Custom Domain Playbook
Use this playbook for custom domain verification failures, SSL provisioning delays, routing issues, and domain takeover concerns.
Evidence to collect
Collect tenant ID, configured hostname, domain purpose, DNS provider, visible error, DNS screenshots, expected CNAME or TXT values, and time since records were changed.
Check common failures
Check for wrong DNS zone, extra protocol or path, conflicting A or AAAA records, stale CNAME target, missing verification token, unsupported root/apex setup, and propagation delay.
Routing checks
Confirm the domain belongs to the tenant, the workspace has entitlement, the purpose matches record/share routing expectations, and SSL provisioning is not still pending.
Takeover concern
If a domain appears attached to the wrong tenant or a customer claims unauthorized domain use, escalate. Do not manually reassign the domain without approval and before/after audit capture.
Customer reply shape
Give the exact DNS issue when known. If propagation is likely, ask the customer to wait and recheck. Do not expose internal routing tables or tenant identifiers in customer-facing text.