Free to explore: filter winning sites by DR, traffic and niche  ·  Try the live explorer →

Search Console verification, explained

DNS settings on a laptop

Most guides treat Google Search Console domain verification as a box to tick during setup. Add a record, click verify, move on. That framing causes the most common failure: someone tidies up DNS, swaps a theme or removes a plugin a year later, and the site quietly stops being verified.

The method you choose matters less than understanding two things: which property type you are verifying, and that the proof has to stay in place for as long as you want access.

Domain property or URL-prefix property

Search Console offers two property types, and the choice comes before any verification method. A Domain property covers all protocols and subdomains: http and https, www and non-www, and any other subdomain, in one view. A URL-prefix property covers only the exact prefix you enter, so https://www.example.com/ and https://example.com/ are separate properties.

A TXT record being added

The trade-off is in how you prove ownership. According to Google’s Search Console Help page on verifying site ownership, a Domain property can be verified only by a DNS record. URL-prefix properties accept several methods, which the table below sets out.

MethodDomain propertyURL-prefix property
DNS recordYes, the only methodVia the domain name provider option
HTML file uploadNoYes
HTML tagNoYes
Google AnalyticsNoYes
Google Tag ManagerNoYes

Google states the file restriction directly: “HTML file upload can be used for URL-prefix properties, but not Domain properties.” If you have only FTP or CMS access and no access to DNS, a Domain property is not available to you yet.

URL-prefix properties still have a place even when you run a Domain property. A prefix such as https://example.com/blog/ gives a team that owns one section its own view, without handing it the whole domain. Many sites run both: the Domain property as the master view, and URL-prefix properties for the sections or subdomains that different people look after.

How Google Search Console domain verification works

For a Domain property, Search Console gives you a TXT record to add at your DNS provider. You add it, wait for the change to be visible, and click verify. If it fails, the usual cause is that the record has not propagated yet, was added to the wrong domain or zone, or was pasted with extra characters.

A meta tag in an HTML head

Our recommendation is to use a Domain property wherever you can get DNS access. It is the one view that catches problems on a subdomain or protocol you forgot about, and the DNS record is less exposed to everyday site changes than a file or a tag. Our guide on how to use Google Search Console covers what to do once you are in.

The catch is in Google’s own warning: “To stay verified, don’t remove the DNS record from your provider, even after verification succeeds.” DNS records do get removed, usually by someone cleaning up entries they do not recognise, or when a domain moves to a new DNS host and only the obvious records are copied across.

Choosing a property type

The HTML tag and the other URL-prefix methods

Google Search Console HTML tag verification means adding a meta tag to the head of your home page. Search Console gives you the exact tag, with your verification code in the content attribute. It looks like this:

To get the Google Search Console verification code, add a URL-prefix property and choose the HTML tag method; the tag is shown on that screen. Paste the whole tag, or the token alone if your SEO plugin has a field for it.

The HTML file upload method works the same way with a file instead of a tag. Search Console gives you a small file to download, you upload it to the root of the property, and Google fetches it. It suits sites where you control the server but cannot easily edit templates. Its weakness is that the file looks like clutter to anyone tidying the web root, and a redeploy from a repository that does not contain it will remove it.

A tag manager container

The Google Analytics and Google Tag Manager methods reuse code already on your pages, which makes them quick. They also tie verification to that code staying in place. If you later remove the tag, change containers or move to another analytics tool, the token goes with it. Our comparison of Search Console and Google Analytics explains why the two tools are worth keeping separate in your head, even when one verifies the other.

Why verification lapses, and what to do when it fails

Google is explicit that verification is ongoing. You stay verified “as long as Search Console can confirm the presence and validity of your verification token”, and Search Console “periodically checks”. If the token is removed, “your permissions on that property will expire after a certain grace period.” Google does not give that period as a number on the help page, so do not plan around one.

A verification success message

When you see Google Search Console ownership verification failed, work through the likely causes in order. Is the token still where you put it? Is it on the exact property you are verifying, with the right protocol and subdomain? Has a caching layer, CDN or security plugin blocked Google from fetching the file or page? Has the site moved?

Migrations are the classic trigger. A new theme drops the meta tag, a new host does not carry over the verification file, or a DNS move leaves the TXT record behind. Our site migration checklist includes verification for that reason.

A team sharing site access

Two habits prevent most of this. First, verify each property with more than one method, so losing a single token does not cost you access. Second, keep a short note of which tokens exist and where, and share it with whoever manages DNS, the theme and analytics. Most lapses are not technical failures. They are one person removing something another person added, without knowing what it did.

When you give colleagues or an agency access, add them as users in Search Console rather than asking them to verify separately. That way their access does not depend on yet another token sitting somewhere on the site.

One limitation. Google’s help page does not say how often it checks for tokens or how long the grace period lasts. You will not always get a warning in time to fix a removed token before access expires, which is the main argument for a second method.

Frequently asked questions

How do I verify a Domain property in Search Console?

Add the TXT record Search Console gives you at your DNS provider, then click verify. A Domain property can be verified only by DNS record.

Can I use HTML file upload for a Domain property?

No. Google says “HTML file upload can be used for URL-prefix properties, but not Domain properties.”

Can I delete the DNS record after verifying?

No. Google says: “To stay verified, don’t remove the DNS record from your provider, even after verification succeeds.”

What happens if my verification token is removed?

Search Console periodically checks for it. If it is gone, your permissions on that property expire after a grace period.

The takeaway Use a Domain property and a DNS record where you can, add a second method as backup, and treat every token as something that must stay in place. Verification is checked continuously, not once.