Adding the CNAME record for server-side tracking

For
Whoever administers DNS for your domain
The change
One CNAME record
Time required
About two minutes, plus propagation
Reversible
Yes, completely. Delete the record.

What this is, in two sentences

Server-side measurement runs through a subdomain of your own domain, which requires one CNAME record to be added. That is the entire request.

The record

FieldValue
TypeCNAME
Host / Namesst (some panels want the fully qualified name, see the note below)
Value / Target / Points toSupplied with the request, once the measurement container is provisioned
TTLAutomatic, or 3600
Proxy status (Cloudflare only)DNS only, proxy OFF (grey cloud)
Before you save

The target hostname is issued when the measurement container is provisioned and will be supplied alongside this request. If you have this page but no real hostname to point at, ask before making any change.

On the Host field. Registrars differ. Some want just the subdomain label, sst. Others want the fully qualified name, sst.yourdomain.com. If you enter sst and the panel displays sst.yourdomain.com afterwards, that is correct. If you enter the full name and it saves as sst.yourdomain.com.yourdomain.com, that is wrong. Remove it and enter sst alone.

On the Cloudflare proxy. If your domain is on Cloudflare, this record must be set to DNS only. Proxying it through Cloudflare breaks the measurement endpoint. Click the orange cloud so it turns grey.

What it does, and what it does not do

What it does. It points a subdomain at a measurement endpoint so that analytics and advertising data is collected from your own domain rather than from a third-party one. Browsers and ad blockers increasingly discard third-party measurement, which is why the industry has moved to this pattern.

What it does not do:

  • It does not affect your website or the www hostname. The site is untouched.
  • It does not affect email. No MX, SPF, DKIM, or DMARC record is being changed, added, or removed. Mail delivery and deliverability are unaffected.
  • It does not create a mailbox. The subdomain cannot send or receive email.
  • It does not give anyone access to your DNS, your hosting, or your registrar.
  • It is not a redirect and does not appear anywhere a visitor will see.

Three questions you are probably about to ask

Is this a security risk?
The subdomain resolves to a managed measurement endpoint that accepts analytics requests and forwards them to Google. It serves no content, hosts no application, and has no access to your infrastructure. The one legitimate consideration with any CNAME to a third party is that the third party controls what is served there, which is why it points at a named, contracted vendor rather than an anonymous host, and why removing the record removes the delegation completely and immediately.

Does this affect email deliverability?
No. Deliverability is governed by MX, SPF, DKIM, and DMARC records. None of them are being touched. Adding a subdomain CNAME has no bearing on any of them.

What if we want to remove it later?
Delete the record. That is the whole reversal. Nothing else in the zone depends on it, nothing else breaks, and no cleanup is required elsewhere. Measurement stops resolving through the subdomain and reverts to the standard browser-based method.

Where the setting lives, by provider

ProviderPath
CloudflareSelect the domain → DNSRecordsAdd record → Type CNAME → remember to set Proxy status to DNS only
GoDaddyMy Products → domain → DNSAdd New Record → Type CNAME
NamecheapDomain ListManageAdvanced DNSAdd New RecordCNAME Record
Network SolutionsManage AccountDomain NamesManageAdvanced DNSCNAMEAdd
Squarespace DomainsDomain → DNSCustom recordsAdd record
Route 53Hosted zone for your domain → Create record → Record type CNAME
Managed by your web hostThe record still needs to be added at whichever nameservers the domain currently points to. If you are unsure which those are, tell us and we will check and send you the answer.

Confirming it is done

Reply with a screenshot of the saved record, or just reply "done" with the time you saved it. Propagation is usually minutes but can take up to a few hours, and we will verify from our side before relying on it.

If anything about this request does not look right to you, please say so rather than working around it. A brief conversation now is much cheaper than a change made on an assumption.


Questions about anything on this page: admin@laurenmilligan.pro

Back to all guides