Why Verify Your Domain?
Verifying your company's email domain lets your team members discover SSO automatically from the Tomba sign-in page. When someone enters an email address with your domain (e.g., [email protected]), Tomba recognizes it and offers the SSO sign-in option.
Without domain verification, members need to know the direct SSO link to sign in.
Step 1: Go to Verified Domains
Scroll down to the Verified Domains section.
Click Add Domain.
Step 2: Enter Your Domain
In the modal, type your company's email domain — for example,
yourcompany.com.Click Add Domain.
[Image: add_domain_modal.png] — Upload this image
Tip: Use the domain that matches your team's email addresses. If your team uses @yourcompany.com, enter yourcompany.com.
Step 3: Add the DNS TXT Record
Tomba needs to verify that you own the domain. You'll do this by adding a DNS record.
After adding your domain, Tomba shows you the DNS record to create:
[Image: dns_verification_wizard.png] — Upload this image
Copy these values and add them to your domain's DNS settings:
Field | Value |
Host / Name |
|
Type |
|
Value |
|
Use the copy buttons in the wizard to avoid typos.
Where to add DNS records — this depends on where your domain is registered:
Cloudflare — DNS > Records > Add Record
GoDaddy — DNS Management > Add New Record
Namecheap — Domain List > Manage > Advanced DNS > Add New Record
Google Domains — DNS > Custom Records > Manage Custom Records
If you're not sure where your DNS is managed, ask your IT team.
Step 4: Wait for Verification
After adding the DNS record, Tomba automatically checks every 15 seconds to see if the record is live. You'll see a "Checking DNS…" spinner in the wizard.
Verification succeeds — You'll see a green checkmark and the message "Domain verified!" The modal closes automatically.
[Image: domain_verified_success.png] — Upload this image
Still waiting? — DNS changes can take anywhere from a few minutes to 48 hours to propagate, depending on your DNS provider. You can close the modal and verify later.
Tip: Click Verify Now at any time to trigger an immediate check, or click I'll verify later to close the modal and come back to it.
🔧 Managing Your Domains
After closing the wizard, your domain appears in the Verified Domains list with its status:
Verified (green badge) — The domain is active and SSO discovery is enabled.
Pending (yellow badge) — DNS verification hasn't completed yet. You can click Verify to retry.
To remove a domain, click the trash icon next to it. This disables SSO discovery for that domain but doesn't affect existing SSO logins.
💡 Tips
You can add multiple domains if your organization uses more than one email domain.
Domain verification only needs to be done once. The DNS record can stay in place.
Verifying a domain doesn't force anyone to use SSO — it just makes it easier to find. Use SSO Enforcement Modes to control whether SSO is optional or required.
Related Resources
SAML Single Sign-On (SSO) — SSO overview
Set Up SAML SSO — Step-by-step setup guide
SSO Enforcement Modes — Control how your team signs in
Need Help?
Got questions about domain verification? Contact our support team — we're here to help!
