No KYB · No Email · Wallet Only
Powered by XRPL Mainnet
The complete guide · Domain Verification

Prove a domain belongs to your wallet — both directions.

A VerifiedHub domain badge proves one thing that can't be faked: the same person controls both the XRPL wallet and the website. This guide explains exactly how it works, what you can verify, how to publish your file, and what your badge means.

$5one-time, paid in XRP · badge renews yearly
How it works Why it can't be faked What you can verify Anchor vs badge The steps Publishing the file For your web admin FAQ

01 How it works

Domain verification links two things that only the real owner can connect: your XRPL wallet and your website. We confirm the link from both sides and match them ourselves — we never take anyone's word for it.

The two-way check
Your wallet
on the XRP Ledger
names domain
lists wallet
Your domain
your website

One direction: your wallet's on-chain Domain field points to your website. The other: your website hosts a small file (xrp-ledger.toml) that lists your wallet. When both agree, you're verified.

02 Why it can't be faked

The badge is trustworthy because neither half alone proves anything — and that's by design. Here's why each half is weak on its own, but unbreakable together:

Half 1 · weak alone

The website file

Anyone who runs a website can write any wallet address into their TOML file. A scammer could list your wallet on their site. So "the file lists this wallet" proves nothing by itself.

Half 2 · weak alone

The on-chain Domain field

Anyone can set their wallet's Domain field to any text — even a domain they don't own. So "the wallet points to this domain" proves nothing by itself either.

✓ Both together · proof

Only the true owner controls both sides

Writing a wallet into a website's file needs control of the server. Setting a wallet's on-chain Domain field needs the wallet's private key. These are held by different keys — so when both match, the same person must control the website and the wallet. An impostor who has only one side can never fake the other.

Think of a safe-deposit box that needs two keys turned at once. Either key alone opens nothing — that's the point. Requiring both means no impostor can get in with just one.

03 What you can verify

The test is simple: domain verification works on any website where you (or your web admin) can publish a file on the server. It does not work on a profile hosted on someone else's platform — because you don't control their server.

Works
  • Your business websiteyourbrand.com
  • A subdomain you controlshop.yourbrand.com
  • Any site where you can add a file at /.well-known/
Doesn't work
  • Amazon storefrontamazon.com/stores/…
  • Facebook / LinkedIn Page
  • X / YouTube channel
  • Etsy / eBay store
The simple test: Can you (or your web admin) upload a file to the website? If yes, you can verify it. If it's only a profile on a big platform, you can't — that platform's domain isn't yours.
Looking for a different verification? X accounts, usernames, and AI agents each have their own flow.
See all Verifications →

04 Two things, two lifespans

Domain control can change — a domain can be sold or transferred. So your verification has two parts that last for different lengths of time, and we're explicit about both:

Permanent · cannot be changed

On-chain anchor

When you sign the AccountSet, the link between your wallet and domain is written to the XRP Ledger — forever. It is timestamped, public, and can never be changed or deleted by anyone, including us. That proof is yours permanently.

1 year

Verified badge

The badge confirms you still control the domain right now. Because domains can change hands, we re-check yearly to keep it honest. Renew anytime to confirm continued control.

05 The steps

  1. Connect your wallet & enter your domain
    The same wallet you'll verify from. No username required — domain verification works on its own, and links to your username automatically if you claim one later.
  2. Pay the fee — $5 in XRP
    A one-time $5, converted to XRP at checkout. Sign once in your wallet — we capture the payment automatically, nothing to copy. This issues a verification credit that never expires until you're verified.
  3. Sign the AccountSet
    A second signature writes your domain into your wallet's on-chain Domain field. Free — no payment, just a signature. This anchor is written to the XRP Ledger permanently and can never be changed or deleted.
  4. Publish your TOML file
    Add the file we generate to your site at /.well-known/xrp-ledger.toml. On WordPress, our plugin does it for you; otherwise your web admin uploads it.
  5. Verify
    Click Verify now when it's live — or do nothing, and our hourly re-checker finds it and verifies you automatically. Your credit holds until both halves match, however long that takes.

06 Publishing the file

Everyone gets the same file. How you publish it is up to you:

🔌

On WordPress

Easy

Install the VerifiedHub plugin, enter your wallet, and it publishes the file for you automatically. Hand it to your web admin if you'd rather they install it.

📄

Everywhere else

Manual

Download the file and send it to your web admin with the requirements below. They'll know exactly what to do.

The file must meet four requirements to verify:

📁
Exact location
Served at https://yourdomain/.well-known/xrp-ledger.toml — folder name starts with a dot, filename exactly as shown.
🔒
HTTPS
Must load over https://, not http://.
🌐
Publicly readable
No login or password wall in front of it.
CORS header
Sends Access-Control-Allow-Origin: * so we can read it.

07 Send this to your web admin

Not the technical one? Copy this message, attach the file we generate, and send it on. Replace yourdomain.com with your domain.

Message for your web admin
Hi — please publish the attached file on our website so it loads at exactly: https://yourdomain.com/.well-known/xrp-ledger.toml Requirements: • Served over HTTPS (not HTTP) • Publicly accessible (no login) • Sends header: Access-Control-Allow-Origin: * • Folder and filename exactly as above (note the leading dot in .well-known) Once it's live, let me know. Thanks!

08 Frequently asked

Do I need a username first?
No. Domain verification is standalone — your wallet is all you need. If you claim a username later, your verified domain links to it automatically, because both are tied to the same wallet.
What if I publish the file wrong the first time?
No problem. Your paid credit never expires and survives unlimited retries. Fix the file or the AccountSet and check again — there's never a second charge until you're verified.
Why does the badge expire after a year if the anchor is permanent?
They're two different things. The on-chain anchor is a permanent historical record — yours forever. The badge is a freshness guarantee that you still control the domain right now. Since domains can be sold, we re-check yearly so the badge never silently lies.
Do I paste the file contents back to VerifiedHub?
No. You publish it on your own site, and we fetch it ourselves from your domain. You only tell us your domain (or paste the file's URL) — we read the live file directly. That's what keeps the verification trustworthy.
Can I verify a domain I don't own the server for?
No. You must be able to publish a file on the website. If it's a profile on a platform like Amazon, Facebook, or Etsy, you don't control their server, so it can't be verified this way.
Is the payment refundable?
The $5 is non-refundable, but it buys a credit that never expires until you verify — so as long as you eventually publish your file and set your Domain field, you'll get verified. The free TOML checker lets you confirm your setup first.

Ready to verify your domain?

Connect your wallet, enter your domain, and follow the steps.

Verify a domain → Want to test your TOML first? Use the free TOML checker.
← Back to directory
Copied to clipboard