---
title: "Managing domains"
description: "Add custom domains to Edge CDN with an external URL or storage bucket origin, CNAME setup, automatic SSL via Let's Encrypt, and optional password protection."
url: "https://edge.network/docs/cdn/domains"
section: "CDN"
---

# Managing domains

Add custom domains to your CDN deployment with automatic SSL certificate provisioning.

## Adding a domain

Each domain you add to a deployment needs to be configured with a domain name and an origin source:

- **Domain:** the domain or subdomain visitors will use (e.g. `cdn.yoursite.com`).
- **Origin type:** where the CDN fetches content from:
  - **External URL:** pull content from any HTTP/HTTPS endpoint: your origin server, another cloud provider's storage, or any web-accessible URL. Example: `https://your-bucket.s3.amazonaws.com`.
  - **Storage Bucket:** use an Edge Storage bucket as your origin. No external URL is needed: select one of your buckets directly. This suits static assets, images and files. [Learn more about Edge Storage](/docs/storage).

> [!TIP]
> **Storage bucket integration.** When using a Storage bucket as your origin, the CDN fetches content directly via internal networking. This means faster origin fetches, no public bucket configuration required, and unified billing.

## DNS configuration

After adding a domain, you need to configure your DNS to point to Edge CDN.

### For subdomains (recommended)

Add a CNAME record:

```text
cdn.yoursite.com.  CNAME  cdn.edge.network.
```

> [!WARNING]
> **Root domains (apex domains)** (e.g. `yoursite.com`) cannot use CNAME records. Use your DNS provider's ALIAS or ANAME record type, or consider using Edge DNS, which supports this natively.

![Add Domain modal with domain and origin fields](/media/docs/control-cdn-domains.svg)

## Domain status

Domains go through several states during setup.

### DNS status

- `pending`: waiting for you to configure DNS
- `verified`: DNS is correctly configured
- `failed`: DNS check failed; verify your CNAME record

### SSL status

- `issuing...`: certificate is being issued (30–60 seconds)
- `active`: a valid SSL certificate is in place
- `failed`: certificate issuance failed; check DNS

## Automatic SSL certificates

Edge CDN automatically provisions free SSL certificates for all domains using Let's Encrypt.

- **Free certificates:** no cost for SSL; included with every domain
- **Auto-renewal:** certificates renew automatically before expiry
- **Fast issuance:** certificates issued in under 60 seconds
- **TLS 1.3:** modern encryption with the latest TLS version

## Editing the domain origin

You can change the origin for any domain at any time without removing and re-adding it.

1. Click the domain row you want to edit.
2. The **Edit Domain Origin** modal opens.
3. Select a new origin type (**External URL** or **Storage Bucket**).
4. Enter the new origin URL or select a different bucket.
5. Click **Save Changes**.

> [!NOTE]
> **No downtime.** Changing the origin causes no interruption. The CDN starts fetching from the new origin for subsequent requests while existing cached content remains available.

## Root path behaviour

Control what happens when visitors access the root path (`/`) of your CDN domain directly.

### Proxy to origin (default)

Requests to the root path are proxied to your origin as normal. Use this if your origin has content at its root.

### Redirect to URL

Redirect visitors to a URL of your choice. Useful when your CDN subdomain should redirect to your main site.

- **301 Permanent:** for permanent redirects (SEO-friendly, browsers cache it)
- **302 Temporary:** for temporary redirects (not cached)

### Show Edge info page

Display a simple branded page identifying the domain as an Edge CDN endpoint. Useful for CDN-only subdomains that shouldn't be browsed directly.

> [!TIP]
> **Common use case:** if your CDN is at `cdn.yoursite.com` serving assets for `yoursite.com`, you might want to redirect root path visitors to your main site rather than showing a directory listing or 404 from your origin.

## Password protection

Any CDN domain can be protected with a username and password (HTTP Basic Auth). Visitors are prompted for credentials by their browser before anything is served. This is useful for sharing a dev build or staging site on a public URL without making it public.

1. Open your deployment's **Domains** tab.
2. Click the lock icon on the domain you want to protect.
3. Enable **Require a username and password** and set the credentials.
4. Click **Save**. Protection is live on the edge within seconds.

- **Enforced at the edge:** credentials are checked before the cache and origin; protected content is never served without them, not even from cache.
- **Hashed storage:** passwords are stored as bcrypt hashes; edge nodes never see the plaintext, and failed attempts are naturally rate-limited by the hash cost.
- **SSL keeps working:** certificate issuance and renewal are exempt from the check, so protected domains still get automatic SSL.
- **No performance cost:** verified credentials are cached at the edge, so authenticated requests are served at full CDN speed.

> [!TIP]
> **Private dev previews.** Upload a build to an Edge Storage bucket, serve it on a test domain with the bucket as origin, and enable password protection. You get a shareable HTTPS URL that only people with the credentials can open.

## Removing a domain

You can remove a domain from your deployment at any time.

> [!CAUTION]
> **Traffic stops immediately.** When you remove a domain, traffic to that domain stops being served by Edge CDN. Update your DNS records to point elsewhere before removing.

1. Click the trash icon next to the domain you want to remove.
2. Confirm the removal in the modal.
3. The domain and its SSL certificate are removed.

## Next steps

- [Configure caching](/docs/cdn/caching) — Set cache TTLs for your domains
- [Image optimisation](/docs/cdn/image-optimization) — Enable on-the-fly image processing
