Custom Domains & DNS Setup
Availability. Custom domains are part of the Professional, Scale and Enterprise plans and
are being rolled out agency by agency. Until the Domains card appears under
/dashboard/settings in your portal, the feature is not yet switched on for your platform — ask
in the Request your plan thread (/dashboard/custom-plan) and we will tell you where you are
in the rollout. Nothing on this page changes what your clients see until that card is live for you.
What it covers
| Surface | Without a custom domain | With one |
|---|---|---|
| Client portal address | app.agentlane.agency | A subdomain you own, e.g. portal.your-agency.com, with its own HTTPS certificate |
| Links in client email (invites, password resets, notifications) | Point at the platform address | Point at your portal address once it is live |
| Sender of client email | no-reply@agentlane.agency, with your agency as the display name | no-reply@mail.your-agency.com (or a local part you choose), once your sender domain is verified |
| Logo and colours on the client portal and in client email | Yours already — see Partner Dashboard → Settings | Unchanged |
Two things stay AgentLane’s, and we say so before launch: the single-sign-on step, where a client signs in through Keycloak, still passes through an AgentLane-hosted page; and the API hostname a browser talks to is still ours. Email to your own team (billing, seat and plan notices, team invites) also keeps the AgentLane sender — you are our customer, your clients are yours.
Limits in this version: one portal address and one sender domain per agency; the portal
address must be a subdomain (a bare your-agency.com cannot carry the CNAME record this uses).
Who can do this
Only an agency admin can add, verify or remove a domain. Team members with the moderator
permission see the card read-only. The Domains card also tells you if your plan does not include
custom domains; the API refuses the change in the same case, so a plan change is the only way in.
The portal address, step by step
Enter the address
Under Settings → Domains → Portal address, type the subdomain you want, e.g.
portal.your-agency.com, and press Add portal address. The card now shows the two DNS records
the address needs:
| Type | Name | Value |
|---|---|---|
CNAME | portal.your-agency.com | the platform target the card shows |
TXT | _agentlane-verify.portal.your-agency.com | a one-off token that proves you control the name |
Both are required. The CNAME alone would let anyone point a name at us; the TXT ties the name to your agency.
Get the records into your zone
Pick one of the two tabs under Set up the DNS records:
- Configure automatically — choose Cloudflare or Amazon Route 53, paste a credential, press Preview changes, read the exact create/update/no-op per record, then Apply. Details and the credential scopes are in the next section.
- Do it yourself — copy or download the records as a plain list, a BIND zone-file snippet, a
Cloudflare
curlscript, or a Route 53 change batch with itsaws route53command, and apply them in your provider’s control panel or CLI.
Wait for verification
We check the records every few minutes (press Check now to run a check immediately). Status moves from Waiting for DNS to Issuing certificate to Live. Issuing the certificate usually takes a minute or two after DNS verifies. If nothing verifies within 72 hours the address is marked Failed; Retry opens a fresh window.
Done
Once Live, your clients can sign in at your address and their emails link there. We keep re-checking the two records daily; if both disappear, the address is taken down again so nobody can hijack a dangling name. Remove takes it down on purpose; the same address can be re-added after an hour.
Automatic setup: what we do with your credential
The credential you paste is used for that one request and then discarded. It is not stored, not logged and not shown back to you; both Preview and Apply send it again rather than keep it between the two calls. If you prefer, revoke the token at your provider as soon as the address shows Live.
What the automation will and will not do:
- It writes only the two records above, under your own hostname, in the zone that holds it.
- It never deletes anything. If another record is already in the way (for example an
Arecord at the same name), the preview stops with a message telling you what to remove by hand. - It only ever talks to the provider’s official API host.
- On Cloudflare the CNAME is written with the proxy (orange cloud) off. This is required: a proxied CNAME answers with Cloudflare’s own addresses, so the ownership check and the certificate issuance would both fail.
Cloudflare
Create an API token (My Profile → API Tokens → Edit zone DNS template) limited to the zone that holds your hostname. Never use the Global API Key. The automation looks the zone up by name.
Amazon Route 53
Create an IAM access key allowed route53:ListHostedZonesByName, route53:GetHostedZone,
route53:ListResourceRecordSets and route53:ChangeResourceRecordSets, ideally restricted to the
one hosted zone. If the key cannot list zones, paste the hosted zone id and the lookup is
skipped. Temporary credentials (with a session token) work too. Writes are UPSERTs of the exact
name and type.
Namecheap, GoDaddy and everyone else
Not connected, on purpose:
- Namecheap’s API needs every caller IP allow-listed on your account and an account-level key that reaches all your domains — far more access than two records justify.
- GoDaddy’s DNS API is only available to accounts with 10+ domains or an active Discount Domain Club plan, so most agencies cannot create a key at all.
Use the Do it yourself tab for these: the plain record list fits any control panel.
The sender domain
Under Settings → Domains → Sender domain, add a domain or subdomain you control (a subdomain
such as mail.your-agency.com keeps your own mailbox’s SPF record untouched) and choose the local
part of the From address. The card lists the DNS records our email provider needs (DKIM, SPF and a
return-path record), with a per-record status. Until the domain verifies, client email keeps the
platform sender with your agency as the display name; once verified it is sent as
Your Agency <no-reply@mail.your-agency.com>.
The automatic DNS setup covers the portal address only; sender-domain records are applied by hand from the table in the card.
Troubleshooting
| Symptom | Likely cause |
|---|---|
| “That hostname belongs to the platform” | You entered an agentlane.agency name. Use a subdomain of a domain you own. |
| “Use a subdomain such as portal.your-agency.com” | A bare domain cannot be a CNAME in this version. |
| “CNAME points at …, expected …” | The record exists but targets something else. Update its value. |
| “TXT … has a different value” | A stale token from an earlier attempt. Replace it with the one the card shows now, or use Configure automatically, which updates it. |
| Cloudflare: verified DNS never becomes Live | The CNAME is proxied. Turn the orange cloud off for that record. |
| “already has a … record” during preview | Another record sits at the same name. Remove or rename it — we will not delete it for you. |
| Status stuck on Issuing certificate | Usually under two minutes. If it lasts longer, press Check now; if it persists, ask us. |