Once a custom domain is verified for a web app or static web app, can I delete the TXT verification record from our DNS or does that need to remain active?

Daniel-4204 45 Reputation points
2024-09-19T13:38:05.97+00:00

Once a custom domain is verified for a web app or static web app, can I delete the TXT verification record from our DNS or does that need to remain active?

image

Azure App Service
Azure App Service
Azure App Service is a service used to create and deploy scalable, mission-critical web apps.
7,913 questions
Azure Static Web Apps
Azure Static Web Apps
An Azure service that provides streamlined full-stack web app development.
968 questions
0 comments No comments
{count} votes

Accepted answer
  1. TP 98,086 Reputation points
    2024-09-19T14:01:42.9266667+00:00

    Hi,

    For a web app it is preferred (not mandatory) to leave the txt record in place to prevent potential future subdomain takeover. For static web app it makes no difference--in other words you can delete it if you want.

    Excerpt from documentation:

    These records don't prevent someone from creating the Azure App Service with the same name that's in your CNAME entry. Without the ability to prove ownership of the domain name, threat actors can't receive traffic or control the content.

    app service txt record warning

    Above warning from this article.

    Please click Accept Answer and upvote if the above was helpful.

    Thanks.

    -TP

    1 person found this answer helpful.
    0 comments No comments

1 additional answer

Sort by: Most helpful
  1. Marcin Policht 25,925 Reputation points MVP
    2024-09-19T14:05:08.57+00:00

    As per https://video2.skills-academy.com/en-us/azure/dns/dns-web-sites-custom-domain

    App Services uses this record only at configuration time to verify that you own the custom domain. You can delete this TXT record after your custom domain is validated and configured in App Service.


    If the above response helps answer your question, remember to "Accept Answer" so that others in the community facing similar issues can easily find the solution. Your contribution is highly appreciated.

    hth

    Marcin

    1 person found this answer helpful.
    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.