See all checks
Docs

Verify site ownership

Updated September 2026

Relvato only runs checks against a site whose owner has proven they control it. That is what stops anyone from pointing a monitoring tool — one that loads pages, logs in, and can place test orders — at a website they have nothing to do with. You prove it once, in one of two ways, and checks start running. This page covers both, how each proof is re-checked, and what to do if checks pause because proof lapsed.

What ownership gates

Until a site is proven, Relvato records what it hears about — a plugin event, a deploy — but runs nothing. No page loads, no logins, no test orders. The site page shows a banner naming the missing proof, and the run buttons stay disabled with the reason.

Proof is per site, and a site is one address. Two accounts can both add the same site, and each has to prove ownership on its own.

Option A — connect the WordPress plugin

Install the Relvato plugin, then paste the site's connect token into its settings page. The token is on your site's Settings → Connection tab in Relvato. Only someone who can install a plugin and open that tab can do this, which is what makes it proof.

This is the option to choose for a WordPress site: it also unlocks the checks that need the plugin, such as checkout, login, payment methods and the admin-roster security check.

Once connected, the plugin keeps proof alive by itself. It reports in every few hours, sends an event whenever something changes on the site, and answers Relvato's periodic check. Any one of those counts as a sign of life — which matters on sites whose firewall blocks incoming requests, because the plugin reaching out still counts. If the plugin can't answer at all, see Fix “Plugin not responding”.

Option B — verify the domain

Any site can be proven with a domain record instead, and it is the only option for sites without a WordPress integration. Open Settings → Connection and pick one of two methods. Relvato shows the code for your site; add it exactly as shown.

DNS TXT record: add a TXT record at the host _relvato-challenge — so the full name is _relvato-challenge.yourdomain.com — with your code as the value. Relvato also accepts the record at the domain root, so the plain @ host works if the sub-name is awkward at your DNS provider. DNS changes can take a few minutes to propagate.

Homepage meta tag: copy the meta tag Relvato shows, named relvato-site-verification and carrying your code, and paste it into the head of your homepage. Relvato reads the homepage and looks for that exact code, so a catch-all or “coming soon” page can't pass by accident.

Then press Verify. A verified domain unlocks every check that doesn't need the plugin: uptime, SSL, visual and structure checks, page speed, broken links and the rest.

Subdomains and www

Each address proves itself. Verifying example.com does not cover shop.example.com — add the record for the exact host you monitor, for example _relvato-challenge.shop.example.com. Since you control the domain's DNS, that is usually a second record in the same place.

www is the exception: www.example.com and example.com count as the same site, so one record covers both.

Sites that share a domain also share Relvato's pacing: it runs one check at a time across them, and when a firewall blocks one it holds the others back instead of walking into the same wall. See Allowlist Relvato behind a firewall.

Proof doesn't last forever

Domains change hands and DNS records get edited, so Relvato re-checks a verified domain about every 30 days. If the record is gone, checks pause until you verify again.

Plugin proof lapses two ways. If Relvato sees no sign of the plugin for 45 days, proof expires — a live plugin reports in within hours, so silence that long means it is genuinely gone. And because a WordPress site's plugin is connected to exactly one Relvato account, reconnecting it to a different account revokes the previous account's proof immediately. That is what happens at an agency handover: the new account's checks start, the old account's stop.

You are warned first. Relvato emails 10 days and 2 days before plugin proof expires, and immediately if a reconnection revokes it, with the same notice in the app's alerts. Keeping a verified domain alongside the plugin is the belt-and-braces option: the two proofs are independent, so one lapsing doesn't pause your checks.

If checks are paused

The banner on the site page names the reason and links to both remedies: reconnect the plugin with this site's connect token, or verify the domain. Either one restores checks on the next run.

Nothing else is affected while checks are paused. Journeys, settings, visual baselines, run history and alert preferences stay exactly as they were, and scheduled checks resume once proof is back.

The two proofs at a glance

ProofHow you set it upHow Relvato re-checks itWhat makes it lapse
WordPress pluginPaste the site's connect token into the pluginThe plugin reports in every few hours, on every change, and answers Relvato's check45 days with no sign of the plugin, or reconnecting it to another Relvato account
Domain recordA TXT record at _relvato-challenge, or a meta tag on the homepageRe-checked about every 30 daysThe record or tag is removed or changed

Ownership FAQ

Can two accounts monitor the same site?

Yes — an agency and a site owner can both watch it, each proving ownership separately. The plugin, though, belongs to whichever account it is connected to: reconnecting it to a new account revokes the previous account's plugin proof at once. Domain proof is independent, so an account that also verified the domain keeps its plugin-free checks running.

Does verifying example.com cover shop.example.com?

No. Each host proves itself, so add the record for the exact address you monitor. The one exception is www: www.example.com and example.com are treated as the same site.

A firewall blocks Relvato from reaching my site. Will plugin proof lapse?

No. The plugin reaches out to Relvato — every few hours, and whenever something changes on the site — so proof stays alive even when incoming requests are blocked. Allowlisting Relvato is still worth doing so the checks themselves can run.

What happens to my data while checks are paused?

Nothing is deleted. Journeys, settings, visual baselines, run history and alert preferences are untouched; checks simply don't run until ownership is proven again, then resume on schedule.

Do I need the plugin at all?

Not for public-page monitoring: a verified domain covers uptime, SSL, visual and structure checks, page speed, broken links and more. The plugin unlocks the checks that need to see inside WordPress or WooCommerce — checkout, login, payment methods, background jobs, file and admin-account integrity.

I removed the plugin but want to keep public-page checks. What should I do?

Verify the domain before plugin proof expires and nothing pauses. If it already expired, verify the domain and checks resume on the next run.

Related reading
Docs

Prove it once, then stop watching manually

Connect the plugin or add one DNS record, and Relvato checks your real journeys around the clock.