Urgent.News

What's breaking now, across thousands of outlets.

Tech

Customer Domain Verification: Scheduled Polling and Triggered Rechecks for Tenant Onboarding

Give each fintech tenant a platform-owned subdomain first, and activate it from the platform's own DNS change. For a customer-owned hostname, run scheduled verification in the background and offer a customer-triggered recheck as an extra control. A button alone cannot establish that a DNS change has reached the resolver doing the check. Short answer: use the DNS ownership boundary to choose the…

Fintech tenants receive a subdomain from the platform, which is activated through the platform's DNS change. For customer-owned hostnames, the platform conducts scheduled verification in the background and offers a customer-triggered recheck as an additional control. However, a button alone is insufficient to confirm that a DNS change has reached the resolver performing the check.

The platform uses the DNS ownership boundary to determine the default verification method. A customer-owned zone undergoes scheduled checks, supplemented by a rate-limited recheck. The platform provides separate states like awaiting DNS, verified, and ready to serve, along with the last observed result and check time. It never treats a failed lookup as a permanent rejection, as the customer may still be editing the zone.

The platform recommends controlling ownership first, with customer-triggered rechecks used only when necessary. The feedback latency is a secondary criterion. While a customer may have published the correct record, a resolver might still be returning an earlier absence. A recheck reports what this verifier observed, not a guarantee of global propagation.

The verification worker maintains a small state machine, persisting the hostname, tenant ID, challenge, attempt count, next check time, and last observation. A customer-initiated recheck moves an eligible record forward in the queue, calling the same verifier. This ensures that both scheduled jobs and manual rechecks adhere to the same verification rules and avoid disagreements.

In summary, the verification process prioritizes DNS ownership, uses scheduled checks with customer-triggered rechecks as an optional control, and maintains transparency through distinct states and clear status updates.

Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at dev.to →

More in Tech

Cyber Decoys After the CISA Guide: Turning an Assumed Breach into an Alert Pipeline

Cyber Decoys After the CISA Guide: Turning an Assumed Breach into an Alert Pipeline On 16 September 2026, CISA published Using Cyber Decoys to Strengthen Detection and Response , its first guide that…

  • CISA released comprehensive guide on 16 September 2026 for implementing cyber decoys.
  • Decoys create high-fidelity evidence of malicious exploration in critical infrastructure.
  • Effective placement of decoys crucial to avoid false positives and maintain detection effectiveness.

Governance Attack Surface Review: Gemini

Governance Attack Surface Review: Gemini Target Protocol : Gemini (TVL: $5636.8M) Gemini – Governance Attack Surface Review TVL: ≈ $5.64 B (Ethereum + L2) Date: 24 Sep 2026 Prepared by: [Your Name]…

  • Nine distinct attack vectors identified in Gemini Protocol review
  • Highest risk score of 7.4 out of 10 indicates high risk level
  • Recommendations focus on technical and governance improvements

More from Thursday 24 September →