Connect and verify a custom domain
Understand the DNS, hosting and HTTPS requirements instead of expecting DNS alone to activate a domain.
2 min read
Screenshots show the real application in an isolated demo environment with fictional example data. Setup notices and controls may differ by environment, plan and role. Click an image to view it full-size, and always use the values generated in your own workspace.
A domain needs three kinds of readiness
Domain ownership, routing to the supported hosting target and a working HTTPS application response are separate checks. Passing a TXT check alone does not install a certificate or configure the web server.
The custom-domain feature must be permitted by your workspace plan. If the stable hosting target is not configured, activation cannot complete until the hosting administrator supplies it.
Add and verify the DNS records
- 1Open Branding & domains and add the hostname you control.
- 2Copy the exact ownership TXT name/value shown for that domain. Add it at the authoritative DNS provider.
- 3Copy the shown CNAME target for that hostname. Do not invent a hosting target or point it at a temporary preview URL.
- 4Allow DNS changes to propagate, then run Verify DNS. Compare the full record name and value if the check fails.
- 5Complete the hosting/HTTPS readiness steps and use activation only when the application challenge succeeds.
Common DNS mistakes
- A provider may automatically append your domain to a record name; avoid duplicating it.
- Existing conflicting records at the same hostname can prevent correct routing.
- A root/apex domain may need a DNS-provider-specific setup rather than a normal subdomain CNAME.
- A CDN/proxy can alter the response or certificate; verify the actual public HTTPS result.
Workspace membership still applies
A branded domain does not remove account security or workspace membership checks. A signed-in person who is not a member of that domain’s workspace can receive an access denial. Keep an approved main-domain login path available during testing and never switch a live domain before HTTPS and routes are verified.