# POST /v1/domains/{id}/verify

Check the records now

Looks both records up at once and records the result; the answer carries the domain as it stands and what each lookup found. A lookup that fails at the resolver changes nothing. A check that begins a verified domain's 24-hour warning or ends its verification mails the account's administrators, as Sendora's own checks do.

Takes an account key (`ak_…`) as a bearer token. TypeScript: `account.domains.verify(domainId)`. Python: `account.domains.verify(domain_id)`.

## Parameters

- `id` (path, required, string (uuid)): The domain id.

## Responses

### 200 The domain as it stands, with what each lookup found.

- `domainId` (string (uuid), required)
- `domain` (string, required)
- `verified` (boolean, required): True while both records count as found; only then may mail go out. A lookup that fails at the resolver never changes it, and a record found missing on a verified domain starts a 24-hour warning (failingSince) through which the domain stays verified.
- `createdAt` (string (date-time), required)
- `lastCheckedAt` (string (date-time) or null, required): When the records were last looked up.
- `failingSince` (string (date-time) or null, required): When a check first found a record of this verified domain missing or wrong. Mail keeps going out, the records are looked up hourly, and the first check 24 hours after this that still misses one ends the verification. Null unless the domain is verified and in that warning; verified and each record tell the rest.
- `returnPath` (object, required): The return-path record, which also satisfies SPF.
  - `type` ("CNAME", required)
  - `host` (string, required): The name to create the record under.
  - `value` (string, required): The value the record must hold.
  - `verified` (boolean, required)
  - `verifiedAt` (string (date-time) or null, required)
- `dkim` (object, required): The DKIM public key record.
  - `type` ("TXT", required)
  - `host` (string, required): The name to create the record under.
  - `value` (string, required): The value the record must hold.
  - `verified` (boolean, required)
  - `verifiedAt` (string (date-time) or null, required)
- `check` (object, required)
  - `returnPath` ("ok" | "missing" | "mismatch" | "dns_error", required): dns_error is a resolver failure, such as a DNSSEC problem or a timeout, not an absent record.
  - `dkim` ("ok" | "missing" | "mismatch" | "dns_error", required): dns_error is a resolver failure, such as a DNSSEC problem or a timeout, not an absent record.

Example:

```json
{
  "domainId": "0d7f6a1e-4c0b-4b7e-9d3c-2a1f5e8b9c01",
  "domain": "example.se",
  "verified": false,
  "createdAt": "2026-09-15T12:00:00.000Z",
  "lastCheckedAt": null,
  "failingSince": null,
  "returnPath": {
    "type": "CNAME",
    "host": "sendora-bounces.example.se",
    "value": "bounces.sendora.se",
    "verified": false,
    "verifiedAt": null
  },
  "dkim": {
    "type": "TXT",
    "host": "s1._domainkey.example.se",
    "value": "v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA...",
    "verified": false,
    "verifiedAt": null
  },
  "check": {
    "returnPath": "missing",
    "dkim": "missing"
  }
}
```

## Errors

Every error answers `error`, the code, and `message`, a sentence for a person. A code that adds fields is shown in full below the table.

| Code | Status | Meaning |
| --- | --- | --- |
| `unauthorized` | 401 | The key is missing, malformed or revoked. |
| `wrong_token_kind` | 403 | The key is of the other kind: a server key (sk_) where an account key (ak_) is needed, or the reverse. The message names the kind the operation takes. |
| `not_found` | 404 | No such domain of this account. |
