# Invalid DNS record

**URL:** <https://community.letsencrypt.org/t/invalid-dns-record/175768>\
**Category:** Client dev\
**Created:** [April 13, 2022, 4:05pm UTC](https://community.letsencrypt.org/t/invalid-dns-record/175768 "2022-04-13T16:05:04Z")\
**Posts on this page:** 1\
**Showing post:** 12

<div class="post-metadata">

**Author:** ![\_az](https://avatars.discourse-cdn.com/v4/letter/_/22d042/32.png) [@\_az](https://community.letsencrypt.org/u/_az)\
**Post date:** [April 13, 2022, 11:03pm UTC](https://community.letsencrypt.org/t/invalid-dns-record/175768/12 "2022-04-13T23:03:23Z")

</div>

> [@franciscofabian](#):
>
> ```nohighlight
> detail: 'Incorrect TXT record "ph-fuQOgWCC9VeqXIVYnor-vfx1WzIcxG3jVNK3191o" found at _acme-challenge.auth.runningplanandtrack.com',
> status: 403
> },
> url: 'https://acme-staging-v02.api.letsencrypt.org/acme/chall-v3/2177871348/7gJ0fw',
> token: 'ph-fuQOgWCC9VeqXIVYnor-vfx1WzIcxG3jVNK3191o',
> 
> ```

I think it will be helpful if you read over [the DNS challenge part of RFC8555](https://datatracker.ietf.org/doc/html/rfc8555#section-8.4) again carefully.

`token` does not go directly into the DNS TXT record.

You take the `token` from the challenge, and then:

1. [Derive the key authorization](https://datatracker.ietf.org/doc/html/rfc8555#section-8.1) by concatenating it to your JWK thumbprint
2. Calculate the SHA-256 digest of the value from (1)
3. Encode the value from (2) using `base64url`

... then put that in the DNS TXT record.

---

_[View the full topic](https://community.letsencrypt.org/t/invalid-dns-record/175768)._
