From 5a8d21904deff9d454c9d7a2e54f22120ebe8124 Mon Sep 17 00:00:00 2001
From: Waleed
Date: Fri, 24 Jul 2026 11:32:27 -0700
Subject: [PATCH] fix(sso): surface DNS verification failures and the provider
auto-append gotcha (#5931)
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
* fix(sso): surface DNS verification failures and the provider auto-append gotcha
Post-merge audit follow-ups for verified domains (#5909):
- The host field handed admins the FQDN `_sim-challenge.acme.com`. GoDaddy,
Namecheap, Hover and most cPanel panels append the zone to whatever is typed,
yielding `_sim-challenge.acme.com.acme.com` — the record looks right in their
panel but never verifies, and our 422 tells them to wait 48 hours. Add a hint
under the field (and a docs callout) telling those admins to enter just the
label.
- DNS failures were logged at debug, but production log level is ERROR, so a
blocked-egress or SERVFAIL condition was invisible to us and misreported to the
admin as "record not found yet". Log infrastructure-class failures at warn with
the DNS error code; keep the genuinely-absent codes at debug.
- Trim the joined TXT value before comparing: several DNS panels pad the stored
string, which otherwise fails an exact match forever.
- Lower the resolver to 2s/1 try. c-ares multiplies timeout across servers and
retries by ~7x, so the previous 5s/2-try config could block a verify request
for ~35s when resolvers are unreachable.
- Cover `checkDomainTxtRecord` — the function that decides whether the gate opens
had no tests. Adds exact match, chunk-joined value, match among unrelated
records, padded value, near-miss, another org's token, absent record,
infrastructure failure, and empty-response cases.
* fix(sso): log DNS infrastructure failures at error so prod actually surfaces them
Production's default minimum log level is ERROR, so the warn introduced in the
previous commit was still filtered out — the fault stayed invisible exactly as
before. A resolver failure that is not 'record absent' is a genuine
infrastructure error, so ERROR is both the visible and the honest severity.
* fix(sso): state the zone-removal rule instead of a wrong subdomain hint
The hint computed the bare label as the first segment of the challenge host, so
for a subdomain like eng.acme.com it advised entering `_sim-challenge` when the
host relative to the acme.com zone is `_sim-challenge.eng` — following it would
publish the record on the wrong name and verification would never succeed, the
exact failure the hint exists to prevent. Deriving the real zone needs the Public
Suffix List (acme.co.uk defeats naive label-stripping), so state the rule instead:
enter the host with the trailing zone removed. Docs show both the apex and the
subdomain form.
---
.../platform/enterprise/verified-domains.mdx | 6 +-
.../sim/ee/sso/components/domain-settings.tsx | 10 ++-
.../lib/auth/sso/domain-verification.test.ts | 81 ++++++++++++++++++-
apps/sim/lib/auth/sso/domain-verification.ts | 47 +++++++++--
4 files changed, 132 insertions(+), 12 deletions(-)
diff --git a/apps/docs/content/docs/en/platform/enterprise/verified-domains.mdx b/apps/docs/content/docs/en/platform/enterprise/verified-domains.mdx
index d56dc3230c..fe91e17e83 100644
--- a/apps/docs/content/docs/en/platform/enterprise/verified-domains.mdx
+++ b/apps/docs/content/docs/en/platform/enterprise/verified-domains.mdx
@@ -23,7 +23,11 @@ Go to **Settings → Security → Verified domains** in your organization settin
3. Add that TXT record at your DNS provider.
4. Click **Verify**. Sim looks up the record; on success the domain is marked **Verified**.
-DNS changes can take up to 48 hours to propagate — if verification does not succeed immediately, wait and retry. You can remove the TXT record after the domain is verified; the verification persists.
+
+ Some DNS providers — GoDaddy, Namecheap, Hover, and most cPanel panels — append your zone to whatever you type in the host field. If yours does, enter the host with the trailing zone removed, or you will end up with `_sim-challenge.acme.com.acme.com` and verification will never succeed. Managing the `acme.com` zone, `_sim-challenge.acme.com` becomes `_sim-challenge`; verifying the subdomain `eng.acme.com` from that same zone, `_sim-challenge.eng.acme.com` becomes `_sim-challenge.eng`. Cloudflare and Route 53 take the full host as shown.
+
+
+DNS changes can take up to 48 hours to propagate — if verification does not succeed immediately, wait and retry. Keep the TXT record published: leaving it in place means the domain stays verifiable if you ever need to verify it again.
Add each domain you own separately. Subdomains (`eng.acme.com`) are verified independently of the apex.
diff --git a/apps/sim/ee/sso/components/domain-settings.tsx b/apps/sim/ee/sso/components/domain-settings.tsx
index 4185d96aeb..04f10e6a8d 100644
--- a/apps/sim/ee/sso/components/domain-settings.tsx
+++ b/apps/sim/ee/sso/components/domain-settings.tsx
@@ -21,13 +21,15 @@ interface DomainSettingsProps {
interface CopyFieldProps {
label: string
value: string
+ hint?: string
}
-function CopyField({ label, value }: CopyFieldProps) {
+function CopyField({ label, value, hint }: CopyFieldProps) {
return (
{label}
+ {hint ? {hint} : null}
)
}
@@ -71,7 +73,11 @@ function DomainRow({ organizationId, domain, onRemove }: DomainRowProps) {
Add this TXT record at your DNS provider, then verify. DNS changes can take up to 48
hours to propagate.