# POST /v1/inbound/domains/{id}/verify

Check the records now

Looks both records up at once and records the result; the answer carries the domain as it stands and what each lookup found. A TXT record that is right while another account holds the name verified reads as mismatch.

Takes a server key (`sk_…`, or `sk_test_…` on a test server) as a bearer token. TypeScript: `sendora.inboundDomains.verify(inboundDomainId)`. Python: `sendora.inbound_domains.verify(inbound_domain_id)`.

## Parameters

- `id` (path, required, string (uuid)): The inbound domain id.

## Responses

### 200 The domain as it stands, with what each lookup found.

- `inboundDomainId` (string (uuid), required)
- `streamId` (string (uuid), required): The inbound stream the domain delivers to.
- `domain` (string, required): The domain, lower-cased and IDNA-encoded.
- `verified` (boolean, required): True while both records are seen; only then is mail to the domain accepted.
- `createdAt` (string (date-time), required)
- `lastCheckedAt` (string (date-time) or null, required): When the records were last looked up.
- `unverifiedAt` (string (date-time) or null, required): When a verified domain lost its records. Mail to it is deferred for 72 hours from then and refused after, until the records are back.
- `mx` (object, required): The MX record that brings the domain’s mail to Sendora, at any priority.
  - `type` ("MX", required)
  - `host` (string, required): The name to create the record under.
  - `value` (string, required): The value the record must hold.
  - `verified` (boolean, required)
  - `verifiedAt` (string (date-time) or null, required)
- `txt` (object, required): The TXT record that proves the claim; it carries a value only you were shown.
  - `type` ("TXT", required)
  - `host` (string, required): The name to create the record under.
  - `value` (string, required): The value the record must hold.
  - `verified` (boolean, required)
  - `verifiedAt` (string (date-time) or null, required)
- `check` (object, required)
  - `mx` ("ok" | "missing" | "mismatch" | "dns_error", required): dns_error is a resolver failure, such as a DNSSEC problem or a timeout, not an absent record.
  - `txt` ("ok" | "missing" | "mismatch" | "dns_error", required): dns_error is a resolver failure, such as a DNSSEC problem or a timeout, not an absent record.

Example:

```json
{
  "inboundDomainId": "6c2a9e1d-3f4b-4a8c-9d0e-1b2c3d4e5f60",
  "streamId": "b7d2e4f6-1a3c-4d5e-9f80-2c4e6a8b0d1f",
  "domain": "post.example.se",
  "verified": false,
  "createdAt": "2026-09-19T09:00:00.000Z",
  "lastCheckedAt": null,
  "unverifiedAt": null,
  "mx": {
    "type": "MX",
    "host": "post.example.se",
    "value": "10 inbound.sendora.se.",
    "verified": false,
    "verifiedAt": null
  },
  "txt": {
    "type": "TXT",
    "host": "_sendora-inbound.post.example.se",
    "value": "sendora-inbound=7f3a9c2e5b1d4f6a8c0e2b4d6f8a1c3e",
    "verified": false,
    "verifiedAt": null
  },
  "check": {
    "mx": "missing",
    "txt": "missing"
  }
}
```

## Errors

Every error answers `error`, the code, and `message`, a sentence for a person. A code that adds fields is shown in full below the table.

| Code | Status | Meaning |
| --- | --- | --- |
| `unauthorized` | 401 | The key is missing, malformed or revoked. |
| `wrong_token_kind` | 403 | The key is of the other kind: a server key (sk_) where an account key (ak_) is needed, or the reverse. The message names the kind the operation takes. |
| `not_found` | 404 | No such inbound domain of this server. |
