Guide
White label domain: what it is and how to set one up
A white label domain is a domain you own that fronts another company's product, so your customers see your brand in the address bar and never the vendor's. You add a DNS record that points a name such as app.example.com at the vendor, the vendor secures the name with an HTTPS certificate, and the product answers there.
The four things people mean by white label domain
The phrase covers four different jobs. They share one mechanism, a DNS record plus an HTTPS certificate, but they are bought, set up and priced differently. Find yours in the table, then jump to the matching guide.
| Meaning | Who it is for | What you do | Read next |
|---|---|---|---|
| Your domain on someone else's product | Agencies and businesses that use a platform | Point a subdomain you own, such as app.example.com, at the platform so clients log in under your brand. | GoHighLevel setup guide |
| Customer domains inside your own product | Software companies | Let each customer connect their own domain to your app, with DNS and HTTPS handled for them. | White label custom domains |
| Selling domains under your brand | Hosts, agencies and platforms | Resell registrations and renewals through a reseller program or an API. | Domain reseller guide |
| Hiding the vendor in DNS, email or links | Anyone with a branded stack | Run vanity nameservers, a branded sending domain or a branded link domain. | Jump to that section |
The first two are the same mechanism seen from opposite sides. The vendor offers the feature and the customer adds the DNS record. If you build software, you are the vendor in that sentence, which is the job custom domains for SaaS exists to do.
How a white label domain works
Three things have to be true before app.example.com opens a vendor's product with your name on it.
- DNS points the name at the vendor. You create a CNAME record, an alias from
app.example.comto a hostname the vendor gives you. When someone visits, DNS follows the alias and returns the vendor's server addresses. - The vendor holds a certificate for your name. The browser sends the name it wants in the TLS handshake (Server Name Indication) and expects a certificate that covers exactly that name. Most vendors request one automatically from Let's Encrypt. A common check, called HTTP-01, fetches a file from your name over plain HTTP, so it only passes once your record points at the vendor. The record comes first and the certificate follows.
- The vendor maps the name to your account. The server reads the Host header, finds the account that registered
app.example.com, and serves your branded login or tenant. If the name was never registered, the visitor sees a generic vendor page or an error.
app.example.com. 300 IN CNAME edge.vendor.example.net.That one line is the whole DNS side. Everything else is the vendor's job. When a white label domain fails, one of the three steps is missing, and the symptom tells you which: a DNS error points at step 1, a certificate warning at step 2, and a generic vendor page or a 404 at step 3.
White label, custom, vanity and branded domains
These terms overlap and search results mix them. This is how people use each one.
| Term | Usually means | Example |
|---|---|---|
| Custom domain | Any domain you own that you point at a service which normally runs on its own domain. | shop.example.com on a store builder |
| White label domain | A custom domain used so the vendor's brand shows nowhere the customer looks: login, links and email. | app.example.com on a CRM |
| Vanity domain | A short or brandable name, often for links. See vanity domain. | go.example.com |
| Branded domain | A domain that carries your brand, most often for links or email sending. | links.example.com |
| Subdomain | A name under a domain you own. See custom domain vs subdomain. | app.example.com |
In practice a white label domain is a custom domain with a stricter goal: nothing the customer sees should name the vendor.
Subdomain or root domain
Use a subdomain whenever the vendor allows it. A CNAME works on a subdomain and cannot work on a root domain, because DNS does not let a CNAME share a name with other records (RFC 1034, RFC 2181) and a root domain always carries SOA and NS records.
| Name | CNAME allowed | What to use |
|---|---|---|
app.example.com (subdomain) | Yes | A CNAME to the vendor's hostname. |
example.com (root, also called the apex) | No | ALIAS, ANAME or CNAME flattening if your DNS host offers it, or A records to the vendor's addresses. Otherwise send the root to www. |
ALIAS, ANAME and CNAME flattening are DNS host features rather than standard record types, and each host names and limits them differently. The explainers on apex domain vs CNAME and CNAME flattening cover the details. Vendors tend to steer you to a subdomain: HighLevel's help article for its login domain says to use one.
How to set up a white label domain
The steps are the same on almost every platform. Menu names differ, so take the exact target from your vendor's own instructions.
- Pick a subdomain you do not use yet. Common choices are
app,login,portalandgo. Use a domain whose DNS you can edit. - Copy the target from the vendor. It is a hostname such as
edge.vendor.example.net. Do not guess it. Vendors change targets and often use a different one for each feature. - Add a CNAME record. Name: the subdomain only (
app, not the full name, because most DNS hosts add the domain for you). Value: the vendor's hostname. TTL: 300 seconds while you test. - Clear conflicts. A name that has a CNAME can hold no other record. Delete any A, AAAA, TXT or second CNAME record at the same name.
- Turn off the proxy. If your DNS is on Cloudflare, set the record to DNS only (grey cloud) unless the vendor says otherwise. A proxied record answers with Cloudflare's addresses instead of the vendor's, so the vendor cannot prove control of the name or issue its certificate.
- Add the domain in the vendor's settings and save. Many vendors check the record at this point and start the certificate.
- Wait, then verify. DNS usually answers within minutes, and the certificate follows once DNS is right. Run the checks below, then open the name in a private window and on a phone.
- Finish the branding. Upload your logo and add your terms and privacy links if the vendor asks, so no screen falls back to the vendor's.
DNS records cheat sheet
Use this table to match a goal to a record type. The values in the last column are the traps that cause most failed setups.
| Goal | Type | Name | Value | Watch for |
|---|---|---|---|---|
| Subdomain to a vendor | CNAME | app | The vendor's hostname | Nothing else may exist at the same name. |
| Root domain to a vendor | ALIAS, ANAME or flattened CNAME; or A | @ | The vendor's hostname or address | Host specific. Your mail records at the root stay in place. |
| Vanity nameservers | NS, plus glue at the registrar | ns1 | Your DNS servers' addresses | Glue is required when the nameserver sits inside the domain it serves. |
| Branded email sending | TXT for SPF, CNAME or TXT for DKIM | As the sender instructs | As the sender instructs | SPF allows 10 DNS lookups (RFC 7208). |
| Limit certificate issuers | CAA | @ | 0 issue "letsencrypt.org" | If you publish CAA records, list every CA your vendors use. |
example.com. 3600 IN CAA 0 issue "letsencrypt.org"With no CAA records, any certificate authority may issue for your names. Once you publish any, the authority checks them before it issues, starting at the full name and climbing toward the root until it finds a set (RFC 8659).
Where the vendor's name still shows
The login address is only the first surface. Walk the list below as a client would and fix whatever still names the vendor.
| Surface | What a visitor sees | How to check | Fix |
|---|---|---|---|
| Login and app address | The URL in the address bar | Open the login in a private window | A white label domain on a subdomain |
| HTTPS certificate | The name on the certificate in the padlock details | The openssl command in the next section | Point DNS straight at the vendor so it can issue a certificate for your name |
| Links in email and SMS | Form, calendar and review links | Send yourself a test and hover the link | A branded link domain, which is a second CNAME |
| Email sender | A "via" label beside your name in some inboxes | Open the message source and read DKIM-Signature (d=) and Return-Path | A dedicated sending domain with SPF and DKIM |
| Nameservers | Nameserver names in a DNS lookup | dig +short NS example.com | Vanity nameservers, with glue records where the nameserver sits inside the domain |
| Help center, status page, docs | A separate address for each tool | List every public hostname you give clients | One subdomain and one record per tool |
| Footer, logo, legal links | "Powered by" lines and vendor terms | Click through every screen as a client | A vendor setting, often on a higher plan |
Check a white label domain in two minutes
Run these four commands in a terminal and replace app.example.com with your name. Or paste the name into the free Domain Health Check, which tests DNS, the CNAME on a root domain, HTTPS, the certificate, its renewal runway and the redirect from http to https.
dig +short CNAME app.example.com
dig +short app.example.com
curl -sI https://app.example.com | head -n 5
echo | openssl s_client -connect app.example.com:443 -servername app.example.com 2>/dev/null | openssl x509 -noout -subject -issuer -dates| Command | A healthy answer | A problem looks like |
|---|---|---|
dig +short CNAME | The vendor's hostname. | Empty output: no record, a typo, or the full name typed into the name field. A flattened or A record answers with addresses instead. |
dig +short | One or more addresses that belong to the vendor. | Nothing, or addresses that are not the vendor's: a proxy or a stale record. |
curl -sI | A 200 response, or a redirect to the login. | A TLS error, a 404 from a generic page, or a timeout. |
openssl | The subject names your host, the issuer is a real authority, and notAfter is in the future. | A different host in the subject, an expired date, or no output at all. |
When a white label domain does not work
Most failures come from six causes. The full troubleshooting guide has the commands for each.
| Symptom | Likely cause | Fix |
|---|---|---|
| Site not found, or NXDOMAIN | The record is missing, or the full name was typed into the name field so the domain appears twice (app.example.com.example.com). | Enter only the subdomain, save, and re-run dig. |
| Works on some networks and fails on others | A cached answer is still live, or DNSSEC is broken after a DNS move. | Wait out the TTL. Check the DS record at your registrar after any DNS move. |
| Certificate warning | The certificate is not issued yet, or a proxy or a CAA record is blocking issuance. | Point DNS straight at the vendor, DNS only, and allow the vendor's CA in CAA. |
| The vendor's generic page | The name is not saved in the vendor's account, or was saved with a typo. | Re-enter the exact name in the vendor's settings. |
| An error about a CNAME at the root | A CNAME was placed on the apex. | Use the host's ALIAS or flattening, or switch to a subdomain. |
| The old login still shows after a change | The vendor still holds the previous entry. | Remove the old domain in the vendor's settings, save, then add the new one. |
If you build software: white label domains for your customers
When customers bring their own domain to your product, you are the vendor in every section above. You own DNS verification, certificate issuance and renewal, routing by host, and the support tickets when a customer's record is wrong. CustomDomain™ is a managed service for that part. Your customer enters a domain and a guided flow takes over. Where their DNS provider supports it, the records are written for them; otherwise they get the exact records to copy. Ownership is verified, and the records are watched afterward for drift.
Every plan includes the embeddable widget, the SDK, the REST API, webhooks, drift detection and an MCP server. On Growth and above, traffic can run through the CustomDomain™ reverse proxy edge with automatic HTTPS. Removing CustomDomain™ branding from the connect flow and reselling domains are part of Enterprise. The white label custom domain guide shows how the pieces fit.
What a white label domain costs
Pointing a domain you already own at a vendor costs nothing at most DNS hosts, and many vendors issue the certificate for free through Let's Encrypt. The real costs sit in four places:
- The domain itself. A registration is billed yearly and the price depends on the ending. Read the renewal price, which can differ from the first-year price.
- The vendor's plan. Platforms often reserve white label domains and branding removal for higher plans. Check their pricing page before you promise it to clients.
- Engineering time, if you build custom domains into your own product. You need DNS verification, certificate issuance and renewal, and routing by host.
- Domain resale, if you sell domains. The table shows what the accreditation route costs.
| Path | What you pay | Source |
|---|---|---|
| Use a vendor's white label domain feature | The vendor's plan price. The CNAME record is free at most DNS hosts. | The vendor's pricing page |
| Offer customer domains in your own SaaS with CustomDomain™ | From $10 a month (Starter, 10 domain connections a year), $149 (Startup, 600 a year) and $649 (Growth, adds the reverse proxy edge and automatic HTTPS). Premium and Enterprise are by contract. Every self-serve plan starts with a 14 day free trial. | CustomDomain™ pricing |
| Become an ICANN accredited registrar | US$3,500 non-refundable application fee and US$4,000 a year, plus variable fees and a fee on each registration, renewal and transfer. | ICANN registrar financial considerations and registrar fees |
| Run your own top-level domain | USD 227,000 evaluation fee per application in the 2026 round, before the cost of running a registry. The application window closed on 12 August 2026. | ICANN evaluation fee FAQs |
Is a white label domain legal?
Yes. White labelling means selling or presenting a product under your own brand, and it is a normal, lawful way to do business. It goes wrong when it deceives or infringes:
- Misleading claims. False statements about who makes a product can count as misleading advertising, depending on the claim and the country.
- Trademarks. A domain that contains someone else's trademark can lose a dispute under ICANN's UDRP and, in the US, can create liability under the anticybersquatting law (ACPA).
- Vendor terms. Some platforms restrict resale or reserve white labelling for certain plans. The contract decides, not the technology.
- Impersonation. A domain built to pass as another company is fraud, however it is hosted.
This is general information, not legal advice. Ask a lawyer when a contract or a trademark is involved.
White label nameservers, email domains and link domains
The same idea applies to three other places a vendor's name can leak. Each uses different records.
White label nameservers
Vanity nameservers show ns1.example.com instead of the DNS host's own name. You set them at the registrar: the nameserver hostnames, plus glue records (addresses held in the parent zone) when a nameserver lives inside the domain it serves. Without glue, resolvers cannot find the nameserver and the domain stops resolving. Your DNS host must support vanity nameservers, and you must keep the addresses in step with the host's.
White label email domains
A branded sending domain makes mail show your domain instead of the platform's. The platform gives you records to add: an SPF TXT record and one or more DKIM records, often CNAME or TXT. Use a subdomain such as mail.example.com to keep the reputation of your root domain separate. An SPF record may cause at most 10 DNS lookups (RFC 7208), and past that limit it returns a permanent error.
White label link and short URL domains
A branded link domain replaces the platform's short domain in the links you send. It works like the login domain: a CNAME on a subdomain, a certificate, and a registration in the platform. Use a dedicated subdomain so a problem with link reputation does not touch your main site.
Sources and further reading
- RFC 1034, Domain names: concepts and facilities (CNAME rules, section 3.6.2)
- RFC 2181, Clarifications to the DNS specification (section 10.1)
- RFC 8659, DNS Certification Authority Authorization (CAA) records
- RFC 7208, Sender Policy Framework (SPF)
- Let's Encrypt, challenge types
- IANA, root zone database and TLD types
- ICANN, registrar financial considerations
- ICANN, registrar fees
- ICANN, gTLD evaluation fee FAQs, 2026 round
- HighLevel, set up a whitelabel domain for the desktop web app
- HighLevel, branding system generated links (API domain)
- HighLevel, which domain type do you need
Frequently asked questions
What is a white label domain?
A white label domain is a domain you own that fronts another company's product, so customers see your brand instead of the vendor's. A DNS record, usually a CNAME on a subdomain such as app.example.com, points it at the vendor, and the vendor issues the HTTPS certificate.
What is the difference between a white label domain and a custom domain?
A custom domain is the general term for a name you own that points at a service. A white label domain is a custom domain used with a stricter goal: no screen, link or email should name the vendor. The DNS work is the same.
What is the difference between a white label domain and an API domain?
On HighLevel, the white label domain brands the login and app address. The API domain, also called the branded domain, brands the system generated links sent by email and SMS, such as forms, calendars and review links. HighLevel lists them as separate domain types with their own DNS records, so set up each one on its own subdomain.
Can I use my root domain as a white label domain?
Usually not. A CNAME cannot sit at the root of a domain, so most vendors ask for a subdomain such as app.example.com. Some DNS hosts offer ALIAS, ANAME or CNAME flattening so a root domain can follow a hostname, but support depends on both your DNS host and the vendor.
How long does a white label domain take to start working?
DNS often answers within minutes. Vendors commonly quote up to 48 hours for every network to catch up, depending on the record's TTL and what resolvers have cached. The HTTPS certificate follows once DNS is correct. Setting the TTL to 300 seconds before you change a record shortens the wait.
Is white labelling illegal?
No. White labelling is a lawful, standard way to sell a product under your own brand. Problems come from deception, trademark infringement, breaking a vendor's resale terms or impersonating another company. This is general information, not legal advice.
What are the 7 types of domains?
There is no single official list of seven. IANA sorts top-level domains into five types: generic, country code, sponsored, generic restricted and infrastructure, and it also lists a test type. Platforms publish their own lists. As of September 2026, HighLevel's help center names seven domain types for its product: website and funnel, purchased, white label, API or branded, dedicated sending, client portal and WordPress.
How much does a white label domain cost?
Pointing a domain you own at a vendor is free in DNS terms, and many vendors include the certificate. You pay for the domain registration, which is billed yearly and priced by ending, and for the vendor plan that unlocks white labelling. Reseller programs and building your own platform cost more. The cost table above lists the verified figures.
Can I create my own top-level domain?
A new generic top-level domain can only be created through ICANN's New gTLD Program. The 2026 round closed its application window on 12 August 2026, the evaluation fee was USD 227,000 per application, and an applicant must also be able to run a registry. For branding, a subdomain or a name on an existing ending is the practical route.
What is a white label example?
An agency sells a marketing platform it does not build. Clients sign in at app.agencyname.com, see the agency's logo, receive links on links.agencyname.com and never see the platform's name. A software company that lets customers run a hosted help center at help.theircompany.com is the same idea from the vendor's side.
Is domain flipping illegal?
No. Buying domains and selling them at a profit is legal. Registering a name in bad faith to profit from someone else's trademark is cybersquatting, which can lose a UDRP case and, in the US, create liability under the ACPA.
What is the difference between white label and private label?
White label products are made by one company and sold by many under their own brands, so the same product appears under several names. Private label products are made for one retailer to its own specification and sold only under that retailer's brand.