Closing out the dns.TXT sweep (#277, #278, #280, #281, #282, #284, #285, #286, #287) with the
candidates I am not proposing, and why. Corpus throughout: 6215 TXT records from 178 mutually
independent apex domains, resolver 1.1.1.1.
A. Tokens I cannot attribute to a vendor
These are well-formed, corroborate widely, and produce zero false positives — but I could not find
public documentation tying them to a product, so I am not guessing at an entry.
| Token |
Domains |
Records |
Sample value |
mgverify= |
18 |
35 |
mgverify=4e7a1ef686139875f21ee18e629284f4b32b4bef29516a48d428069 |
ms-domain-verification= |
13 |
23 |
ms-domain-verification=ac8dd20b-3188-4459-b004-7200f30e32e5 |
dtm-domain-verification= |
13 |
13 |
dtm-domain-verification=pKWJVhJM8WfWtDBjyfKZjwxGurB9fiCf1TpvWO_K |
astro-domain-verification= |
10 |
10 |
astro-domain-verification=cm5hb8qjm3wb901m7e7upqm1x |
work-accounts-domain-verification= |
5 |
6 |
work-accounts-domain-verification=E1Dam7wMb2Dy2rNshwaxprSeqb3Oig |
Notes on the two I tried hardest to pin down:
mgverify= — a web search suggests Mailgun, but the corpus does not support it: of the
18 domains carrying mgverify=, only 5 carry any Mailgun reference
at all (SPF include or otherwise). I am treating the attribution as unproven.
work-accounts-domain-verification= — appears on 5 domains
including google.com, which is suggestive of a Google product but is weak evidence on its own,
since google.com carries almost every token in the corpus.
I also tried co-occurrence attribution — checking which known vendors appear on the same domains — and
it is useless at this scale: atlassian-domain-verification= is on 133 of 178 domains, so ~90%
co-occurrence with anything is what chance already produces.
If a maintainer recognises any of these, I will write the entry and the corroboration.
B. Candidates below the ten-link bar
| Candidate |
Pattern |
Domains |
Records |
| Wrike |
wrike-verification= |
9 |
13 |
| LucidLink |
lucidlink-verification= |
9 |
11 |
| Cisco Duo |
duo_sso_verification= |
9 |
15 |
| Cisco Intersight |
^intersight= |
8 |
12 |
| Trend Micro Email Security |
^tmes= |
5 |
7 |
| Axway Amplify |
axway-amplify= |
2 |
7 |
| Adobe Experience Manager |
^_aemverification\. |
1 |
6 |
Trend Micro Email Security has internal corroboration despite the low count: every domain carrying
tmes= also carries include:spf-us.tmes.trendmicro.com in its SPF record.
Cisco Duo is a candidate for the Cisco entry proposed in #284 rather than its own entry, since Duo
is a Cisco product — happy to add it there if you'd rather not have a separate entry.
C. Deliberately excluded
google-site-verification= matched 167 of 178 domains that returned TXT (850 records). It is used
interchangeably for Search Console, Workspace verification, Ads and more, so a fingerprint on it would
fire almost always while identifying almost nothing.
Question
Is the ten-link rule in CONTRIBUTING.md a hard bar for dns.TXT fingerprints specifically? A
verification token is self-identifying in a way a scriptSrc pattern is not, and measured on this
corpus the catalog already carries loom-verification (4 domains), windsurf-verification= (4) and
heroku-domain-verification (0). If the bar is firm I will extend the corpus and come back only with
what clears it.
Closing out the
dns.TXTsweep (#277, #278, #280, #281, #282, #284, #285, #286, #287) with thecandidates I am not proposing, and why. Corpus throughout: 6215 TXT records from 178 mutually
independent apex domains, resolver
1.1.1.1.A. Tokens I cannot attribute to a vendor
These are well-formed, corroborate widely, and produce zero false positives — but I could not find
public documentation tying them to a product, so I am not guessing at an entry.
mgverify=mgverify=4e7a1ef686139875f21ee18e629284f4b32b4bef29516a48d428069ms-domain-verification=ms-domain-verification=ac8dd20b-3188-4459-b004-7200f30e32e5dtm-domain-verification=dtm-domain-verification=pKWJVhJM8WfWtDBjyfKZjwxGurB9fiCf1TpvWO_Kastro-domain-verification=astro-domain-verification=cm5hb8qjm3wb901m7e7upqm1xwork-accounts-domain-verification=work-accounts-domain-verification=E1Dam7wMb2Dy2rNshwaxprSeqb3OigNotes on the two I tried hardest to pin down:
mgverify=— a web search suggests Mailgun, but the corpus does not support it: of the18 domains carrying
mgverify=, only 5 carry any Mailgun referenceat all (SPF include or otherwise). I am treating the attribution as unproven.
work-accounts-domain-verification=— appears on 5 domainsincluding
google.com, which is suggestive of a Google product but is weak evidence on its own,since
google.comcarries almost every token in the corpus.I also tried co-occurrence attribution — checking which known vendors appear on the same domains — and
it is useless at this scale:
atlassian-domain-verification=is on 133 of 178 domains, so ~90%co-occurrence with anything is what chance already produces.
If a maintainer recognises any of these, I will write the entry and the corroboration.
B. Candidates below the ten-link bar
wrike-verification=lucidlink-verification=duo_sso_verification=^intersight=^tmes=axway-amplify=^_aemverification\.Trend Micro Email Securityhas internal corroboration despite the low count: every domain carryingtmes=also carriesinclude:spf-us.tmes.trendmicro.comin its SPF record.Cisco Duois a candidate for theCiscoentry proposed in #284 rather than its own entry, since Duois a Cisco product — happy to add it there if you'd rather not have a separate entry.
C. Deliberately excluded
google-site-verification=matched 167 of 178 domains that returned TXT (850 records). It is usedinterchangeably for Search Console, Workspace verification, Ads and more, so a fingerprint on it would
fire almost always while identifying almost nothing.
Question
Is the ten-link rule in
CONTRIBUTING.mda hard bar fordns.TXTfingerprints specifically? Averification token is self-identifying in a way a
scriptSrcpattern is not, and measured on thiscorpus the catalog already carries
loom-verification(4 domains),windsurf-verification=(4) andheroku-domain-verification(0). If the bar is firm I will extend the corpus and come back only withwhat clears it.