Allowed domains
Which sites may send events for a website, and how domains, subdomains and www are matched.
Every website has a list of allowed domains. The relay only accepts events from pages on those domains, so nobody can copy your snippet onto another site and send events into your pixel.
- Step 1: Allowed domains lists every site the relay accepts events from for this website.
- Step 2: Click Add domain to get an empty row.
- Step 3: Type the domain only, without https:// or a path. Subdomains are covered automatically.
- Step 4: Click Save changes. Events from the new domain are accepted straight away.
How domains are matched
- A domain covers itself and every subdomain.
example.comallowswww.example.com,book.example.comandshop.eu.example.com. - It does not work the other way round.
www.example.comdoes not allowexample.com. When in doubt, list the bare domain. - The scheme, port and path are ignored.
https://example.com/contactis read asexample.com. - Hosts are compared as whole names, so
example.comnever allowsexample.com.other-site.net.
Add or remove a domain
- Open the website from Websites.
- Under Allowed domains, click Add domain and type the domain, or click the cross next to one to remove it.
- Click Save changes.
The change applies to the next event. A website needs at least one domain.
Domains in analytics
When a website has more than one domain, its analytics can be split by domain. Each event is recorded with the site's own host (without www.), only when that host is on this list.
Events from an unlisted domain
The relay answers them with 403 Origin not allowed and does not record them. If a site stops showing events after a move to a new domain, add the new domain here. See Events missing in Meta.
Related articles
Still stuck?
Tell us what you are trying to do and we will help you set it up.