domains

POST /v1/domains/{domainId}/registrar-guide/verify

Check now whether this domain's nameserver change has taken effect.

All domains endpoints

Authentication

Send an API key as a bearer token. The key must carry the sites.view permission; a key without it is refused with 403, not 404.

This endpoint takes no organisation id. Your key already identifies the organisation it belongs to, and the response is scoped to it.

Try it

Replace anything in angle brackets with your own values, and the key placeholder with a key from your dashboard.

curl -X POST https://api.zinndigital.com/v1/domains/{domainId}/registrar-guide/verify \
  -H "Authorization: Bearer zdk_live_…"

Signed in? The API console in your dashboard fills in your real organisation id and your own key, and runs the request against the live API so you can see the actual response. Open this endpoint in the API console

Details

The **verify button** on the instruction card. Reads the live public DNS and the domain's registry record and answers in four states, so the customer can tell whether the steps they just followed worked. ⛔ **Four outcomes, where `GET /v1/domains/{domainId}/delegation` has three, and the fourth is the point.** That endpoint is a drift watch and answers `delegated` / `not_delegated` / `unknown` — correct for what it does. It is not sufficient here: a customer who pressed Save at their registrar thirty seconds ago is genuinely `not_delegated` to any resolver, because the registry has the change and nothing else does yet. Telling them "not yet" is true, useless, and reads as failure. `propagating` is that state told honestly — **the registry has the pair we asked for and public DNS has not caught up** — and it is a success message, not a warning. ⛔ `unknown` is not `not_delegated`. They send a customer to opposite actions, and a lookup that failed must never be rendered as "you have not done it". `expected` is resolved **per domain** from the zone's own nameservers where the DNS provider assigns them, so a footprint-free domain is compared against its own pair rather than a platform constant. `observed` is what it points at right now — public DNS where that answered, the registry's record otherwise. **Writes nothing.** The recorded reading, the drift ladder and the "your domain has left us" alarm belong to `GET`/`POST /v1/domains/{domainId}/delegation`; a customer pressing a button on an instruction card is asking a question, not supplying evidence. `POST` rather than `GET` only because it makes two live outbound lookups and must never be cached or prefetched. Requires `sites.view`, RLS-scoped. It changes nothing about the domain, and gating it behind a management permission would leave a read-only user looking at instructions they can never confirm they have followed.

Parameters

NameTypeRequiredWhat it is
domainId (path)UuidYesThe domain's id.

Response

NameTypeRequiredWhat it is
outcomestring<delegated, propagating, not_delegated, unknown>Yes`delegated` = done. `propagating` = the registry has our pair and public DNS has not caught up; the customer did it right and must simply wait. `not_delegated` = a real reading…
expectedstring[]YesThe pair to set, resolved **per domain** from the zone's own nameservers where the provider assigns them — never a platform constant (D1034).
observedstring[]YesWhere it points right now — public DNS where that answered, the registry's record otherwise. Empty means the reading was positive and there was nothing there, not that the readi…
recheck_after_secondsintegerYesRoughly how long to wait before pressing again, or `null` when there is nothing to wait for. A hint about the interface, not a claim about DNS propagation.

Errors this endpoint can return

401 · 403 · 404