Custom Domain
Your Privacy Request Center is a hosted form that lives on your own domain, so Data Subjects submit requests from an address that matches your brand (for example, privacy.example.com). You can set up and manage this domain yourself from Settings. DataGrail generates the DNS records you need, verifies your ownership, and provisions the SSL certificate automatically.
You manage your domain from the Privacy Request Center page under Settings.
Before You Start
To set up a custom domain, you will need the following:
- An Admin role in DataGrail
- Access to your organization's DNS provider to add records
- The subdomain you want to use for your Privacy Request Center
Your domain must be a subdomain that begins with either privacy or preferences. You choose the prefix from a dropdown when adding the domain, so you only enter the base domain yourself.
| Prefix | Example |
|---|---|
privacy | privacy.example.com |
preferences | preferences.example.com |
Adding A Domain
To begin, add the domain you want to use for your Privacy Request Center.

- Go to Settings and select Privacy Request Center.
- Select a prefix (privacy or preferences) from the dropdown.
- Enter your base domain in the Domain field—only the domain, with no prefix (for example,
example.com). - Select Set Up Domain.
After you add the domain, DataGrail generates the DNS records you need and begins provisioning your SSL certificate.
Adding DNS Records
Once your domain is added, the DNS Records section lists two CNAME records to add at your DNS provider. Both records are required.

| Record | Type | Purpose |
|---|---|---|
| Routing | CNAME | Points your domain to your Privacy Request Center |
| SSL Certificate Validation | CNAME | Lets DataGrail verify you own the domain and issue its SSL certificate |
You can copy each value individually, or select Download Records to export both records as a CSV file to share with whoever manages your DNS.
- Copy the Name and Value for each record, or select Download Records for a CSV.
- At your DNS provider, add both records exactly as shown, using the type CNAME.
- Leave both records in place—removing either one takes your domain or its certificate offline.
The Routing and SSL Certificate Validation records must stay in your DNS permanently. DataGrail uses them to keep your domain reachable and to automatically renew your SSL certificate. Removing them will take your Privacy Request Center offline.
DataGrail issues your SSL certificate through Amazon. If your domain uses CAA records—a DNS setting that limits which certificate authorities can issue certificates for your domain—they must allow Amazon, or the certificate cannot be issued and verification will fail. Most domains don't use CAA records, so you can usually skip this step.
To check, run dig yourdomain.com caa in a terminal, or use any online CAA lookup tool. If nothing is returned, no action is needed. If records are returned and none of them reference an Amazon certificate authority (amazon.com, amazontrust.com, awstrust.com, or amazonaws.com), add a record at your DNS provider with the type CAA and the value 0 issue "amazon.com".
Verifying The Domain
After you add the records at your DNS provider, DataGrail verifies them and issues your SSL certificate.
Select Check Status to see whether verification is complete. The page also refreshes automatically about every 30 seconds, so you can leave it open while DNS changes take effect. Verification usually takes a few minutes, but can take up to an hour depending on how quickly your DNS provider propagates the records.
Your domain's status is shown as a badge:
| Status | Meaning |
|---|---|
| Pending Validation | DataGrail is waiting to detect your DNS records and issue the certificate |
| Ready to Activate | Your records are verified and the certificate is issued—you can now make the domain live |
| Active | The domain is live for your Privacy Request Center |
| Failed | The records could not be verified—review them and start over |
Activating The Domain
Once the status shows Ready to Activate, you choose when to switch your Privacy Request Center to the new domain.
Select Make Active to switch your Privacy Request Center to the new domain. This can take a few minutes. When it finishes, the domain shows as Active with its SSL certificate active and set to auto-renew. Select Open to view your live Privacy Request Center.
Replacing A Domain
You can move your Privacy Request Center to a different domain at any time without downtime.
- On the Privacy Request Center settings page, select Replace Domain.
- Add the new domain and its DNS records, following the same steps above.
- When the new domain is verified, select Make Active.
Your current domain stays live the whole time—the new one does not take over until you select Make Active. Once you activate the new domain, DataGrail decommissions the previous one automatically.
SSL Certificates
DataGrail provisions and manages your SSL certificate for you—there is no manual certificate setup. As long as the Routing and SSL Certificate Validation records remain in your DNS, your certificate renews automatically before it expires. If you remove the records, the certificate cannot renew and your Privacy Request Center will go offline.
Troubleshooting
If you run into issues while setting up your domain, review the following.
Verification failed or the records can't be found
DataGrail could not find your CNAME records. Confirm that both records are added at your DNS provider and that each Name and Value matches exactly what is shown—even a small difference will prevent verification. DNS changes can also take time to propagate. Once the records are correct, select Start Over to try again.
The certificate won't issue even though the records are correct
If your CNAME records match exactly but the SSL certificate still won't issue, your domain may have CAA records that block Amazon from issuing the certificate. Run dig yourdomain.com caa (or use an online CAA lookup tool) to check. If records are returned and none reference an Amazon certificate authority (amazon.com, amazontrust.com, awstrust.com, or amazonaws.com), add a CAA record at your DNS provider with the value 0 issue "amazon.com", then select Start Over.
My records look right, but the domain still won't validate
Some DNS providers—including GoDaddy—automatically append your base domain to the Name of every record you add. If you paste the full Name from DataGrail, your record can end up doubled (for example, privacy.example.com.example.com), and verification will fail.
If your provider does this, enter only the subdomain portion in the Name field—leave off your base domain—so the provider appends it for you. Check the record after saving to confirm it resolves to the exact Name shown in DataGrail.
Disclaimer: The information contained in this message does not constitute as legal advice. We would advise seeking professional counsel before acting on or interpreting any material.