- HTML Meta Tag
- HTML File Upload
- DNS TXT Record
- Backlink to Posticy
If your website uses Cloudflare, strong bot protection, or another security service that may block automated requests, DNS TXT verification is usually the most reliable option.
If you have direct access to your website's files, you can also use the HTML File Upload method.
The Backlink method can be used if you prefer to verify ownership by publishing a link to Posticy on your website.
For example:
<meta name="posticywebsite" content="YOUR_VERIFICATION_CODE">
After adding the tag, return to Posticy and start the verification.
Most WordPress websites and other CMS platforms allow you to add custom code to the website header through a theme, plugin, or site settings.
Search for:
posticywebsite
You should see the verification tag and your verification code.
Do not rely only on the browser's developer tools. If JavaScript adds the tag after the page loads, you may see it in DevTools even though the Posticy verification system cannot see it.
The tag should be present directly in the HTML returned by your server.
- The tag was added outside the <head> section
- The verification code was changed or copied incorrectly
- JavaScript inserts the tag after the page loads
- The website is returning a cached version of the homepage
- Cloudflare or another security service blocks the verification request
- The website is not publicly accessible
The file should be accessible directly through a URL similar to:
https://example.com/verification.html
Open the URL in your browser before attempting verification to make sure the file is publicly accessible.
Important
The verification URL must return HTTP 200 OK directly.
If the URL redirects somewhere else first, automated verification may fail even if the file eventually opens in your browser.
The file should also be uploaded to the root of the website rather than a subfolder.
When should I use HTML File verification?
This method works well if you have direct access through:
- FTP
- SFTP
- cPanel
- Plesk
- Hosting file manager
- Server access
Some hosted platforms, including Wix, Squarespace, and Shopify, may not allow you to upload files directly to the website root. In that case, use the Meta Tag or DNS method instead.
Method 3: DNS TXT Record
DNS verification is particularly useful for websites protected by Cloudflare, firewalls, anti-bot systems, or other security services.
Add the TXT record provided by Posticy to your domain's DNS settings.
It will look similar to:
Type: TXT
Host: @
Value: posticywebsite=YOUR_VERIFICATION_CODE
TTL: 3600
After saving the record, wait for the DNS changes to propagate and try verification again.
Where should I add the TXT record?
Add it wherever your domain's DNS is currently managed.
For example, if your nameservers point to Cloudflare, the TXT record should be added in Cloudflare rather than at the registrar where you purchased the domain.
For the main domain, the host is normally:
@
For a subdomain, the DNS record needs to be added for that subdomain.
How long does DNS verification take?
DNS changes are often visible within 5 to 30 minutes, although propagation can sometimes take longer depending on your DNS provider.
You can check whether the record is publicly available with:
dig TXT example.com +short
Your Posticy verification value should appear in the result.
Why is DNS recommended for cloud-protected websites?
DNS verification does not require Posticy to access your website.
This means services such as Cloudflare, Wordfence, Imunify360, or hosting firewalls cannot block the verification request.
You also do not need to temporarily disable your website security.
Method 4: Backlink to Posticy
You can also verify your website by publishing a link to Posticy.
Add the following link to a publicly accessible page on your website:
<a href="https://posticy.com/">Posticy</a>
Then provide the URL of the page containing the link during verification.
The link must:
- Be published on the website you are verifying
- Be accessible without logging in
- Point to https://posticy.com/
- Use Posticy as the anchor text
- Be included in the HTML that Posticy can access
The anchor text is checked case-insensitively.
Why does Backlink verification fail?
Verification may fail if:
- The page URL belongs to a different domain
- The page cannot be accessed
- The link points to the wrong URL
- The anchor text is different
- JavaScript adds the link after the page loads
- A firewall or anti-bot service blocks Posticy from accessing the page
This is commonly caused by website security systems.
Posticy's verification system needs to access your website automatically. Some security services identify automated requests as bots and block or challenge them.
Examples include:
- Cloudflare Bot Fight Mode
- Cloudflare Under Attack Mode
- Wordfence
- SiteGround security features
- Imunify360
- Hosting firewalls
- Other bot protection systems
Caching can also cause problems. For example, Posticy may receive an older cached version of your homepage that does not yet contain the verification tag.
Your browser may pass security checks, cookies, or JavaScript challenges that an automated verification request cannot.
If your website uses strong bot protection, try DNS TXT verification. Because DNS verification does not access the website itself, it is not affected by website firewalls.
Check the Meta Tag
Check a DNS TXT record
After verification, the website status changes to Wait for Admin.
The Posticy team will then review the website. Once approved, it can become available on the marketplace.
Go to:
Help → Submit a Ticket
Use a subject such as:
Manual verification - example.com
Please include:
- Your Posticy account email
- Website URL
- Verification methods you tried
- Error message you received
- Relevant technical setup, for example "Cloudflare + Bot Fight Mode"
- Proof that verification was added
Our team can check the website using different networks and investigate why automated verification is failing.
If necessary, we may request additional evidence that you control the website.
No. You only need to successfully complete one verification method.
What is the easiest verification method?
For most websites, the HTML Meta Tag method is the easiest.
If your website uses Cloudflare or strong bot protection, DNS TXT verification is usually more reliable.Yes. We recommend using the DNS TXT Record method because it does not require Posticy to access your website.
The tag may be inserted by JavaScript, Posticy may be receiving a cached version of the page, or your security system may be blocking automated requests.
Check View Page Source rather than only using DevTools.Yes. Redirects are particularly important for the HTML File Upload method. The verification file should return 200 OK directly.
Yes. Make sure you verify the exact subdomain added to Posticy. For DNS verification, add the TXT record for that subdomain.
Usually, no.
Try DNS verification first. If you choose another verification method, you can temporarily adjust security settings if necessary and restore them immediately afterward.You should not permanently weaken your website's security just to complete verification.
Most DNS records become visible within 5 to 30 minutes, but in some cases propagation can take longer.
Verification confirms website ownership. Posticy still needs to review and approve the website.
After successful verification, check whether its status has changed to Wait for Admin.If automated verification continues to fail, submit a support ticket with evidence showing that you control the website. The Posticy team can investigate the verification issue and may request additional proof if required.
Contact Support
For a manual verification investigation, submit a support ticket and include the domain, methods tried, error, and evidence of control. Successful ownership verification still requires Posticy’s review before Marketplace approval.