Wizard Fortress

Placement order

Verify the domain without mixing identity systems.

Two different OpenAI products use TXT records. Do them in this order. Do not paste a Builder Profile challenge into the Admin Console, or the reverse.

  1. Leave apex and notebook alone. @ is Tailscale. notebook is an existing tunnel.
  2. Pages on www only. Custom domain www.wizard-fortress.com. Cloudflare creates the proxied CNAME.
  3. Builder Profile. Verify www.wizard-fortress.com only. TXT name www, DNS only.
  4. Skip tenant SSO on this zone unless you really want work-email identity sharing a zone with Tailscale.
  5. Do not touch mail records. SPF is already -all. Empty DKIM stays empty.

TXT placement

PurposeNameTypeProxy
Pages public gatewwwCNAME to PagesProxied
OpenAI Builder challengewwwTXTDNS only
Tailscale apex@CNAME to ts.netDNS only — do not edit
Notebook tunnelnotebookCNAME to cfargotunnelProxied — do not edit

Parent domain does not verify subdomains. Verify www as www.

Snapshot already in

2026-09-25 phone grid: 5 records. www is the empty slot. That is the gate.