Your domain's record
Every domain that uses triauth publishes one TXT record at the domain itself. Websites read it to learn where your authenticator is, and how to find your identity records.
dns
example.com. TXT "triauth auth.triauth.org mode=private include=any"The record has two required parts and two options. The options may be left out.
| Part | Meaning |
|---|---|
triauth | Marks the record. Only one TXT record per domain may start with it. |
auth.triauth.org | The address of the authenticator for everyone at this domain. It is a host name, without https:// and without a path. Websites send your browser to https:// followed by this name. |
mode=private | Where your identifier can be read from. private is the default when the option is missing. See Public and private mode. |
include=any | Whether identities at this domain may let other identities act on their behalf, and from which domains. any is the default when the option is missing, and it allows identities from any domain. See Delegation. |
Where the record goes
The record belongs to the domain part of your identifiers. For john@example.com, add it at example.com. For john@team.example.com, add it at team.example.com. Each of these domains can use a different authenticator and a different mode.
In most DNS panels:
- Choose the record type TXT.
- Leave the name empty or type
@for the domain itself. For a subdomain, type its name. - Paste the value, starting with the word
triauth. Most panels add the quotes for you. - Save. Changes become visible within minutes, sometimes longer.
Check the result. On Windows:
nslookup -type=TXT example.comOn macOS and Linux:
shell
dig +short TXT example.comYou can also use an online DNS lookup tool.
Changing the record
Websites read your domain's record through several DNS resolvers. They accept the record only when all resolvers return the same value. Each resolver keeps a copy of the record for its TTL, the time to live set in your DNS panel, before it asks your DNS again. During a change, some resolvers return the old value and some the new one. Sign-ins at your domain then fail until all resolvers return the new value. This can take as long as the TTL.
To change the record without a long gap:
- Set the TTL of the record to one minute, or to the lowest value your DNS provider allows.
- Wait for the old TTL to pass.
- Change the record.
- Set the TTL back to its usual value when the change is visible everywhere.
Changing the authenticator later
The browser on each of your devices keeps its keys bound to the authenticator's address. If you point your domain at a different authenticator address, for example your own copy, set up each device again there and publish its new records. Delete the DNS records of the old devices when you no longer need them.
DNSSEC
If your DNS provider offers DNSSEC, turn it on. Websites then see that your records were signed, and some websites require that.
Rules to remember
- Publish exactly one
triauthrecord per domain. With two or more, websites treat the domain as not configured. - Write options in lowercase, without spaces around
=. A misspelledmodevalue makes every identifier at the domain unusable until you fix it. - When you move to another DNS provider, copy all triauth records with the rest of your zone.