The Custom Domain add-on lets you serve your public bucket over your own subdomain — for example files.yourbusiness.com instead of the platform address. You manage it from the Custom Domain tab on your service.
What you need
- The Custom Domain option added to your service (it's a paid add-on — add it from Manage Options, or pick it when ordering).
- Your bucket set to public under Bucket Options (custom domains serve public content only).
- A subdomain you control (for example
files.example.com). A bare/apex domain such as example.com works only when the tab says so and your DNS provider supports ALIAS records or CNAME flattening.
The five steps
- Order the add-on — add the Custom Domain option to your service.
- Create the CNAME record first — the target is shown on the Custom Domain tab before you submit. Create the CNAME before you submit the request: if our check runs before the record exists, some DNS resolvers remember "not found" for hours.
- Enter your subdomain — on the Custom Domain tab, type your subdomain and submit. Add the TXT record shown on the tab right away, for the same reason.
- Check both records — the CNAME and a TXT record proving you own the domain — the tab shows both DNS records to create at your DNS provider:
- CNAME:
- Type: CNAME
- Name / Host: your subdomain (e.g.
files.example.com)
- Target / Value: the target shown on the tab
- TXT (ownership check):
- Type: TXT
- Name / Host:
_sf-challenge. + your subdomain (e.g. _sf-challenge.files.example.com)
- Value: the token shown on the tab
Both records are required — the TXT record proves you actually control the domain's DNS, not just that a CNAME happens to point at us.
- Verification & approval — we check your DNS automatically every few minutes; you can also press Check now (once a minute). Once both records are found, your request is marked Verified and our team reviews it. After approval it goes Active and your domain starts serving your bucket.
Good to know / limitations
- Reads only. Your S3 API access, the
mc command-line client, and presigned share links keep using the platform domain. The custom domain is for anonymous public reads (e.g. embedding images or files on your website).
- Video and large files. On some servers, video, audio and archive files, and files over 100 MB, are served from the platform address: the visitor is redirected there automatically. Embedding still works, but the address bar shows the platform address for those files.
- Keep the bucket public. If you switch the bucket back to private, the custom domain stops working (visitors get an access-denied error). Make it public again to restore it.
- DNS propagation. New CNAME/TXT records can take a few minutes to a few hours to become visible worldwide. If Check now says it isn't found yet, wait and try again.
- 14-day window. If verification (both the CNAME and the TXT record) isn't completed within 14 days of the request, it is automatically removed and the domain name is freed. Just submit it again when you're ready.
- Removing it. Use Remove domain on the tab at any time. Cancelling the service, or removing the Custom Domain add-on option from your service, also removes the domain automatically (shortly after, on the next processing run) — this still works even if you've already removed the add-on.
- While suspended. If your service is suspended, a domain that is still being set up pauses where it is and continues once the service is active again.