Custom Domains
Custom Domains
Overview
Custom domains allow you to serve your Tailglow pages and ingest data through your own branded domain instead of the default Tailglow URLs. For example, instead of using pages.tailglow.io/your-page, you can use analytics.yourdomain.com/your-page.
You can use custom domains for:
- Custom Pages: Serve your public status pages and dashboards from your own domain.
- Custom Ingest: Send analytics data through your own domain for first-party tracking.
Custom domains are available on the Enterprise plan. A team can have up to 10 custom domains in total across Ingest and Page domains.
Each hostname has one traffic purpose. You can configure several Ingest domains and several Page domains for the same team.
Adding a Custom Domain
To add a custom domain to your team:
- Navigate to your Team Settings page.
- Click the “Domains” tab.
- In either the Ingest domains or Page domains table, click the add button.
- Enter your custom domain (e.g.,
analytics.yourdomain.com). - Click Add Ingest Domain or Add Page Domain, matching the table you chose.
The table you add the hostname from determines its purpose. After adding it, verify domain ownership and configure routing through a two-step DNS process.
DNS Verification
Setting up a custom domain is a two-step process: first verify ownership, then configure traffic routing.
Step 1: Ownership Verification (TXT Record)
Before your domain can be used, you must verify that you own it by adding a TXT record:
- Go to your DNS provider’s management console.
- Add a TXT record:
- Name/Host: The full name shown in Tailglow. For
analytics.yourdomain.com, it is_tailglow-verify.analytics.yourdomain.com. - Value: The verification token shown in your domain settings
- Name/Host: The full name shown in Tailglow. For
- Wait for DNS propagation. Timing depends on your provider and the record’s TTL.
- Click Check DNS in the drawer, or Check Now beside the domain status, to check the TXT record.
Step 2: Routing Setup
Once ownership is verified, configure routing so traffic reaches Tailglow:
CNAME Record
A domain that serves traffic has to be a subdomain such as analytics.yourdomain.com. A root domain
like yourdomain.com cannot hold a CNAME, so it can be verified but not used for ingest or pages.
- Go to your DNS provider’s management console.
- Add a CNAME record:
- Name/Host: The name shown in your domain settings. Your provider may display the same host relative to the DNS zone, such as
analytics. - Value/Target: The CNAME target shown in your domain settings.
- Name/Host: The name shown in your domain settings. Your provider may display the same host relative to the DNS zone, such as
- Wait for DNS propagation.
- Click Check DNS to check the routing configuration.
If your DNS provider offers proxying, use DNS only while setting up the domain. The hostname must point directly to the target shown in Tailglow so its certificate can be provisioned and renewed. A proxied record can leave certificate provisioning stuck or failed.
Ongoing Checks
Tailglow re-checks every record hourly, not just during setup. Both records have to keep resolving for the domain to keep working.
If a record stops resolving, the domain keeps serving while you fix it:
- Ownership (TXT): 24 hours
- Routing (CNAME): 7 days
Put the record back within that window and nothing is interrupted. Past it, Tailglow stops serving the domain until the record resolves again. Adding it back and clicking Check DNS restores service on the next successful check.
A check that cannot reach your DNS provider at all does not count against these windows. Only a lookup that completes and finds the record missing or pointing somewhere else starts the clock.
SSL Certificate Provisioning
Once your domain is verified and routing is configured, Tailglow requests an SSL certificate. The certificate status can report:
- None: No certificate has been requested yet (pre-verification).
- Provisioning: Certificate provisioning is in progress after routing verification.
- Active: The certificate is provisioned and your domain is ready for HTTPS traffic.
- Failed: Certificate provisioning failed. Check the error message in your domain settings for details.
Certificate provisioning often takes a few minutes, but it can take longer. Certificates renew automatically while the required DNS records continue to point directly to Tailglow.
Traffic Purpose
The table used to create a domain assigns its traffic purpose, and one hostname can serve only one purpose at a time. In Domain Details, the Used for chip shows the active purpose.
An Ingest domain can be used as a first-party endpoint for sending analytics data. It keeps the ingest hostname under your domain and may reduce blocking by tools that specifically target known third-party analytics hosts.
A Page domain serves every public page owned by the team. Each Page’s permanent generated slug works on the Tailglow hostname and every custom hostname. A Page can also be given a readable path on one specific domain, such as status.yourcompany.com/weekly-health, and another Page domain can choose a different path for the same Page.
Set that path to / to serve the Page at the hostname’s root, so status.yourcompany.com opens it directly. Only one Page can hold a given path on a domain, including the root. Paths are a single segment: /weekly-health is valid, /team/weekly-health is not.
Pages served from your own hostname remove Tailglow branding and use your team logo as the browser tab icon (favicon). You can update the logo in your team settings.
To remove the active purpose without deleting the hostname, open Domain Details and click Stop using for Ingest or Stop using for Pages. Tailglow explains what the change affects and asks you to hold the confirm button, because the teardown cannot be cancelled once it starts. The change can take time to finish.
Troubleshooting
DNS Verification Failed
If verification fails:
- Check DNS propagation: Use a tool like whatsmydns.net to verify your records have propagated.
- Verify record values: Ensure the CNAME target exactly matches what Tailglow shows.
- Check for conflicting records: Remove any conflicting A or AAAA records if using CNAME.
- Wait and retry: Propagation time depends on your DNS provider and the record’s TTL.
Certificate Provisioning Stuck
If certificate status shows “provisioning” for more than 24 hours:
- Verify DNS is correct: Certificate provisioning requires DNS to be properly configured.
- Check for CAA records: If you have CAA records, ensure they allow certificate issuance.
- Contact support: If issues persist, reach out to support@tailglow.io.
Domain Shows “Failed”
If certificate provisioning failed:
- Check the error message in your domain settings.
- Verify DNS configuration is still correct.
- Try removing and re-adding the domain.
Removing a Custom Domain
To remove a custom domain:
- Navigate to Team Settings > Domains.
- Click the edit button for the domain you want to remove.
- Hold the trash button labeled Hold to remove domain until the action confirms.
Removal can take time, and the row remains visible with a pending state until it finishes. Public Pages stop using the hostname as soon as removal begins, while other services may take longer. Do not rely on the hostname after starting removal. Adding it again later requires new ownership verification.
Best Practices
- Use dedicated subdomains: Hostnames such as
ingest.yourdomain.comandstatus.yourdomain.commake each traffic purpose explicit. Page domains require a subdomain. - Keep DNS records: Don’t remove DNS records after verification. They are re-checked hourly, and removing one eventually takes the domain out of service. See Ongoing Checks.
- Monitor certificate status: Check your domain status periodically to ensure certificates remain active.
- Plan for propagation: When adding new domains, allow time for DNS propagation before relying on them in production.