Custom domain has correct DNS entries for verification, but Entra still says unverified

Tom Ngo 20 Reputation points
2026-05-28T05:10:29.9533333+00:00

We have a tenant for which we are trying to add a custom domain. In the DNS records for the custom domain, we've put in TXT and MX records, exactly as specified in the Entra custom domain UI.

But the UI still reports: "Failed to verify domain name".

The documentation says that one possible cause is that this domain name is already a custom domain name for some other Azure tenant. Can you check this for us? I know that you will likely contact us for further details via private message.

Microsoft Security | Microsoft Entra | Microsoft Entra ID

Answer accepted by question author
Jerald Felix 18,760 Reputation points Volunteer Moderator
2026-05-28T07:51:00.1333333+00:00

Hello Tom Ngo

Greetings! Thanks for raising this question in Q&A forum.

You've correctly identified the most likely cause. When the DNS records are exactly right and verification still fails, the most common reason is that the domain is already verified or registered in another Microsoft Entra tenant. Entra won't allow the same domain to exist in two tenants at the same time there is no DNS change or portal setting that will fix this on your side. Let me walk you through exactly how to confirm this and what to do next.

Step 1: Check which tenant currently holds your domain You can look this up yourself using this free tool simply enter your domain name at:

https://www.whatismytenantid.com/

This will show you the Tenant ID of the directory that currently has your domain verified. Note down this Tenant ID you will need it for the next steps.

Step 2: Determine which scenario applies to you

There are three possible cases:

Case A — The domain is in another tenant you own or manage If you are a Global Administrator in both directories, you simply need to unverify the custom domain from the current directory that holds it, and then re-verify it in your target tenant. Go to the other tenant's Entra admin center > Custom domain names > select your domain > Delete. Then retry verification in your target tenant.

Case B — The domain is in an unmanaged (shadow) tenant This happens when someone in your organization previously signed up for a Microsoft service (like Power BI or Microsoft 365 trials) using your company email domain, which created an unmanaged tenant. When you verify ownership of the domain name via admin takeover, Microsoft Entra ID removes the domain name from the unmanaged organization and moves it to your existing organization. You can perform an external admin takeover using the same DNS TXT record process.

Case C — The domain is in a managed tenant you do not own If the Tenant ID is different and you do not own that directory, the only option is to contact the Microsoft Data Protection team to request the removal of the domain verification from the existing Entra ID tenant. After the removal, you should be able to verify the domain in your tenant without any issues.

Step 3: Raise a Microsoft support ticket to involve the Data Protection team For Case C specifically, here is what to do:

  1. Go to the Microsoft Entra admin center > Help + Support > New support request
  2. Select the issue type as Technical, service as Microsoft Entra ID, and describe the domain verification failure
  3. Request involvement of the Microsoft Data Protection team, and provide your Tenant ID, the domain name, and any correlation/request IDs from the failed verification attempt
  4. The Data Protection team will reach out via email or phone to help resolve the issue — this is the official escalation path when the domain is locked in a tenant you cannot access

Step 4: While waiting — verify your DNS records are correct Just to rule out any DNS issue on your side, use an external DNS lookup tool like https://mxtoolbox.com or run nslookup -type=TXT yourdomain.com from a command prompt. Confirm the exact TXT value shown in the Entra portal appears in the results. Also make sure you added the records to the authoritative DNS zone not just the domain registrar, if your nameservers point elsewhere.

If this answer helps you kindly accept the answer which will help others who have similar questions.

Best Regards,

Jerald Felix.

Was this answer helpful?

1 person found this answer helpful.
0 comments No comments

1 additional answer

Sort by: Most helpful
  1. AI answer

    2026-05-28T05:10:43.33+00:00

    Domain ownership cannot be checked directly, but the documented causes and checks for this situation can be outlined.

    1. Confirm DNS propagation and correctness
      • Wait at least an hour after creating the TXT/MX records; DNS propagation can take an hour or more.
      • At the registrar/DNS host, confirm that the TXT and/or MX records exactly match what is shown in the Microsoft Entra admin center for that domain.
      • Use an authoritative DNS lookup (for example, TXT or MX query with an online tool or nslookup) to ensure the verification record is visible externally. If the expected TXT or MX record is not returned, Entra ID will not be able to verify the domain.
    2. Ensure the records are in the authoritative DNS zone
      • If the domain’s nameservers point to another provider (for example, Microsoft 365 nameservers), the verification TXT/MX record must be created in that authoritative DNS zone, not only at the registrar. If the record is added in the wrong place, Entra ID will not see it and verification will fail.
    3. Check whether the domain is already in use in another directory
      • A custom domain can be verified in only one Microsoft Entra directory at a time. If it is already verified in another tenant, verification in the current tenant will fail.
      • The documented remediation is to remove the domain from the other directory first. That directory’s admin must delete the custom domain there before it can be verified in the new tenant. If access to the old tenant is lost, support assistance is required.
    4. Check for unmanaged (shadow) tenants created by self-service sign-up
      • If users in the organization have signed up for services like Power BI using the domain, an unmanaged tenant may exist that already holds the domain.
      • The documented fix is to perform an admin takeover of that unmanaged directory (internal or external admin takeover) and then manage/remove the domain as needed.
    5. If verification still fails
      • After confirming propagation, record correctness, authoritative DNS placement, and that the domain is not held by another tenant or unmanaged directory, and the Entra portal still reports “Failed to verify domain name,” the next step is to contact Microsoft support for tenant-specific investigation and to confirm whether the domain is bound to another directory.

    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.