Verifying your domain for domain capture
Last updated: July 30, 2026
Important: This feature is in limited rollout and not yet available to all customers. The domain capture experience described below may not appear in your Admin Portal. Contact enterprise@wispr.ai if you need access.
Available on: Wispr Flow Admin Portal (web, admins only)
Verify your company's domain so you can control what happens when someone signs up to Wispr Flow with an email at that domain — for example, auto-adding them to your team. Verification is self-serve and takes a few minutes: publish a DNS TXT record, then set your policy.
Before you start
Domain capture is optional — you and your teammates can continue to use Wispr Flow without verifying your domain.
You must be signed in as an admin (admin, superadmin, or IT admin) in the Wispr Flow Admin Portal. Members cannot see the verification UI.
Your organization must already be linked to the domain you want to verify. If your Settings page shows "Your organization is not linked to any domains," contact enterprise@wispr.ai to add one.
You need admin access to your DNS provider (for example, Cloudflare, GoDaddy, Namecheap, or Route 53) so you can publish a TXT record.
Verify your domain
Open the Admin Portal in your browser, go to Organization settings, and scroll to the Domain capture (Optional) section. Each linked domain appears as its own row with a Verified or Unverified label.
Click Start verification next to the unverified domain. A modal titled Verify [domain] opens and generates a unique TXT record with a Host and a Value.
Copy both fields using Copy host and Copy value. The Host follows the pattern
_wispr-verify.<your-domain>, and the Value always starts withwispr-verify=.Add a new TXT record in your DNS provider using the exact Host and Value, then save the change.
Return to the Wispr Flow tab and click Check verification. If you see "Domain verified successfully," you're done. If you see "TXT record not found yet," wait a few minutes and click Check verification again.
Tip: DNS changes can take up to an hour (sometimes longer) to propagate globally. A failed first check is normal — give it time before troubleshooting.
Note: Verification uses public DNS, so the record must be publicly resolvable — split-horizon or internal-only DNS will not work. The value must match exactly, with no extra characters. If you close the dialog before finishing, the button changes to Continue verification — click it to pick up where you left off, and your existing TXT record stays valid.
Set your domain capture policy
Once a domain is verified, a policy dropdown appears next to it on the Settings page. Choose one of two policies:
Off: Do not restrict new sign-ups on this domain.
Require team membership: Users signing up with this domain must join this enterprise to use Flow.
Until you pick one, the dropdown displays the placeholder text Not set and no domain capture rule applies. You can change the policy at any time, and the new value takes effect immediately. On a successful change, a Domain capture policy updated toast appears. If the change fails to save, it rolls back and a Failed to update domain capture policy toast appears.
Important: A domain must be verified before you can set a policy. On unverified domains, the dropdown does not appear — a Start verification or Continue verification button is shown in its place.
Note: Enforcement of Require team membership is rolling out. After you set the policy on a verified domain, the join prompt appears in the desktop app once the rollout reaches your organization. Your setting is saved either way.
What new users see during sign-up
When a new user signs up with an email at your domain, they see a team step during onboarding. What appears depends on whether a team already exists for your domain:
Existing team detected: Users see a Team Consolidation step that pre-selects current teammates from your domain. They can add invite emails before joining, or choose Skip for now to bypass this step. Clicking Continue without selecting or adding any emails has the same effect as Skip. This step is part of an active rollout and is only shown to some users whose organization is detected as having existing members — not every user with an existing-team domain will see it.
No existing team: Users first see an Invite your team step where they can enter one or more teammate emails (or Skip for now). If they add at least one email and continue, they then see a Create a team name step pre-filled with a name generated from their email domain, with an Auto-add all future @[domain] users checkbox (checked by default). When enabled, anyone who later signs up with your domain is automatically added to the team — no manual invite needed. If they submit zero emails or skip, the create-team step is not shown.
Important: Enabling Auto-add all future @[domain] users automatically adds a paid seat to your plan for every new user who signs up with your domain. Review your plan before enabling this option.
This option is set during team creation. To change it later, contact support. The team member view shows a +N joined this month indicator so you can track how many users were auto-added recently.
FAQs
How is this different from verifying my domain for SSO?
They are independent. SSO setup is handled separately and does not require a customer-facing DNS step. Domain capture verification uses a DNS TXT record and only controls sign-up behavior on your domain. You can have one without the other. See Verify your domain for SSO.
Does verification ever expire?
No. Once a domain is verified it stays verified, and you can leave the TXT record in your DNS or remove it. We do not auto-recheck.
Can members see or change this?
No. Only admins (admin, superadmin, or IT admin roles) see the domain verification section in Settings, and only admins can start verification or change the policy. Non-admins see the message "Only admins can see domain verification status."
I added the TXT record but Check verification keeps failing. What should I check?
Confirm the following:
The Host and Value match exactly what the dialog showed. Extra spaces or quotes can cause failures.
The value is exactly
wispr-verify=<token>with nothing extra. Some DNS providers wrap TXT values in quotes or append content — make sure the saved record is byte-for-byte identical to what the dialog showed.DNS has had time to propagate. Up to an hour is normal, occasionally longer.
The record is on the correct domain (not on a subdomain by mistake).
If it still fails after an hour, reach out to support.
Can I verify multiple domains?
Yes. Each domain linked to your organization shows up as its own row in Settings, with its own verification status, TXT record, and policy. Verify and set a policy on each one independently.
When are invited team members notified?
Invited teammates receive an email notification and are added to the team when they next log in to Wispr Flow.
What does "Auto-add all future @domain users" do?
When enabled, anyone who signs up with your domain is added to your team automatically and a seat is added to your plan. This option is set during team creation; to change it later, contact support. See What new users see during sign-up above for the full behavior.
Still need help?
Reach out to support if:
Your Settings page shows your organization is not linked to any domains and you need one added.
DNS has propagated (confirmed with a public DNS lookup tool) but Check verification still fails.
You want to remove or change a domain that is already verified.
Include your organization name, the domain you are verifying, and a screenshot of the TXT record in your DNS provider — that is usually all we need.