---
title: "Configuring Domains"
canonical: "https://docs.infoblox.com/space/BloxOneCloud/35397045/Configuring%20Domains"
format: markdown
---
<span style="color: #000000">The </span>**<span style="color: #000000">Infoblox SSO Portal</span>**<span style="color: #000000"> > </span>**<span style="color: #000000">Domains</span>**<span style="color: #000000"> page allows you to view, manage, and verify mastery of the domains you wish to configure for 3rd party IdP or multi-factor authentication.</span>

<span style="color: #000000">By default, a domain entry is present when you first log in to the account. This entry matches the company domain that was created with your account. The default domain entry must be mastered before it can be used to configure 3rd party IdP or multi-factor authentication.</span>

> ⚠️ **Note**
> ⚠️ 
> ⚠️ <span style="color: #000000">You can configure 3rd party IdPs and MFA (multi-factor authentication) only for domains that you master. </span>

<span style="color: #000000">To configure domains for your account, complete the following sections.</span>

# <span style="color: #000000">Adding Domain</span>

<span style="color: #000000">In the context of SSO, a domain refers to the web address that is specific to your organization. Specifically, a domain represents the part of an email address that comes after the “@” symbol. The domain signifies the web address associated with an email account. For example, if your organization is named Example Corporation and you use the domain </span>*<span style="color: #000000">example.com</span>*<span style="color: #000000">, your employees’ email addresses might follow this format: </span>*<span style="color: #000000">firstname.lastname@example.com</span>*<span style="color: #000000">. In this case, </span>*<span style="color: #000000">example.com</span>*<span style="color: #000000"> serves as the custom email domain that is unique to your organization.</span>

<span style="color: #000000">To add a domain, complete the following:</span>

1. <span style="color: #000000">Log in to the Infoblox SSO Portal at </span>[<span style="color: #000000">https://sso.infoblox.com/</span>](https://sso.infoblox.com/)<span style="color: #000000">.</span>
2. <span style="color: #000000">On the </span>*<span style="color: #000000">Domains</span>*<span style="color: #000000"> page, click </span>**<span style="color: #000000">Add Domain</span>**<span style="color: #000000">.</span>
3. <span style="color: #000000">In the </span>*<span style="color: #000000">Add Domain</span>*<span style="color: #000000"> dialog, enter a domain name.</span>
4. <span style="color: #000000">Click </span>**<span style="color: #000000">Save & Close</span>**<span style="color: #000000">.</span>

# <span style="color: #000000">Proving Mastery of Domain</span>

<span style="color: #000000">Once you have added a domain, it is important to verify the mastery of it. The verification not only ensures a secure authentication process, but also prevents other customers from using the same domain.</span>

> ⚠️ <span style="color: #000000">Domain verification takes place during the initial setup. Once the domain is successfully mastered, it becomes exclusively associated with your SSO Portal. The system does not recheck the TXT record periodically or verify token presence a second time.</span>

<span style="color: #000000">To verify mastery of a domain, complete the following:</span>

1. <span style="color: #000000">Log in to the Infoblox SSO Portal at </span>[<span style="color: #000000">https://sso.infoblox.com/</span>](https://sso.infoblox.com/)<span style="color: #000000">.</span>
2. On the *Domains* page, c<span style="color: #000000">opy the verification token of the target domain.</span>
3. <span style="color: #000000">Open a second browser window and sign in to your domain host account.</span>
4. <span style="color: #000000">Go to your domain’s DNS records. This page title could be one of the following depending on your browser: </span>**<span style="color: #000000">DNS Management</span>**<span style="color: #000000">, </span>**<span style="color: #000000">Name Server Management</span>**<span style="color: #000000">, </span>**<span style="color: #000000">Control Panel</span>**<span style="color: #000000">, or </span>**<span style="color: #000000">Advanced Settings</span>**<span style="color: #000000">.</span>
5. <span style="color: #000000">Select the option to add a new DNS record.</span>
6. <span style="color: #000000">For the record type, select </span>**<span style="color: #000000">TXT</span>**<span style="color: #000000">.</span>
7. <span style="color: #000000">In the </span>**<span style="color: #000000">Name/Host/Alias</span>**<span style="color: #000000"> field, enter </span>**<span style="color: #000000">@</span>**<span style="color: #000000"> or leave it blank. Your host might require you to enter your domain in this field, which in this example is </span>*<span style="color: #000000">example.com</span>*<span style="color: #000000">. Your other DNS records might indicate what you should enter.</span>
8. <span style="color: #000000">In the </span>**<span style="color: #000000">Value</span>**<span style="color: #000000">/</span>**<span style="color: #000000">Answer</span>**<span style="color: #000000">/</span>**<span style="color: #000000">Destination</span>**<span style="color: #000000"> field, paste the verification token you copied from the </span>*<span style="color: #000000">Domains</span>*<span style="color: #000000"> page. Ensure that you copy the entire token string to include the prefix </span>*<span style="color: #000000">infobox-domain-mastery=</span>*
9. <span style="color: #000000">Save the record.</span>
10. <span style="color: #000000">Verify that the TXT record has been successfully added as follows:</span>
  1. <span style="color: #000000">Wait approximately five minutes for the record to propagate.</span>
  2. <span style="color: #000000">You may check if your record is updated by performing a '</span>*<span style="color: #000000">dig</span>*<span style="color: #000000">' command from a terminal.</span>
  3. <span style="color: #000000">Run 'dig -t txt <your domain here>' in which <your domain here> is your domain. In this example, the domain is </span>*<span style="color: #000000">example.com</span>*<span style="color: #000000">.</span>
  4. <span style="color: #000000">You should see an output similar to the following:</span>  
<span style="color: #000000">; <<>> DiG 9.14.8 <<>> -t txt example.com;; global options: +cmd</span>  
<span style="color: #000000">;; Got answer:</span>  
<span style="color: #000000">;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 9528</span>  
<span style="color: #000000">;; flags: qr rd ra; QUERY: 1, ANSWER: 5, AUTHORITY: 0, ADDITIONAL: 1</span>  
<span style="color: #000000">;; OPT PSEUDOSECTION:</span>  
<span style="color: #000000">; EDNS: version: 0, flags:; udp: 4096</span>  
<span style="color: #000000">; COOKIE: fnjakghvu3q8fxx2jfc902jcw9hco9h3bvaxeojviowjv0wjf0 (good)</span>  
<span style="color: #000000">;; QUESTION SECTION:</span>  
<span style="color: #000000">;example.com.            IN    TXT</span>  
<span style="color: #000000">;; ANSWER SECTION:</span>  
<span style="color: #000000">example.com.        300        IN    TXT    "infoblox-domain-mastery=fjakldshgajrfoiwxxxfuihaebvnlwajfoh3iu283ru98g44hiwnvlzkbk"</span>  
<span style="color: #000000">;; Query time: 42 msec</span>  
<span style="color: #000000">;; SERVER: 192.0.2.1#53(192.0.2.2)</span>  
<span style="color: #000000">;; WHEN: Mon Jun 29 09:33:13 PDT 2020</span>  
<span style="color: #000000">;; MSG SIZE  rcvd: 380</span>
11. <span style="color: #000000">Go back to the SSO Portal.</span>
12. <span style="color: #000000">On the </span>*<span style="color: #000000">Domains</span>*<span style="color: #000000"> page, select the checkbox of the domain to verify (in this example, it is </span>*<span style="color: #000000">example.com</span>*<span style="color: #000000">).</span>
13. <span style="color: #000000">Click </span>**<span style="color: #000000">Verify Master</span>**<span style="color: #000000">. The system checks the TXT record of the selected domain and whether the verification token is present. If the token is in the record, your domain is verified and solely linked to your SSO Portal.</span>