Tracking · First-party domain

First-party tracking domain: serve the pixel from your own subdomain

Out of the box, the Admaxxer pixel loads from admaxxer.com and sends its events there. A first-party tracking domain moves both onto a subdomain you own, such as t.yourbrand.com, so blockers that filter known analytics domains don't recognise it. You add one CNAME record; Admaxxer checks it and takes care of the HTTPS certificate.

One DNS record · HTTPS handled for you · Included in every plan

What changes when you use your own subdomain

With the standard install, the pixel script loads from https://admaxxer.com/js/script.js and sends events to https://admaxxer.com. With a tracking domain, the snippet loads https://t.yourbrand.com/pixel.js, and its data-proxy-origin attribute tells the pixel to send every request (events, batched events and identify calls) to the same subdomain.

Prefer to run your own proxy?

If you'd rather forward pixel traffic through infrastructure you already run, follow one of the self-hosted proxy guides instead: Cloudflare, NGINX, Vercel, Next.js, Netlify, Nuxt, Apache or WordPress. A tracking domain needs no server work on your side.

Before you start

Set it up

  1. Open Integrations and scroll to First-party tracking domain. Click Add a domain (or Add another if you already have one).
  2. Type your subdomain, for example t.yourbrand.com, in Subdomain. If you have more than one pixel site, choose it under Pixel site. Click Add domain. The new row shows Verifying DNS… and the exact record to create.
  3. At your DNS provider, create the CNAME record shown in the table below. On Cloudflare, set the record to DNS only.
  4. Wait for the row to turn Live. Admaxxer checks pending domains automatically every few minutes, and the panel refreshes itself while it's open. Click Re-check now to check straight away after you change DNS.
  5. Under Updated pixel snippet, click Copy snippet and replace your existing Admaxxer snippet with it.
  6. Open your site with your browser's developer tools on the Network tab: pixel.js should load from your subdomain. Then open Dashboard → Pixel: the Live Visitors card counts pageviews from the last five minutes.
The DNS record to add (the panel shows the same values with a copy button).
FieldValueNotes
TypeCNAME—
Namet.yourbrand.comThe panel shows your full subdomain. Some providers, including Cloudflare and Vercel DNS, want only the part before your domain, such as t.
Value / Targettracking-edge.admaxxer.comExactly this: no https://, no path. Point the record straight at it, not at another record that points to it.
TTL300 or AutomaticA short TTL makes later changes take effect sooner.
Proxy (Cloudflare)DNS onlyA proxied record hides the CNAME, so Admaxxer can't see it to verify the domain.

What the updated snippet looks like

<script async
  src="https://t.yourbrand.com/pixel.js"
  data-website-id="admx_YOUR_WEBSITE_ID"
  data-proxy-origin="https://t.yourbrand.com">
</script>

Always copy the snippet from the panel rather than typing it: it already contains your website ID and subdomain. The only differences from the standard snippet are where the script loads from and the data-proxy-origin attribute.

What the statuses mean

What you seeWhat it meansWhat to do
Verifying DNS… with Awaiting first DNS lookupThe domain was added and hasn't been checked yet.Nothing. The first check runs shortly.
We don't see any CNAME record at this hostname yet…No CNAME record was found for the subdomain.Create the record, or check the name for typos and that Cloudflare is set to DNS only. New records can take a few minutes to appear.
Your CNAME currently points at …, but we need …A CNAME exists but points somewhere else.Change the record's value to tracking-edge.admaxxer.com.
LiveThe CNAME points at Admaxxer and the domain is verified.Copy the updated snippet and install it.

HTTPS is handled for you

There's no certificate to buy, upload or renew. Once a domain is Live, the first HTTPS request to it gets a certificate issued automatically, and it's renewed for you after that. That first request can take a moment longer while the certificate is issued. Certificates are only issued for domains that have been verified in an Admaxxer workspace.

Troubleshooting

Stuck on Verifying DNS

The panel won't accept the domain

Live, but the snippet doesn't load or send

If your site sends a Content Security Policy, allow your tracking subdomain in both script-src and connect-src. 'self' doesn't cover other subdomains. See Fix Content Security Policy errors.

Removing a tracking domain

  1. Put the standard snippet back on your site first. The tracking-domain snippet stops working once the subdomain no longer reaches Admaxxer.
  2. In the First-party tracking domain panel, click Remove on the domain.
  3. Delete the CNAME record at your DNS provider.

Removing the domain in Admaxxer stops us from issuing new certificates for it. Deleting the CNAME is what stops traffic reaching the subdomain, so do both.

Frequently asked questions

Q: Will I lose data when I switch to the tracking-domain snippet?

No. The snippet keeps the same website ID, so events keep landing in the same site. Visitor identifiers live on your website's own domain, so returning visitors are still recognised after the switch.

Q: Can I use my root domain instead of a subdomain?

No. The panel only accepts subdomains. DNS doesn't allow a CNAME on a root domain, and pointing your root domain at Admaxxer would take your main site offline.

Q: Do I need to buy or install an SSL certificate?

No. The certificate for your tracking subdomain is issued automatically once the domain is verified, and renewed for you.

Q: Can I have more than one tracking domain?

Yes. You can add a tracking domain for each pixel site, up to a per-workspace limit. A subdomain can be active in only one workspace at a time.

Q: I use a different pixel variant, such as the cookieless or Plus script. What do I change?

The panel's snippet loads the standard pixel. To keep your variant, keep its file path, for example /js/script.cookieless.js, swap admaxxer.com for your tracking subdomain, and add the same data-proxy-origin attribute the panel's snippet uses.