# ACME DNS validation - get 'incorrect TXT' error with the correct value

**URL:** <https://community.letsencrypt.org/t/acme-dns-validation-get-incorrect-txt-error-with-the-correct-value/179850>\
**Category:** Help\
**Created:** [June 21, 2022, 1:59pm UTC](https://community.letsencrypt.org/t/acme-dns-validation-get-incorrect-txt-error-with-the-correct-value/179850 "2022-06-21T13:59:19Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![eilon](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/eilon/32/62397_2.png) [@eilon](https://community.letsencrypt.org/u/eilon)\
**Post date:** [June 21, 2022, 1:59pm UTC](https://community.letsencrypt.org/t/acme-dns-validation-get-incorrect-txt-error-with-the-correct-value/179850/1 "2022-06-21T13:59:19Z")

</div>

My domain is: [acme-eilon-123.incaptest.co](http://acme-eilon-123.incaptest.co)

I ran this command:

[https://acme-staging-v02.api.letsencrypt.org/acme/authz-v3/2772601574](https://acme-staging-v02.api.letsencrypt.org/acme/authz-v3/2772601574)

It produced this output:

{  
"identifier": {  
"type": "dns",  
"value": "[acme-eilon-123.incaptest.co](http://acme-eilon-123.incaptest.co)"  
},  
"status": "invalid",  
"expires": "2022-06-28T13:43:09Z",  
"challenges": [  
{  
"type": "dns-01",  
"status": "invalid",  
"error": {  
"type": "urn:ietf:params:acme:error:unauthorized",  
"detail": "Incorrect TXT record "DM-FfJAjetBnS1a9IX-wmtxOmjhjceN1SMTg7nZtmq0" found at \_acme-challenge.acme-eilon-123.incaptest.co",  
"status": 403  
},  
"url": "[https://acme-staging-v02.api.letsencrypt.org/acme/chall-v3/2772601574/RFgHdA](https://acme-staging-v02.api.letsencrypt.org/acme/chall-v3/2772601574/RFgHdA)",  
"token": "DM-FfJAjetBnS1a9IX-wmtxOmjhjceN1SMTg7nZtmq0",  
"validated": "2022-06-21T13:48:52Z"  
}  
]  
}

Note that the TXT record in the error is the same as the token, what I am doing wrong?

---

<div class="post-metadata">

**Author:** ![mcpherrinm](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/mcpherrinm/32/59604_2.png) [@mcpherrinm](https://community.letsencrypt.org/u/mcpherrinm)\
**Post date:** [June 21, 2022, 2:09pm UTC](https://community.letsencrypt.org/t/acme-dns-validation-get-incorrect-txt-error-with-the-correct-value/179850/2 "2022-06-21T14:09:41Z")

</div>

The value of the TXT record isn't just the token: it's the base64url-encoded sha256 of a key authorization.

RFC 8555 documents how to construct this in sections 8.1 (for the key authorization) and 8.4, for the DNS challenge type:

[rfc8555 section 8.1](https://datatracker.ietf.org/doc/html/rfc8555#section-8.1)

[rfc8555 section 8.4](https://datatracker.ietf.org/doc/html/rfc8555#section-8.4)

---

<div class="post-metadata">

**Author:** ![eilon](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/eilon/32/62397_2.png) [@eilon](https://community.letsencrypt.org/u/eilon)\
**Post date:** [June 21, 2022, 2:29pm UTC](https://community.letsencrypt.org/t/acme-dns-validation-get-incorrect-txt-error-with-the-correct-value/179850/3 "2022-06-21T14:29:49Z")

</div>

Just went over it now,

Thank you

---

<div class="post-metadata">

**Author:** ![mcpherrinm](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/mcpherrinm/32/59604_2.png) [@mcpherrinm](https://community.letsencrypt.org/u/mcpherrinm)\
**Post date:** [June 21, 2022, 2:49pm UTC](https://community.letsencrypt.org/t/acme-dns-validation-get-incorrect-txt-error-with-the-correct-value/179850/4 "2022-06-21T14:49:08Z")

</div>

It’s worded very formally, please feel free to ask any questions if there’s anything unclear or you’re having trouble with still.

---

<div class="post-metadata">

**Author:** ![system](https://global.discourse-cdn.com/letsencrypt/original/3X/c/a/ca6c06ea1ea201324bba7048c6841ce60236468d.png) [@system](https://community.letsencrypt.org/u/system)\
**Post date:** [July 21, 2022, 2:49pm UTC](https://community.letsencrypt.org/t/acme-dns-validation-get-incorrect-txt-error-with-the-correct-value/179850/5 "2022-07-21T14:49:36Z")

</div>

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.
