A vanity URL is a custom domain (for example, myapp.mycompany.com) that points to your Unqork environment, giving end-users a branded web address instead of the default Unqork subdomain. To map traffic from domain to another, you use a CNAME record. Vanity URLs are supported for Express Unqork environment URLs. Unqork doesn't support DNS A records.
Some clients restrict all traffic to route through the vanity URL. When that's the case, any configuration still referencing the original Unqork domain stops working. Review After Adding a Vanity URL before going live.
CDN Considerations
If your organization uses a (like Akamai or Cloudflare), consult your IT or networking team before submitting a request. The key question is who manages the SSL certificate.
You manage SSL: No Unqork involvement needed for the certificate; your IT team or CDN provider retains full responsibility for certificate management and renewal.
Unqork manages SSL: Follow the steps below.
Some CDN configurations route internal or VPN traffic separately from public internet traffic. In those cases, two SSL certificates might be required: for internal traffic and for public traffic. Each might need separate management. Your IT team must identify which certificates require Unqork's involvement before you proceed.
Adding a Vanity URL
To use a custom domain, your Unqork environment needs an SSL (Secure Sockets Layer) certificate that authorizes it to serve traffic on that domain. Two certificate methods are available depending on your cloud provider.
ACM is the preferred method. Certificate expiry times will be reduced to 47 days in 2029, making automatic renewal increasingly important.
ACM (AWS)
AWS Certificate Manager (ACM) is available for AWS environments. AWS acts as the certificate authority and generates SSL certificates on behalf of your domain.
Unqork Support provides the DNS validation record, you have 72 hours to add the CNAME.
To configure a vanity URL using ACM:
Contact Unqork Support at support.unqork.com and submit a request for a vanity URL, providing your vanity URL and Unqork environment URL.
Receive validation entries from Unqork Support to add to your DNS record.
DNS entries include your domain name. If your DNS provider automatically appends the top-level domain to record names, don't include it manually when creating the record.
Create two CNAME DNS records:
Record | Name | Type | Value |
|---|---|---|---|
Validation |
| CNAME |
|
Mapping |
| CNAME |
|
When the DNS entries propagate, the certificate validates automatically.
Test the validation entries:
Open a terminal window.
Run
nslookup <record_name>.Confirm the expected record value returns.
If the terminal doesn't return the record value, verify that the domain name is not auto-appended to the record name.
Contact Unqork Support at support.unqork.com to finalize the configuration.
Your vanity URL won't be functional until Unqork Support confirms the configuration is complete.
PFX (AWS, Azure, GCP)
The PFX method is available for AWS, Azure, and GCP environments.
Don't use wildcard certificates (for example,
*.clientdomain.com). Provide a certificate for your specific domain, and include the certificate chain in the PFX file. Unqork doesn't generate certificate signing requests (CSRs). Your CA handles that independently.
To configure a vanity URL using PFX:
Contact Unqork Support at support.unqork.com and submit a request for a vanity URL. Your CA provides a PFX file (including the password) containing the following:
Certificate
Chain
Key
Don't attach the PFX file to the support ticket. Send the file and password securely through SendSafely.
Create CNAME DNS record mapping your vanity URL to your Unqork environment URL.
Record | Name | Type | Value |
|---|---|---|---|
Mapping |
| CNAME |
|
If your DNS provider automatically appends the top-level domain to record names, don't include it manually when creating the record.
Unqork confirms receipt of the PFX file and applies the certificate to your environment.
Contact Unqork Support at support.unqork.com to finalize the configuration.
Your vanity URL won't be functional until Unqork Support confirms the configuration is complete.
After Adding a Vanity URL
After adding a vanity URL, review and update the following if they might reference the original Unqork domain:
SSO configuration: Update redirect URIs in your identity provider to use the vanity URL.
Refer string generation: Update any configuration that constructs refer string URLs.
Login modules: Update any custom links in login modules.
URL construction: Review any configuration that builds URLs for links, redirects, or other purposes.
External links: Update any external links pointing to your Unqork application.
Automated tests: Update test scripts that reference the original domain.
Renewal
Certificates must be renewed annually. The process depends on the certificate type.
ACM: Renews automatically; no action required.
PFX: Requires annual renewal. Unqork Support contacts you 30 days before expiration.
To renew a PFX certificate:
Your CA submits a request at support.unqork.com with a PFX file (including the password) containing the following:
Certificate
Chain
Key
Don't attach the PFX file to the support ticket. Send the file and password securely through SendSafely.
Verify your CNAME DNS record still maps correctly from your vanity domain to your Unqork environment URL.
Unqork confirms receipt of the updated PFX file and applies the renewed certificate.
Test the validation entries using
nslookup <record_name>in a terminal.
Changelog
Date | Change |
|---|---|
2026-09-28 | Initial publication (EN-7917). |
2026-09-28 | Updated from review: full legacy content restored, style fixes applied (EN-7917). |