A cloud-based identity and access management service for securing user authentication and resource access
Hello Tom Ngo
Greetings! Thanks for raising this question in Q&A forum.
You've correctly identified the most likely cause. When the DNS records are exactly right and verification still fails, the most common reason is that the domain is already verified or registered in another Microsoft Entra tenant. Entra won't allow the same domain to exist in two tenants at the same time there is no DNS change or portal setting that will fix this on your side. Let me walk you through exactly how to confirm this and what to do next.
Step 1: Check which tenant currently holds your domain You can look this up yourself using this free tool simply enter your domain name at:
https://www.whatismytenantid.com/
This will show you the Tenant ID of the directory that currently has your domain verified. Note down this Tenant ID you will need it for the next steps.
Step 2: Determine which scenario applies to you
There are three possible cases:
Case A — The domain is in another tenant you own or manage If you are a Global Administrator in both directories, you simply need to unverify the custom domain from the current directory that holds it, and then re-verify it in your target tenant. Go to the other tenant's Entra admin center > Custom domain names > select your domain > Delete. Then retry verification in your target tenant.
Case B — The domain is in an unmanaged (shadow) tenant This happens when someone in your organization previously signed up for a Microsoft service (like Power BI or Microsoft 365 trials) using your company email domain, which created an unmanaged tenant. When you verify ownership of the domain name via admin takeover, Microsoft Entra ID removes the domain name from the unmanaged organization and moves it to your existing organization. You can perform an external admin takeover using the same DNS TXT record process.
Case C — The domain is in a managed tenant you do not own If the Tenant ID is different and you do not own that directory, the only option is to contact the Microsoft Data Protection team to request the removal of the domain verification from the existing Entra ID tenant. After the removal, you should be able to verify the domain in your tenant without any issues.
Step 3: Raise a Microsoft support ticket to involve the Data Protection team For Case C specifically, here is what to do:
- Go to the Microsoft Entra admin center > Help + Support > New support request
- Select the issue type as Technical, service as Microsoft Entra ID, and describe the domain verification failure
- Request involvement of the Microsoft Data Protection team, and provide your Tenant ID, the domain name, and any correlation/request IDs from the failed verification attempt
- The Data Protection team will reach out via email or phone to help resolve the issue — this is the official escalation path when the domain is locked in a tenant you cannot access
Step 4: While waiting — verify your DNS records are correct Just to rule out any DNS issue on your side, use an external DNS lookup tool like https://mxtoolbox.com or run nslookup -type=TXT yourdomain.com from a command prompt. Confirm the exact TXT value shown in the Entra portal appears in the results. Also make sure you added the records to the authoritative DNS zone not just the domain registrar, if your nameservers point elsewhere.
If this answer helps you kindly accept the answer which will help others who have similar questions.
Best Regards,
Jerald Felix.