Skip to contentSkip to Content
ReferenceCustom Domains & DNS Setup

Custom Domains & DNS Setup

Availability. Custom domains are part of the Professional, Scale and Enterprise plans and are being rolled out agency by agency. Until the Domains card appears under /dashboard/settings in your portal, the feature is not yet switched on for your platform — ask in the Request your plan thread (/dashboard/custom-plan) and we will tell you where you are in the rollout. Nothing on this page changes what your clients see until that card is live for you.

What it covers

SurfaceWithout a custom domainWith one
Client portal addressapp.agentlane.agencyA subdomain you own, e.g. portal.your-agency.com, with its own HTTPS certificate
Links in client email (invites, password resets, notifications)Point at the platform addressPoint at your portal address once it is live
Sender of client emailno-reply@agentlane.agency, with your agency as the display nameno-reply@mail.your-agency.com (or a local part you choose), once your sender domain is verified
Logo and colours on the client portal and in client emailYours already — see Partner Dashboard → SettingsUnchanged

Two things stay AgentLane’s, and we say so before launch: the single-sign-on step, where a client signs in through Keycloak, still passes through an AgentLane-hosted page; and the API hostname a browser talks to is still ours. Email to your own team (billing, seat and plan notices, team invites) also keeps the AgentLane sender — you are our customer, your clients are yours.

Limits in this version: one portal address and one sender domain per agency; the portal address must be a subdomain (a bare your-agency.com cannot carry the CNAME record this uses).

Who can do this

Only an agency admin can add, verify or remove a domain. Team members with the moderator permission see the card read-only. The Domains card also tells you if your plan does not include custom domains; the API refuses the change in the same case, so a plan change is the only way in.

The portal address, step by step

Enter the address

Under Settings → Domains → Portal address, type the subdomain you want, e.g. portal.your-agency.com, and press Add portal address. The card now shows the two DNS records the address needs:

TypeNameValue
CNAMEportal.your-agency.comthe platform target the card shows
TXT_agentlane-verify.portal.your-agency.coma one-off token that proves you control the name

Both are required. The CNAME alone would let anyone point a name at us; the TXT ties the name to your agency.

Get the records into your zone

Pick one of the two tabs under Set up the DNS records:

  • Configure automatically — choose Cloudflare or Amazon Route 53, paste a credential, press Preview changes, read the exact create/update/no-op per record, then Apply. Details and the credential scopes are in the next section.
  • Do it yourself — copy or download the records as a plain list, a BIND zone-file snippet, a Cloudflare curl script, or a Route 53 change batch with its aws route53 command, and apply them in your provider’s control panel or CLI.

Wait for verification

We check the records every few minutes (press Check now to run a check immediately). Status moves from Waiting for DNS to Issuing certificate to Live. Issuing the certificate usually takes a minute or two after DNS verifies. If nothing verifies within 72 hours the address is marked Failed; Retry opens a fresh window.

Done

Once Live, your clients can sign in at your address and their emails link there. We keep re-checking the two records daily; if both disappear, the address is taken down again so nobody can hijack a dangling name. Remove takes it down on purpose; the same address can be re-added after an hour.

Automatic setup: what we do with your credential

The credential you paste is used for that one request and then discarded. It is not stored, not logged and not shown back to you; both Preview and Apply send it again rather than keep it between the two calls. If you prefer, revoke the token at your provider as soon as the address shows Live.

What the automation will and will not do:

  • It writes only the two records above, under your own hostname, in the zone that holds it.
  • It never deletes anything. If another record is already in the way (for example an A record at the same name), the preview stops with a message telling you what to remove by hand.
  • It only ever talks to the provider’s official API host.
  • On Cloudflare the CNAME is written with the proxy (orange cloud) off. This is required: a proxied CNAME answers with Cloudflare’s own addresses, so the ownership check and the certificate issuance would both fail.

Cloudflare

Create an API token (My Profile → API Tokens → Edit zone DNS template) limited to the zone that holds your hostname. Never use the Global API Key. The automation looks the zone up by name.

Amazon Route 53

Create an IAM access key allowed route53:ListHostedZonesByName, route53:GetHostedZone, route53:ListResourceRecordSets and route53:ChangeResourceRecordSets, ideally restricted to the one hosted zone. If the key cannot list zones, paste the hosted zone id and the lookup is skipped. Temporary credentials (with a session token) work too. Writes are UPSERTs of the exact name and type.

Namecheap, GoDaddy and everyone else

Not connected, on purpose:

  • Namecheap’s API needs every caller IP allow-listed on your account and an account-level key that reaches all your domains — far more access than two records justify.
  • GoDaddy’s DNS API is only available to accounts with 10+ domains or an active Discount Domain Club plan, so most agencies cannot create a key at all.

Use the Do it yourself tab for these: the plain record list fits any control panel.

The sender domain

Under Settings → Domains → Sender domain, add a domain or subdomain you control (a subdomain such as mail.your-agency.com keeps your own mailbox’s SPF record untouched) and choose the local part of the From address. The card lists the DNS records our email provider needs (DKIM, SPF and a return-path record), with a per-record status. Until the domain verifies, client email keeps the platform sender with your agency as the display name; once verified it is sent as Your Agency <no-reply@mail.your-agency.com>.

The automatic DNS setup covers the portal address only; sender-domain records are applied by hand from the table in the card.

Troubleshooting

SymptomLikely cause
“That hostname belongs to the platform”You entered an agentlane.agency name. Use a subdomain of a domain you own.
“Use a subdomain such as portal.your-agency.com”A bare domain cannot be a CNAME in this version.
“CNAME points at …, expected …”The record exists but targets something else. Update its value.
“TXT … has a different value”A stale token from an earlier attempt. Replace it with the one the card shows now, or use Configure automatically, which updates it.
Cloudflare: verified DNS never becomes LiveThe CNAME is proxied. Turn the orange cloud off for that record.
“already has a … record” during previewAnother record sits at the same name. Remove or rename it — we will not delete it for you.
Status stuck on Issuing certificateUsually under two minutes. If it lasts longer, press Check now; if it persists, ask us.

Custom Domains & DNS Setup — AgentLane