How to Verify Your Website on Posticy

Before you can list a website on Posticy, you need to verify that you own or control it.


Website verification helps us make sure that websites are added by legitimate owners, publishers, or authorized representatives.


Once your website is successfully verified, its status will change to Wait for Admin. The Posticy team will then review the website before approving it for the marketplace.

How can I verify my website?
Posticy supports four website verification methods:


  1. HTML Meta Tag
  2. HTML File Upload
  3. DNS TXT Record
  4. Backlink to Posticy
You only need to complete one of these methods.
Which verification method should I use?
For most websites, we recommend starting with the HTML Meta Tag method.
If your website uses Cloudflare, strong bot protection, or another security service that may block automated requests, DNS TXT verification is usually the most reliable option.
If you have direct access to your website's files, you can also use the HTML File Upload method.
The Backlink method can be used if you prefer to verify ownership by publishing a link to Posticy on your website.
Method 1: HTML Meta Tag
Add the verification meta tag provided by Posticy inside the <head> section of your homepage.
For example:
<meta name="posticywebsite" content="YOUR_VERIFICATION_CODE">
After adding the tag, return to Posticy and start the verification.
Where should I add the meta tag?
The tag must appear inside the <head> section of your homepage.
Most WordPress websites and other CMS platforms allow you to add custom code to the website header through a theme, plugin, or site settings.
How can I check if the tag was added correctly?
Open your homepage and select View Page Source in your browser. You can usually do this with Ctrl+U on Windows.
Search for:
posticywebsite
You should see the verification tag and your verification code.
Do not rely only on the browser's developer tools. If JavaScript adds the tag after the page loads, you may see it in DevTools even though the Posticy verification system cannot see it.
The tag should be present directly in the HTML returned by your server.
Why does Meta Tag verification fail?
Common reasons include:


  • The tag was added outside the <head> section
  • The verification code was changed or copied incorrectly
  • JavaScript inserts the tag after the page loads
  • The website is returning a cached version of the homepage
  • Cloudflare or another security service blocks the verification request
  • The website is not publicly accessible
If everything looks correct but verification still fails, try clearing your website/CDN cache or use the DNS TXT Record method instead.
Method 2: HTML File Upload
Download the verification file provided by Posticy and upload it to the root directory of your website.
The file should be accessible directly through a URL similar to:
https://example.com/verification.html
Open the URL in your browser before attempting verification to make sure the file is publicly accessible.

Important

The verification URL must return HTTP 200 OK directly.

If the URL redirects somewhere else first, automated verification may fail even if the file eventually opens in your browser.

The file should also be uploaded to the root of the website rather than a subfolder.


When should I use HTML File verification?

This method works well if you have direct access through:


  • FTP
  • SFTP
  • cPanel
  • Plesk
  • Hosting file manager
  • Server access

Some hosted platforms, including Wix, Squarespace, and Shopify, may not allow you to upload files directly to the website root. In that case, use the Meta Tag or DNS method instead.


Method 3: DNS TXT Record

DNS verification is particularly useful for websites protected by Cloudflare, firewalls, anti-bot systems, or other security services.

Add the TXT record provided by Posticy to your domain's DNS settings.

It will look similar to:

Type: TXT
Host: @
Value: posticywebsite=YOUR_VERIFICATION_CODE
TTL: 3600

After saving the record, wait for the DNS changes to propagate and try verification again.

Where should I add the TXT record?

Add it wherever your domain's DNS is currently managed.

For example, if your nameservers point to Cloudflare, the TXT record should be added in Cloudflare rather than at the registrar where you purchased the domain.

For the main domain, the host is normally:

@

For a subdomain, the DNS record needs to be added for that subdomain.

How long does DNS verification take?

DNS changes are often visible within 5 to 30 minutes, although propagation can sometimes take longer depending on your DNS provider.

You can check whether the record is publicly available with:

dig TXT example.com +short

Your Posticy verification value should appear in the result.

Why is DNS recommended for cloud-protected websites?

DNS verification does not require Posticy to access your website.

This means services such as Cloudflare, Wordfence, Imunify360, or hosting firewalls cannot block the verification request.

You also do not need to temporarily disable your website security.

Method 4: Backlink to Posticy

You can also verify your website by publishing a link to Posticy.

Add the following link to a publicly accessible page on your website:

<a href="https://posticy.com/">Posticy</a>

Then provide the URL of the page containing the link during verification.


The link must:


  • Be published on the website you are verifying
  • Be accessible without logging in
  • Point to https://posticy.com/
  • Use Posticy as the anchor text
  • Be included in the HTML that Posticy can access

The anchor text is checked case-insensitively.


Why does Backlink verification fail?

Verification may fail if:


  • The page URL belongs to a different domain
  • The page cannot be accessed
  • The link points to the wrong URL
  • The anchor text is different
  • JavaScript adds the link after the page loads
  • A firewall or anti-bot service blocks Posticy from accessing the page

Why can't Posticy verify my website?
Sometimes everything appears correct in your browser, but automated verification still fails.
This is commonly caused by website security systems.
Posticy's verification system needs to access your website automatically. Some security services identify automated requests as bots and block or challenge them.
Examples include:
  • Cloudflare Bot Fight Mode
  • Cloudflare Under Attack Mode
  • Wordfence
  • SiteGround security features
  • Imunify360
  • Hosting firewalls
  • Other bot protection systems
Depending on the configuration, the Posticy request may receive a 403 Forbidden, 503 Service Unavailable, or a challenge page instead of your actual website.
Caching can also cause problems. For example, Posticy may receive an older cached version of your homepage that does not yet contain the verification tag.
My website loads normally. Why does verification still fail?
A website loading correctly in your browser does not necessarily mean automated systems can access it.
Your browser may pass security checks, cookies, or JavaScript challenges that an automated verification request cannot.
If your website uses strong bot protection, try DNS TXT verification. Because DNS verification does not access the website itself, it is not affected by website firewalls.
How can I test website verification myself?
If you have access to a terminal, these commands can help identify common problems.
Check the Meta Tag
curl -sL https://example.com/ | grep posticywebsite
If the verification tag is returned, it is visible in the website's HTML.

Check an HTML verification file
The response should return 200 OK without requiring a redirect.


Check a DNS TXT record
dig TXT example.com +short
Your Posticy verification record should appear in the response.


If your website returns 403, 503, or a security challenge, your firewall or anti-bot system may be blocking verification.
What happens after my website is verified?
Successful ownership verification does not automatically publish the website on the Posticy marketplace.
After verification, the website status changes to Wait for Admin.
The Posticy team will then review the website. Once approved, it can become available on the marketplace.
What should I do if none of the verification methods work?
If you have tried the available verification methods and your website still cannot be verified, contact Posticy Support.
Go to:
Help → Submit a Ticket
Use a subject such as:
Manual verification - example.com
Please include:
  • Your Posticy account email
  • Website URL
  • Verification methods you tried
  • Error message you received
  • Relevant technical setup, for example "Cloudflare + Bot Fight Mode"
  • Proof that verification was added
Proof can include a screenshot of the meta tag in View Page Source, your DNS TXT record, the verification file URL, or the page containing the Posticy backlink.
Our team can check the website using different networks and investigate why automated verification is failing.
If necessary, we may request additional evidence that you control the website.

Frequently Asked Questions
Do I need to complete all four verification methods?

No. You only need to successfully complete one verification method.


What is the easiest verification method?

For most websites, the HTML Meta Tag method is the easiest.

If your website uses Cloudflare or strong bot protection, DNS TXT verification is usually more reliable.


Can I verify a website behind Cloudflare?

Yes. We recommend using the DNS TXT Record method because it does not require Posticy to access your website.


Why can I see the meta tag but Posticy cannot?

The tag may be inserted by JavaScript, Posticy may be receiving a cached version of the page, or your security system may be blocking automated requests.

Check View Page Source rather than only using DevTools.


Can redirects cause verification problems?

Yes. Redirects are particularly important for the HTML File Upload method. The verification file should return 200 OK directly.


Can I verify a subdomain?

Yes. Make sure you verify the exact subdomain added to Posticy. For DNS verification, add the TXT record for that subdomain.


Should I disable Cloudflare or my firewall?

Usually, no.

Try DNS verification first. If you choose another verification method, you can temporarily adjust security settings if necessary and restore them immediately afterward.
You should not permanently weaken your website's security just to complete verification.


How long should I wait after adding a DNS record?

Most DNS records become visible within 5 to 30 minutes, but in some cases propagation can take longer.


I verified my website. Why isn't it visible in the marketplace?

Verification confirms website ownership. Posticy still needs to review and approve the website.

After successful verification, check whether its status has changed to Wait for Admin.


Can Posticy manually verify my website?

If automated verification continues to fail, submit a support ticket with evidence showing that you control the website. The Posticy team can investigate the verification issue and may request additional proof if required.


Contact Support

For a manual verification investigation, submit a support ticket and include the domain, methods tried, error, and evidence of control. Successful ownership verification still requires Posticy’s review before Marketplace approval.

Related guides

Adding Your Website to Posticy Marketplace