Guides
Domain Protection
Restrict which domains can load your deployed scripts.
Domain protection limits script execution to approved domains. Scripts loaded from unapproved domains are blocked.
Enable Domain Protection
- Open the Domains icon in the left activity bar.
- Turn on Domain protection.
- Add domains individually. Wildcard patterns are supported (e.g.,
*.example.com). localhostis always allowed regardless of the domain list.
Any host configured under Staging Domains is also allowed, whether or not it appears in this list.
Propagation
Changes take approximately 60 seconds to apply. Domain rules are stored in Cloudflare KV and checked at the edge.
Plan Requirement
Domain protection requires the Beta, Individual, or Team plan. Free plan users see an upgrade prompt. See Plans and Limits.
Troubleshooting
If your script is blocked unexpectedly, verify:
- The domain is in the allowed list (check for typos).
- Wildcard patterns match the full domain.
- Wait 60 seconds after adding a domain for propagation.