Skip to main content

Custom Domain

Your Privacy Request Center is a hosted form that lives on your own domain, so Data Subjects submit requests from an address that matches your brand (for example, privacy.example.com). You can set up and manage this domain yourself from Settings. DataGrail generates the DNS records you need, verifies your ownership, and provisions the SSL certificate automatically.

You manage your domain from the Privacy Request Center page under Settings.

Before You Start

To set up a custom domain, you will need the following:

  • An Admin role in DataGrail
  • Access to your organization's DNS provider to add records
  • The subdomain you want to use for your Privacy Request Center

Your domain must be a subdomain that begins with either privacy or preferences. You choose the prefix from a dropdown when adding the domain, so you only enter the base domain yourself.

PrefixExample
privacyprivacy.example.com
preferencespreferences.example.com

Adding A Domain

To begin, add the domain you want to use for your Privacy Request Center.

The Domain setup form on the Privacy Request Center settings page, with a prefix dropdown, a domain field, and a Set Up Domain button

  1. Go to Settings and select Privacy Request Center.
  2. Select a prefix (privacy or preferences) from the dropdown.
  3. Enter your base domain in the Domain field—only the domain, with no prefix (for example, example.com).
  4. Select Set Up Domain.

After you add the domain, DataGrail generates the DNS records you need and begins provisioning your SSL certificate.

Adding DNS Records

Once your domain is added, the DNS Records section lists two CNAME records to add at your DNS provider. Both records are required.

The DNS Records table listing the two CNAME records to add, with the domain in a Pending Validation state and a Download Records button

RecordTypePurpose
RoutingCNAMEPoints your domain to your Privacy Request Center
SSL Certificate ValidationCNAMELets DataGrail verify you own the domain and issue its SSL certificate

You can copy each value individually, or select Download Records to export both records as a CSV file to share with whoever manages your DNS.

  1. Copy the Name and Value for each record, or select Download Records for a CSV.
  2. At your DNS provider, add both records exactly as shown, using the type CNAME.
  3. Leave both records in place—removing either one takes your domain or its certificate offline.
Keep Both Records In Place

The Routing and SSL Certificate Validation records must stay in your DNS permanently. DataGrail uses them to keep your domain reachable and to automatically renew your SSL certificate. Removing them will take your Privacy Request Center offline.

Check Your CAA Records

DataGrail issues your SSL certificate through Amazon. If your domain uses CAA records—a DNS setting that limits which certificate authorities can issue certificates for your domain—they must allow Amazon, or the certificate cannot be issued and verification will fail. Most domains don't use CAA records, so you can usually skip this step.

To check, run dig yourdomain.com caa in a terminal, or use any online CAA lookup tool. If nothing is returned, no action is needed. If records are returned and none of them reference an Amazon certificate authority (amazon.com, amazontrust.com, awstrust.com, or amazonaws.com), add a record at your DNS provider with the type CAA and the value 0 issue "amazon.com".

Verifying The Domain

After you add the records at your DNS provider, DataGrail verifies them and issues your SSL certificate.

Select Check Status to see whether verification is complete. The page also refreshes automatically about every 30 seconds, so you can leave it open while DNS changes take effect. Verification usually takes a few minutes, but can take up to an hour depending on how quickly your DNS provider propagates the records.

Your domain's status is shown as a badge:

StatusMeaning
Pending ValidationDataGrail is waiting to detect your DNS records and issue the certificate
Ready to ActivateYour records are verified and the certificate is issued—you can now make the domain live
ActiveThe domain is live for your Privacy Request Center
FailedThe records could not be verified—review them and start over

Activating The Domain

Once the status shows Ready to Activate, you choose when to switch your Privacy Request Center to the new domain.

Select Make Active to switch your Privacy Request Center to the new domain. This can take a few minutes. When it finishes, the domain shows as Active with its SSL certificate active and set to auto-renew. Select Open to view your live Privacy Request Center.

Replacing A Domain

You can move your Privacy Request Center to a different domain at any time without downtime.

  1. On the Privacy Request Center settings page, select Replace Domain.
  2. Add the new domain and its DNS records, following the same steps above.
  3. When the new domain is verified, select Make Active.

Your current domain stays live the whole time—the new one does not take over until you select Make Active. Once you activate the new domain, DataGrail decommissions the previous one automatically.

SSL Certificates

DataGrail provisions and manages your SSL certificate for you—there is no manual certificate setup. As long as the Routing and SSL Certificate Validation records remain in your DNS, your certificate renews automatically before it expires. If you remove the records, the certificate cannot renew and your Privacy Request Center will go offline.

Troubleshooting

If you run into issues while setting up your domain, review the following.

Verification failed or the records can't be found

DataGrail could not find your CNAME records. Confirm that both records are added at your DNS provider and that each Name and Value matches exactly what is shown—even a small difference will prevent verification. DNS changes can also take time to propagate. Once the records are correct, select Start Over to try again.

The certificate won't issue even though the records are correct

If your CNAME records match exactly but the SSL certificate still won't issue, your domain may have CAA records that block Amazon from issuing the certificate. Run dig yourdomain.com caa (or use an online CAA lookup tool) to check. If records are returned and none reference an Amazon certificate authority (amazon.com, amazontrust.com, awstrust.com, or amazonaws.com), add a CAA record at your DNS provider with the value 0 issue "amazon.com", then select Start Over.

My records look right, but the domain still won't validate

Some DNS providers—including GoDaddy—automatically append your base domain to the Name of every record you add. If you paste the full Name from DataGrail, your record can end up doubled (for example, privacy.example.com.example.com), and verification will fail.

If your provider does this, enter only the subdomain portion in the Name field—leave off your base domain—so the provider appends it for you. Check the record after saving to confirm it resolves to the exact Name shown in DataGrail.

 

Need help?
If you have any questions, please reach out to your dedicated Account Manager or contact us at support@datagrail.io.

Disclaimer: The information contained in this message does not constitute as legal advice. We would advise seeking professional counsel before acting on or interpreting any material.