Troubleshooting
During setup
"Domain is not configured for triauth"
The setup did not find a triauth record at your domain.
- Check the name. For
john@example.com, the record belongs atexample.com, not atwww.example.comorauth.example.com. - Wait a few minutes after you add the record. DNS changes take time to spread.
- The setup looked for the record before you added it, so a resolver may still hold the empty answer. See Refresh the resolver caches.
- Check the record from a terminal. On Windows, run
nslookup -type=TXT example.com. On macOS and Linux, rundig +short TXT example.com. The answer must contain a line that starts withtriauth. - Check that there is only one
triauthrecord. With two, the domain counts as not configured. - Check the quotes. The value is one string. If your panel shows it as two strings, join them.
"Please use https://…"
Your domain's record names a different authenticator than the one you opened. Open the address shown in the message.
"This domain is configured with unsupported mode"
The mode option in your domain's record has a value other than public or private. Fix the spelling.
"TXT records are not visible yet"
The identity records you added are not visible to the authenticator yet. Wait, and click Verify now again. The setup looked for these records before you added them, so a resolver may still hold the empty answer. See Refresh the resolver caches. Also, check the name of the records. It must match the name shown in the setup, character for character. You can also finish the setup without verification and sign in once the records are visible.
"No identity records were found for this code"
The lookup code does not match records at your domain. Check it for typos. If you are setting up this identifier for the first time, choose that option instead.
"Identifier is already configured on this device"
This browser already has keys for the identifier. Open the start page to see your identities. To start over, delete the identity there first.
When you sign in
"Authentication request could not be processed"
The authenticator refused the request. Common causes:
- You opened the sign-in link from a page on a different website than the one that asked. Start the sign-in again on the website.
- The identifier in the request is not set up in this browser. Set it up, or sign in from the device where it is.
- The request is malformed or too old. Start again.
"Your identity could not be verified"
The website could not match your signature with your DNS records.
- You set up this device again, but the old records are still published and the new ones are not. Publish the new records and delete the old ones.
- Records of this device were changed or removed. Compare your DNS with the records that the authenticator expects.
"Authentication request has expired"
You took too long to approve. Start the sign-in again.
"Request has been denied"
You clicked Deny, or the website used a permission that you did not grant. Sign in again and approve the request.
"Your domain does not support DNSSEC"
This website only accepts identities whose records are protected by DNSSEC. Enable DNSSEC at your DNS provider.
My keys are gone
The browser removed the authenticator's data, or you cleared it. Set up the device again, publish its new records, and delete the old ones. Keep a second device registered to avoid this in the future. See Devices and keys.
Check your records
On Windows:
nslookup -type=TXT example.com
nslookup -type=TXT john._at.example.comOn macOS and Linux:
shell
dig +short TXT example.com # the domain's record
dig +short TXT john._at.example.com # identity records in public modeYou can also use an online DNS lookup tool. In private mode, the setup shows the exact name of your records. Use it in place of john._at.example.com.
Refresh the resolver caches
The authenticator and websites typically read your records through the public resolvers of Cloudflare and Google. If a resolver looked for a record before you added or changed it, it may remember the old answer for a while, from minutes to days. During that time it does not show the new record. Both resolvers let you drop a name from their cache.
- At Cloudflare, open one.one.one.one/purge-cache, enter the name, choose
TXT, and purge. - At Google, open developers.google.com/speed/public-dns/cache, enter the name, choose
TXT, solve the captcha, and flush.
Purge the name at both resolvers, then verify again.