Cybersecurity verification

Cybersecurity keys can be aimed at live or remote servers. Before that is allowed, you prove you control the domain those servers answer on.

Prerequisites

Cybersecurity also requires identity verification through Sumsub, so there is an accountable person behind the key. There is no separate age gate on this tier; age is gated by content, and only Roleplay serves adult content. See Age and identity.

Two methods, pick one

You prove control with either a DNS TXT record or a .merki challenge file served from the domain. Either one is sufficient. You do not need both.

  • DNS TXT record. Publish a TXT record containing the challenge value at the domain.
  • .merki challenge file. Serve a file at the well-known .merki path on the domain, with the challenge value as its contents.

Challenge life

  • A challenge is valid for at most 7 days.
  • While a challenge is active, the Merki API re-checks it every 30 to 60 seconds.
  • Renew the challenge before 7 days pass, or access is suspended and the key is revoked.
  • Renew early: DNS propagation can take minutes to hours, so renew at day 6 at the latest. A challenge that lapses during propagation is treated as expired. There is no grace window after the 7 day maximum.

Domain rules

Two rules apply, and both surprise people:

  • No wildcards. A domain pattern such as *.example.com is not accepted. Name the exact hostname.
  • No subdomain propagation. Verifying a domain does not verify its subdomains. Verifying example.com does not grant api.example.com or staging.example.com. Each hostname is verified on its own, with its own challenge.

Steps

  1. Choose a method: DNS TXT record, or .merki file.
  2. Publish the challenge value for the exact hostname you want to use.
  3. Wait for the next check, within 30 to 60 seconds.
  4. On success, the hostname is verified and the Cybersecurity key can target it.
  5. Renew before the 7 day maximum (day 6 recommended). Repeat for every additional hostname.

If a check fails

A check fails when the TXT record is removed, the .merki file stops resolving, or the challenge passes its 7 day maximum. When that happens, access to the affected hostname is suspended and the key is revoked. See Revocation triggers.