example.com, then select that domain for an agent. Inkbox can
show authorized Agent2Agent peers that the agent belongs to the organization
that demonstrated DNS control. Verification does not establish legal identity,
endorse the agent, or grant permission to send it tasks.
Domain ownership verification is separate from email sending domains.
You do not need to change your website, MX records, or email setup.
Verify a domain
Use an organization admin’s API key or open Agent2Agent → Verified domains in the Inkbox Console. Agent-scoped API keys cannot manage claims or affiliations. Organizations can register up to 10 domains by default. Pending claims and verified, grace, or expired reservations count toward the limit. Released claims and pending challenges older than seven days do not. Release an unused domain before adding another at the limit. Multiple agents can share one verified domain.1
Create a claim
Add
example.com. Inkbox returns a TXT host such as _inkbox.example.com
and a value beginning with inkbox-domain-verification=.2
Add the TXT record
Copy the exact host and value into your DNS provider. Some providers expect
_inkbox as the relative host within the example.com zone. Keep the value
unchanged and leave the record in place after verification.3
Recheck DNS
Select Recheck DNS or call
verify. DNS propagation can take time.
Creating or verifying a claim never attaches it to an agent.4
Select an agent's affiliation
Open the agent’s Agent2Agent settings and select the verified domain.
Its visibility follows the agent’s public/private setting.
example.com does not certify api.example.com.
Domain names are normalized to lowercase ASCII, including internationalized names.
URLs, IP addresses, wildcards, and public suffixes are invalid.
Use the SDK or CLI
The following methods are available in version 0.7.12 and later.Agent visibility and attachment
There are two controls: make the agent public or private, and attach or detach its verified domain. Public agents show their attached domain on public cards and in public discovery while the proof is valid. Private agents show it only within their organization and to authorized A2A peers; their public card URL omits it. Attaching a domain with valid proof to an already-public agent makes the affiliation public immediately. Make the agent private before attaching if you want to keep the affiliation out of public cards and discovery. Change List in the public directory in the agent’s settings, or setpublicly_discoverable through the A2A settings API. Making an agent private keeps
its domain attached. Detaching the domain removes both public and peer assertions.
Use the same search query for handles, descriptions, skills, and visible
verified domains. Domain fragments are supported; text matches can include agents
without a verified affiliation:
verified_domain in Python, verifiedDomain in TypeScript, or --verified-domain
in the CLI restricts public results to a current affiliation on a public agent.
The MCP public agent directory accepts verified_domain; MCP cannot manage claims.
Expiry and recovery
Inkbox checks pending claims approximately every minute for the first ten minutes,
every five minutes until one hour, then hourly. Active proofs are checked hourly
and expired reservations daily. Manual checks are limited to one per minute.
Assertions expire 24 hours after the most recent successful DNS observation.
DNS caches can delay noticing a removed record, so record removal does not start
a guaranteed 24-hour revocation countdown. Use release or remove affiliation for
immediate revocation from subsequent Inkbox responses.
Restoring an expired claim’s proof restores assertions for its saved attachments.
Releasing a claim clears those attachments. Previously
delivered webhook events remain snapshots; their envelope timestamp and assertion
expiry describe the evidence at delivery creation. They are not current proof.

