Company Claims & Domain Verification Policy
How company profiles are claimed and verified, when the verified badge is granted or revoked, and how disputes are resolved.
_Last updated: 3 August 2026_
This policy governs how a company profile on TrustRating is claimed, how we verify that the claimant genuinely represents the company, when a verified badge is granted and removed, and how disputes over control of a profile are resolved. It is part of the Business Terms of Service. The purpose of the process is to guarantee one thing to everyone who reads a reply, a company post or a badge on this platform: the account speaking for a company actually speaks for that company.
1. Why claims are verified
A claimed profile can reply publicly to reviews, publish company news, correct company details, invite customers and display a verified badge. Every one of those abilities would be dangerous in the wrong hands — an impostor could "apologise" on behalf of a competitor, harvest customer goodwill, or gate reviews. So claims are never granted on say-so: they require evidence of control that only the real company has, and they can be revoked when that evidence turns out to be false or stale. Verification also protects the claimant: once your company's profile is verifiably yours, nobody can talk consumers, partners or moderators into believing otherwise, and every reply published in your name actually came from you — which is worth more than the badge itself.
2. Who may claim
A company profile may be claimed by an owner, officer, employee or engaged agent (for example a marketing agency) authorised by the company to represent it publicly. Authorisation is the substance, the job title is not: a junior employee asked by the owner to handle the profile is authorised; a senior ex-employee with a grudge and an old login is not. Agencies must be able to show their mandate on request and must hand over control when the client asks. One company may have one claim; additional colleagues join through team seats under the Business Terms of Service rather than through competing claims, so the question "who speaks for this company" always has exactly one answer with a documented team behind it. Claiming a company you do not represent — including "reserving" profiles, claiming a competitor, or claiming to suppress criticism — is prohibited, void, and sanctioned under the Acceptable Use Policy.
3. What we verify and how
Verification centres on the company's domain — the strongest publicly checkable proxy for corporate control. Accepted evidence, depending on the case: Domain mailbox verification — receiving and confirming a verification email at an address on the company's own domain (role addresses such as admin@ or info@ carry more weight than personal ones). DNS record verification — publishing a unique token we generate as a DNS record on the company domain; this is the standard route for the verified badge because only a domain administrator can do it. Supplementary evidence — where a company has no usable domain (a local business on a marketplace, for example) or ambiguous branding, we may ask for corroborating evidence such as a listing in an official companies register, documents showing the claimant's role, or verification through an official company channel. We ask for the minimum necessary, use it only for the claim decision, and handle it under the Privacy Policy.
Verification emails and links are tokenised and expire; a claim that is not completed within its window lapses automatically (you will be reminded before it does) and can simply be restarted. We may re-verify at intervals or when circumstances change (Section 8). Evidence submitted for verification is retained only as long as the claim's validity may need defending, is never published, and is handled under the Privacy Policy — reviewers and visitors see the outcome (the badge), never the file.
4. The two verification routes, step by step
The mailbox route. Choose an address on the company's domain (prefer a role address — admin@, office@, info@ — over a personal one); we send a verification email containing a tokenised confirmation link; open it from that mailbox and confirm. The link is single-use and expires; if it lapses, request a fresh one from the claim screen. What this proves: someone controlling a mailbox on the company's domain approved the claim. What can go wrong: aggressive spam filtering (check the spam folder and whitelist our sending domain), catch-all mailboxes forwarding to people who ignore them, and free-mail addresses (gmail and the like prove nothing about a company and are not accepted for domain verification).
The DNS route. The claim screen generates a unique verification token; you (or whoever manages your domain) add it as a DNS record on the company domain; you click verify, and we check the public DNS for the token. What this proves: control of the domain itself — the strongest evidence available, which is why this route anchors the verified badge. What can go wrong: DNS propagation delay (give it time and retry — records can take a while to become visible), adding the record to the wrong zone (a subdomain instead of the root, or a parked duplicate of the domain), and copy-paste errors in the token. The record can be removed after verification succeeds, though leaving it in place makes future re-verification instant.
If neither route is available to you — the domain is managed by an unreachable third party, the business genuinely has no domain — do not guess: contact us describing the situation, and we will find the supplementary-evidence path that fits (Section 3).
5. The process and timelines
Start a claim from the company profile ("Claim this company") or from the business site. Steps: create or sign in to your business account (accounts created mid-claim must be activated by setting a password through the emailed link); complete the verification step above; where manual review is needed — supplementary evidence, conflicting claims, high-risk categories — our team reviews the file, typically within a few business days. High-risk categories are those where impersonation does the most damage — financial services, healthcare, legal services and the like — and the additional scrutiny there is not suspicion of you personally, it is the cost of the badge meaning something in the categories where trust is most exploitable. You are notified of the outcome by email and in the panel. An approved claim unlocks the business dashboard; a rejected claim states the reason and can be re-submitted with better evidence. During a pending claim the profile remains public and reviewable; pending status confers no rights over the profile.
6. Effect of an approved claim
An approved claim links your business identity to the company and unlocks: public replies to reviews; profile management (correcting company details, logo, description, categories); review invitations under the fairness rules of the Business Terms of Service; access to plans, widgets, API and the other paid tools under their respective terms; and — where domain verification specifically was completed — the verified badge on the profile. The badge asserts control of the domain at verification time, nothing more: it is not an endorsement, does not affect the TrustScore, and may not be advertised as a quality mark (see the brand rules in the Content Integrity, Scoring & IP Policy).
7. Competing and disputed claims
Where two parties claim the same company, evidence of domain control prevails; where both show domain control (a franchise dispute, a divorcing partnership, an agency refusing to hand back an account), we may freeze management features while the parties resolve who is authorised, and we follow documents with legal force — court orders, register extracts, signed authorisations — over assertions. During a freeze the profile stays public and reviewable and existing replies stay visible; what pauses is the ability to act in the company's name, because acting in a disputed name is precisely the harm to prevent. We are not an arbitrator of corporate disputes and will not pick a side on the merits — we verify authority, and the party with demonstrated current authority gets the keys. Where a company changes ownership, the new owner may claim with fresh evidence; the previous claim is released. Hostile takeovers of profiles through stale mailboxes or expired domains are reversed when discovered, and deliberately fraudulent claims lead to account termination and, where warranted, referral to law enforcement.
8. Re-verification, lapse and revocation
We may re-check domain control periodically, when a domain expires or changes hands, when a claim shows signs of abandonment, or when credible reports question a claim's validity. If re-verification fails or is ignored after reasonable reminders, the verified badge is removed and management features may be suspended until verification is repeated — the profile itself and its reviews are unaffected. We revoke claims immediately where they were obtained by misrepresentation or are used to violate the Business Terms of Service (for example gating or manipulation), applying the enforcement and appeal framework of the Moderation & Appeals Policy.
9. Releasing a claim
A company may release its claim at any time from the panel, and should do so when it stops being authorised (an agency losing the client, an employee leaving where no successor exists — though transferring to a colleague via team seats is the better route, since it preserves the claim's history, the badge and every configuration instead of starting over). Releasing a claim ends management access and the badge; it does not delete the profile or its genuine reviews, which remain part of the public record exactly as for any unclaimed company, per Section 12 of the Business Terms of Service.
10. Unclaimed companies and removal requests
Companies appear in the directory because consumers deserve a place to review them — consent of the company is not required for the existence of a truthful profile, and "delete our profile" is not a service we sell. What an unclaimed company can do: claim the profile (free) and use every free tool above; report factual errors in company data via the contact page, which we correct; report rule-breaking reviews through the same route with evidence. Profiles are removed or merged only where the company verifiably no longer exists, was created in error or as a duplicate, or where the law requires it.
Duplicates and mergers deserve a word, because they affect scores. Where the same company exists twice (a typo variant, a rebrand, a "www" and bare-domain pair), we merge the profiles and their review histories so the score reflects the whole record; where two genuinely different companies share a name, we keep them separate and disambiguate the profiles. A rebrand does not reset a reputation: the reviews follow the business, not the label — asking for a "fresh profile" to escape history is a removal request in costume, and Section 10's rules apply to it.
11. Security of claimed accounts
A claimed profile is an attractive target. Protect it: use strong unique passwords, remove departed team members immediately, keep the verified domain's DNS and mailboxes secure, and tell us at once via the contact page if you suspect account compromise — we can freeze management features while you regain control. Actions taken through your accounts are attributed to your company under the Business Terms of Service until you notify us of compromise.
Two attack patterns are worth knowing because they start outside our platform. Expired-domain takeover: if your company lets its domain lapse, whoever registers it next controls "your" mailboxes and DNS — and could pass our verification honestly. Renew domains before claims depend on them, and tell us if a domain you verified with changes hands. Phishing: we will never ask for your password by email, and verification emails from us link only to our own domains; a message pressuring you to "re-verify" through an unfamiliar link is an attempt to steal the profile — forward it to us and delete it.
12. Changes
We update this policy as verification techniques and abuse patterns evolve; material changes are announced as described in the Terms of Service. The version in force is always identified by the date above.