Custom Domains
Connecting a custom domain to your Helmdesk instance
Point your own subdomain at your client portal, with automatic HTTPS.
By default, your client portal lives at {your-tenant-slug}.helmdesk.ca. This guide walks through
replacing that with your own domain — for example, support.youritcompany.com — so clients never
see the Helmdesk domain at all.
Before you start
You'll need access to your domain's DNS settings (wherever you manage records for
youritcompany.com — Cloudflare, GoDaddy, Route 53, whichever registrar or DNS host you use).
Step 1: Add the domain in Helmdesk
From Settings → Domains, add the domain you want to use. Helmdesk looks at the shape of what you enter and picks the right verification method automatically:
- A subdomain (like
support.youritcompany.com) uses a CNAME record. - A bare/apex domain (like
youritcompany.comwith no subdomain) uses a TXT record instead — apex domains can't carry a CNAME at their root, that's a DNS-level limitation, not a Helmdesk one.
Helmdesk shows you the exact record to add either way.
Step 2: Add the DNS record
For a subdomain (CNAME): point it at tenants.helmdesk.ca — the one shared address every
customer's custom domain resolves through.
Type: CNAME
Name: support
Value: tenants.helmdesk.ca
For an apex domain (TXT): add a TXT record at _helmdesk-verify.youritcompany.com containing
the verification token Helmdesk shows you.
DNS changes can take anywhere from a few minutes to a few hours to propagate, depending on your provider and the record's TTL.
Step 3: Verify
Back in Settings → Domains, click Verify. Helmdesk checks the DNS record immediately, and also re-checks automatically every few minutes in the background — so even if you click Verify too early, a domain that's still propagating will pick up and finish on its own without you needing to come back and click anything again.
What "active" means
Once verified, your domain moves to an active state and HTTPS is provisioned for it automatically — there's no certificate file to generate or upload yourself.
If something goes wrong
A domain that fails verification or is only partially set up never blocks your team — your portal
stays fully reachable at your default {your-tenant-slug}.helmdesk.ca address the entire time, so
a DNS mistake on your end is never something your clients notice as downtime.