user@sales.example.com isn't covered by example.com; add each email domain separately.