Custom Track Domain

Prev Next

A custom track domain is a subdomain of your own website domain, for example data.exampleshop.com, through which Mapp Intelligence receives your tracking requests. Because the requests go to your own domain instead of a Mapp domain, fewer of them are blocked by ad blockers and browser tracking protection. This improves the completeness of your data.

This article explains how to choose the right DNS record type and how to set up the custom track domain together with Mapp.

Choose a DNS Record Type

You connect your custom track domain to Mapp with an entry at your DNS service provider. There are two options:

  • A/AAAA-Record: Your track domain points directly to the IP addresses (IPv4 and IPv6) of the Mapp tracking server

  • CNAME: Your track domain points to a Mapp domain, which then resolves to the Mapp tracking server.

Everything else in the setup is identical for both options, including the SSL certificate.

Recommendation

Mapp recommends the A/AAAA-Record. Some tracking blockers resolve the DNS entry of a track domain and compare a CNAME target with their block lists. With a CNAME, they find the Mapp domain and block the request. With an A/AAAA-Record, no Mapp domain appears in the DNS response.

A/AAAA-Record

CNAME

Points to

IP addresses (IPv4 and IPv6) of the Mapp tracking server

Mapp domain

Mapp domain visible in DNS

No

Yes

Protection against tracking blockers that check CNAME targets

Yes

No

Browser cookie restrictions (for example, Safari ITP)

Apply to both options in the same way. See Intelligent Tracking Prevention (ITP).

Maintenance

If Mapp ever changes the server IP addresses, you must update the A- and AAAA-Records.

No DNS changes needed on your side.

Already using a CNAME? See Switching Your Custom Track Domain from CNAME to A-Record.

Check Which Record Type a Track Domain Uses

Run nslookup with your track domain in a terminal or command prompt, for example nslookup data.exampleshop.com.

CNAME: The response contains a canonical name line with a Mapp domain.

Non-authoritative answer:
data.exampleshop.com    canonical name = 123456789012345.wt-eu02.net.
Name:    123456789012345.wt-eu02.net
Address: 203.0.113.10

A/AAAA-Record: The response contains only your track domain and its IP addresses: the IPv4 address from the A-Record and the IPv6 address from the AAAA-Record. There is no canonical name line.

Non-authoritative answer:
Name:    data.exampleshop.com
Address: 203.0.113.10
Name:    data.exampleshop.com
Address: 2001:db8::10

If the response shows only an IPv4 address, the AAAA-Record is missing.

Before You Start

Make sure you have the following:

  • Access to the DNS settings of your website domain, or a contact in your IT department who has it.

  • Access to your tracking configuration (Smart Pixel, Tag Integration, mobile SDK, or server-side integration).

You do not need to buy or provide an SSL certificate. Mapp orders the certificate for your track domain and renews it automatically.

The setup is always done together with your Mapp contact. Start by contacting your Customer Success Manager or consultant.

Set Up the Custom Track Domain

Subdomain already delegated to Mapp?

If you have delegated a subdomain to Mapp, for example for Mapp Engage (see Delegate a Domain), Mapp can set up the track domain within that subdomain for you, including the DNS entries and the certificate. In this case, you only need to agree on the track domain name with your Mapp contact (step 1), update your tracking configuration (step 6), and verify the result (step 7).

Step 1: Agree on the Track Domain Name (You and Mapp)

Together with your Mapp contact, choose a subdomain of your website domain.

Scenario

Recommendation

Example

One website domain

Use a subdomain of your website domain.

Website: exampleshop.com
Track domain: data.exampleshop.com

Several website domains (cross-domain tracking)

Use a subdomain of the website domain with the most visitors.

Websites: exampleshop.com (100,000 visitors per month), exampleshop.de and exampleshop.fr (80,000 each)
Track domain: data.exampleshop.com

Your system administrator must confirm that the subdomain is not already in use.

Tip: Avoid names that tracking blockers look for, such as track, tracking, analytics, stats, or pixel. A neutral name such as data is less likely to be blocked.

Step 2: Provide Your Company Data for the Certificate (You)

Mapp needs the following data to order the SSL certificate for your track domain:

  • Organization (legal company name)

  • City

  • State or region (for Germany, the federal state)

  • Country code, for example DE or FR

Own certificate: If your company policy requires you to manage the certificate yourself, tell your Mapp contact before the setup starts. You then provide the certificate to Mapp and are responsible for renewing it in time.

Step 3: Receive the DNS Entries (Mapp)

Your Mapp contact sends you the DNS entries to create:

  • A/AAAA-Record: the IPv4 address (for the A-Record) and the IPv6 address (for the AAAA-Record) of the Mapp tracking server

  • CNAME: the Mapp domain

Step 4: Create the DNS Entries (You)

Create the entries for your track domain with your DNS service provider.

A/AAAA-Record: Create the A-Record. We strongly recommend also creating the AAAA-Record. Without it, visitors who connect via IPv6 only cannot reach your track domain.

data.exampleshop.com.    3600    IN    A        <IPv4 address provided by Mapp>
data.exampleshop.com.    3600    IN    AAAA     <IPv6 address provided by Mapp>

CNAME:

data.exampleshop.com.    3600    IN    CNAME    <Mapp domain provided by Mapp>.

Use exactly the addresses or the Mapp domain you received from Mapp. An incorrect entry means that no tracking request reaches Mapp.

A hostname can have either A/AAAA-Records or a CNAME, not both. If other records already exist for the subdomain, remove them first.

CAA records: If your domain uses CAA records to restrict which certificate authorities may issue certificates, the certificate authority used by Mapp must be allowed for the track domain. Your Mapp contact tells you which one to allow. You can skip this if it is already allowed for your main domain. Example:

data.exampleshop.com.    3600    IN    CAA      0 issue "digicert.com"

Inform your Mapp contact when the entries are in place.

Step 5: Set Up the Certificate (Mapp)

As soon as your track domain points to Mapp, Mapp orders the SSL certificate, installs it on the tracking servers, and sets up monitoring for your track domain. The certificate authority verifies the domain through your new DNS entry, so this step can only start after step 4.

Your Mapp contact confirms when your track domain is ready.

To check the DNS entry yourself, run nslookup for your track domain as described in Check Which Record Type a Track Domain Uses above. The response must show the addresses or Mapp domain you received in step 3.

Step 6: Update Your Tracking Configuration (You)

Replace the current track domain with your custom track domain wherever it is configured.

Only do this after Mapp has confirmed that your track domain is ready. Requests to a track domain without a valid certificate are lost.

Integration

Where to change the track domain

Smart Pixel

In the tracking configuration, see Installation.

Pixel Version 4/5

In the JavaScript file or the global configuration: trackDomain: "data.exampleshop.com"

Mapp Tag Integration

In the configuration of the Mapp Intelligence plugin.

Mobile SDKs

In the SDK initialization. The change reaches users with the next app update.

Server-side integrations

In the track domain setting of the respective library or tag.

Step 7: Verify the Tracking (You)

Check that tracking requests reach Mapp through your custom track domain:

  1. Open your website and the developer tools of your browser, then go to the Network tab.

  2. Reload the page and filter the requests by your track domain, for example data.exampleshop.com.

  3. Check that the tracking requests go to your custom track domain and complete without errors, for example without a certificate error.

  4. Optionally, check the requests in detail with the Mapp Cloud Debugger.

  5. Check that the data appears in Mapp Intelligence. This can take some time.

For mobile apps, check the requests with the debugging options of the SDK.

Keep Existing Visitor IDs

Whether you need to act depends on how your tracking sets cookies:

  • First-party cookies (set by your website): not affected by the change of the track domain.

  • Third-party cookies (set by the track domain): tied to the previous track domain. Use the Cookie Control Plugin to migrate them to the new track domain.

If you use third-party cookies and do not migrate them, all visitors receive new visitor IDs. Their first visit after the change is counted as a new visit, which distorts the metrics for new and returning visitors.

Maintenance

  • Certificate: Mapp monitors the SSL certificate and renews it automatically for as long as you use the track domain. If you provide your own certificate, you must renew it and send the new certificate to Mapp before the old one expires.

  • A/AAAA-Record: Mapp does not plan to change the IP addresses of its tracking servers. If this ever becomes necessary, you must update your A- and AAAA-Records, otherwise tracking requests no longer reach Mapp.

Troubleshooting

Problem

Possible cause

Solution

Mapp cannot complete the certificate setup.

The DNS entry is not active yet, or a CAA record does not allow the certificate authority used by Mapp.

Check the DNS entry with nslookup. Check your CAA records (see step 4).

No tracking requests reach Mapp after the change.

The DNS entry contains a wrong address, or the tracking configuration was changed before Mapp confirmed the track domain.

Compare the DNS entry with the values from Mapp. If needed, switch the tracking configuration back until the track domain is ready.

Some visitors are not tracked.

The AAAA-Record is missing, so visitors who connect via IPv6 only cannot reach the track domain.

Create the AAAA-Record (see step 4).

The browser shows a certificate error for the track domain.

The certificate is not installed yet, or your own certificate has expired.

Wait for the confirmation from Mapp. If you provide your own certificate, send a renewed certificate to Mapp.

Requests are still blocked.

The track domain uses a CNAME, its name is already on block lists, or it contains a typical tracking term.

Switch to an A/AAAA-Record or to a new subdomain, see Switching Your Custom Track Domain from CNAME to A-Record. Also consider request obfuscation in the tracking pixel.

Many returning visitors appear as new visitors.

Third-party cookies were not migrated to the new track domain.

See Keep Existing Visitor IDs above.

FAQ

Do I need to buy an SSL certificate?

No. Mapp orders the certificate for your track domain and renews it automatically. You only provide your company data (see step 2).

Can I use my own certificate?

Yes, if your company policy requires it. Tell your Mapp contact before the setup starts. You are then responsible for renewing the certificate and sending it to Mapp before it expires.

What happens if I change or delete the DNS entry?

Tracking requests no longer reach Mapp. In addition, Mapp can no longer renew the certificate, because the renewal verifies your domain through this DNS entry. Always coordinate changes with your Mapp contact.

What happens when I stop using the track domain?

Tell your Mapp contact. Mapp removes the track domain from its servers and stops renewing the certificate. Then delete the DNS entries with your DNS service provider.

Can I switch from CNAME to A/AAAA-Record later?

Can I use a custom track domain for mobile apps?

Yes. Set the custom track domain in the SDK initialization. The change reaches users with the next app update.

Switching Your Custom Track Domain from CNAME to A-Record
Cookie Control Plugin
Intelligent Tracking Prevention (ITP) 2.1
Mapp Tag Integration