Adding the CNAME record for server-side tracking
- For
- Whoever administers DNS for your domain
- The change
- One
CNAMErecord - Time required
- About two minutes, plus propagation
- Reversible
- Yes, completely. Delete the record.
What this is, in two sentences
Server-side measurement runs through a subdomain of your own domain, which requires one CNAME record to be added. That is the entire request.
The record
| Field | Value |
|---|---|
| Type | CNAME |
| Host / Name | sst (some panels want the fully qualified name, see the note below) |
| Value / Target / Points to | Supplied with the request, once the measurement container is provisioned |
| TTL | Automatic, or 3600 |
| Proxy status (Cloudflare only) | DNS only, proxy OFF (grey cloud) |
The target hostname is issued when the measurement container is provisioned and will be supplied alongside this request. If you have this page but no real hostname to point at, ask before making any change.
On the Host field. Registrars differ. Some want just the subdomain label, sst. Others want the fully qualified name, sst.yourdomain.com. If you enter sst and the panel displays sst.yourdomain.com afterwards, that is correct. If you enter the full name and it saves as sst.yourdomain.com.yourdomain.com, that is wrong. Remove it and enter sst alone.
On the Cloudflare proxy. If your domain is on Cloudflare, this record must be set to DNS only. Proxying it through Cloudflare breaks the measurement endpoint. Click the orange cloud so it turns grey.
What it does, and what it does not do
What it does. It points a subdomain at a measurement endpoint so that analytics and advertising data is collected from your own domain rather than from a third-party one. Browsers and ad blockers increasingly discard third-party measurement, which is why the industry has moved to this pattern.
What it does not do:
- It does not affect your website or the www hostname. The site is untouched.
- It does not affect email. No MX, SPF, DKIM, or DMARC record is being changed, added, or removed. Mail delivery and deliverability are unaffected.
- It does not create a mailbox. The subdomain cannot send or receive email.
- It does not give anyone access to your DNS, your hosting, or your registrar.
- It is not a redirect and does not appear anywhere a visitor will see.
Three questions you are probably about to ask
Is this a security risk?
The subdomain resolves to a managed measurement endpoint that accepts analytics requests and forwards them to Google. It serves no content, hosts no application, and has no access to your infrastructure. The one legitimate consideration with any CNAME to a third party is that the third party controls what is served there, which is why it points at a named, contracted vendor rather than an anonymous host, and why removing the record removes the delegation completely and immediately.
Does this affect email deliverability?
No. Deliverability is governed by MX, SPF, DKIM, and DMARC records. None of them are being touched. Adding a subdomain CNAME has no bearing on any of them.
What if we want to remove it later?
Delete the record. That is the whole reversal. Nothing else in the zone depends on it, nothing else breaks, and no cleanup is required elsewhere. Measurement stops resolving through the subdomain and reverts to the standard browser-based method.
Where the setting lives, by provider
| Provider | Path |
|---|---|
| Cloudflare | Select the domain → DNS → Records → Add record → Type CNAME → remember to set Proxy status to DNS only |
| GoDaddy | My Products → domain → DNS → Add New Record → Type CNAME |
| Namecheap | Domain List → Manage → Advanced DNS → Add New Record → CNAME Record |
| Network Solutions | Manage Account → Domain Names → Manage → Advanced DNS → CNAME → Add |
| Squarespace Domains | Domain → DNS → Custom records → Add record |
| Route 53 | Hosted zone for your domain → Create record → Record type CNAME |
| Managed by your web host | The record still needs to be added at whichever nameservers the domain currently points to. If you are unsure which those are, tell us and we will check and send you the answer. |
Confirming it is done
Reply with a screenshot of the saved record, or just reply "done" with the time you saved it. Propagation is usually minutes but can take up to a few hours, and we will verify from our side before relying on it.
If anything about this request does not look right to you, please say so rather than working around it. A brief conversation now is much cheaper than a change made on an assumption.
Questions about anything on this page: admin@laurenmilligan.pro