Custom domains. Your brand, your domain, our edge.
Apex, subdomain, or wildcard. TLS issued automatically by Caddy on-demand, no manual cert renewal. Wildcard subdomains let multi-tenant tools mint per-customer hostnames without DNS changes per launch.
- Apex, subdomain, or wildcard — all supported
- TLS issued automatically by Caddy on-demand
- DNS verification in under 30 seconds
- Propagated to 3 edge POPs worldwide
Zero-config TLS
Cert issued in under 60 seconds. Renewed forever.
Caddy on-demand TLS checks our domain-manager service to confirm the hostname is allowed, then requests a Let’s Encrypt certificate via ACME — automatically, on the first request. Renewal happens 30 days before expiry. You never touch a cert file.
- Step 1
Domain added
CNAME setYou point your subdomain CNAME at edge.elido.me in your DNS provider.
t=0 - Step 2
DNS verified
< 30sElido polls the CNAME every 30s. Once it resolves, domain-manager marks the hostname as allowed.
t=30s - Step 3
TLS issued
< 2 minCaddy on-demand TLS requests a Let's Encrypt cert via ACME. Certificate issued automatically.
t=90s - Step 4
Live on edge
3 POPs activeYour custom domain is live across Frankfurt, Ashburn, and Singapore. Zero manual steps.
t=120s
Domain management
Manage all your domains in one place
The dashboard polls your CNAME every 30 seconds during the verification window. Once DNS resolves, Caddy picks it up and issues the cert — no manual step, no support ticket.
- Subdomain (CNAME)go.yourcompany.com → edge.elido.me
- Apex (ALIAS/ANAME)yourcompany.com via Route 53 or Cloudflare
- Wildcard (Business)*.go.yourcompany.com — one claim, all subdomains
- Deep-link manifestsapple-app-site-association auto-served
- Auto-renewalCaddy renews 30 days before expiry
- Verifiedlinks.acme.comCNAME · subdomain
- Pending DNSgo.startup.ioCNAME · subdomain
- Wildcard active*.links.agency.comWildcard · DNS-01
- Failedredir.corp.netALIAS · apex
Global edge propagation
One domain. Three continents.
Your custom domain is provisioned across all three of Elido’s edge POPs — Frankfurt, Ashburn, and Singapore — in under 90 seconds. Anycast routes each visitor to the nearest POP automatically.
DNS anycast routes each visitor to the nearest POP automatically. Your domain doesn’t need a separate DNS entry per region.
What you can do
- Apex, subdomain, and wildcard support
- On-demand TLS (Let's Encrypt)
- Apple Universal Links + Android App Links manifests
- Tier-isolated redirect fleets (free / paid / business)
- Premium domain marketplace
What custom domains actually require to work in production
Pointing a domain at a shortener sounds simple. The edge cases below are where most implementations break and what Elido handles automatically.
Caddy on-demand TLS: cert issued on first request, renewed automatically
Elido uses Caddy's on-demand TLS to issue and renew certificates for custom domains. When a domain is first claimed and a request hits the edge, Caddy checks the domain-manager service to verify the hostname is allowed, then requests a Let's Encrypt certificate via ACME. Issuance typically takes under 60 seconds. There is no 'wait 24 hours for your cert' step. Renewal happens automatically 30 days before expiry; Elido manages this entirely. The domain-manager service is the source of truth for which hostnames are allowed — it's the guard that prevents other Elido customers from claiming your domain on the shared edge. To claim a domain, you point a CNAME at the Elido edge and verify ownership via the dashboard; the domain-manager service confirms the CNAME is in place before issuing the cert.
Apex, subdomain, and wildcard — each with different DNS requirements
Subdomain (go.yourcompany.com): CNAME to the Elido edge. Straightforward, works everywhere. Apex domain (yourcompany.com): CNAME at apex is not universally supported by DNS providers; use an ALIAS / ANAME record (supported by Route 53, Cloudflare, DNSimple) or configure Cloudflare proxy mode. Elido's DNS verification accepts either approach. Wildcard (*.go.yourcompany.com): Business only. One wildcard claim covers all subdomains of the pattern — useful for multi-tenant SaaS tools that mint per-customer short domains (customer1.go.yourcompany.com, customer2.go.yourcompany.com) without a DNS change per new customer. Wildcard certs are issued via Let's Encrypt DNS-01 challenge, which requires DNS API access; Elido handles this in the domain-manager service automatically if your DNS is managed via Cloudflare or Route 53 (other providers on request).
apple-app-site-association and assetlinks.json served automatically from your domain
For custom domains used for mobile deep links, Elido serves the apple-app-site-association file at /.well-known/apple-app-site-association and the assetlinks.json at /.well-known/assetlinks.json automatically. You configure your app's bundle ID (iOS) and package name + SHA-256 certificate fingerprint (Android) in domain settings; Elido builds and serves the JSON files at the correct paths. iOS App Clip associations are also supported in the apple-app-site-association if you configure an App Clip target. The files are served with the correct Content-Type headers and cache-control (no-cache, since iOS and Android check them on every launch). If your app team validates Universal Links using the WWDC-recommended aasa-validator tool, it should pass without any additional configuration on your side.
Free, paid, and business traffic on separate redirect fleets
Elido's redirect infrastructure is tier-isolated: free-tier links serve from f.elido.me's fleet, paid-tier links from s.elido.me's fleet, and Business from b.elido.me's fleet. Custom domains route to the tier-appropriate fleet based on the workspace's plan. This means a noisy free-tier neighbor can't degrade redirect latency for Business customers. For custom domains, the practical effect is that a Business workspace with a custom domain (go.yourcompany.com) is on the same isolated fleet as other Business workspaces — not on the shared free-tier edge. Fleet isolation also means Business custom domains can have a dedicated IP range, which matters for organizations that need to allowlist Elido IPs in their network security rules.
Premium short domains available in the dashboard — no domain registrar needed
The Elido domain marketplace lists premium short domains you can add to your workspace without a separate domain registrar. These are Elido-owned domains with short, brand-friendly patterns available to Pro and Business workspaces on a rental basis. Domain marketplace domains are not transferable to another registrar — you rent access, not ownership. The marketplace is small and growing; if you have a specific premium domain in mind that isn't listed, the right path is to register it yourself and claim it via CNAME. Marketplace domains are useful when your company hasn't invested in a short domain yet and you want something nicer than a shared Elido domain immediately.
Teams running custom domains on Elido
Names are placeholders for now — real customer names land here as case studies are published.
“We moved from a generic bit.ly shortener to go.ourcompany.com in an afternoon. The cert was issued in about 45 seconds after the CNAME propagated. Previously our IT team managed a separate redirect service — we deleted it.”
“Wildcard subdomain support on Business means we mint per-client short domains without a DNS change per launch. We set the wildcard once; each client gets client-name.links.agency.com automatically.”
“apple-app-site-association served automatically from our custom domain was the feature that moved the decision. Our iOS team had been maintaining that file manually; Elido generates it from the domain settings and keeps it current.”
Elido custom domains vs Bitly Custom Domain vs Rebrandly
All three support custom domains. The differences are in wildcard support, TLS issuance speed, and what you can configure per domain.
| Feature | Elido | Bitly Custom Domain | Rebrandly |
|---|---|---|---|
| TLS issuance | Caddy on-demand — <60s, no manual step | Managed — typically under 24h | Managed — under 24h |
| Apex domain support | ALIAS/ANAME or Cloudflare proxy | Supported | Supported |
| Wildcard subdomains | Business — one claim covers all subdomains | Not available | Enterprise only |
| Deep-link manifests | Auto-generated from domain settings | Manual configuration | Supported on Business |
| Custom domains on Pro | 1 domain on Pro (€9/mo) | Add-on above base price | 1 on entry plan ($29/mo) |
| Domains on Business | 5 + wildcard | 5 | 5 on mid tier |
| Tier-isolated redirect fleet | Yes — free/paid/business isolated | Shared edge | Shared edge |
| Domain marketplace | Growing catalog of premium short domains | Not available | Not available |
Custom domain questions
What DNS record do I need to add?
For subdomains (go.yourcompany.com): a CNAME record pointing at the Elido edge hostname shown in domain settings. For apex domains (yourcompany.com): an ALIAS or ANAME record (Route 53 alias, Cloudflare CNAME flattening, or DNSimple ALIAS). Standard CNAME at apex is not valid DNS; if your DNS provider doesn't support ALIAS/ANAME, use a subdomain. The domain settings screen shows the exact target hostname and a verification checker.
How long does DNS verification take?
DNS propagation depends on your DNS provider's TTL and the resolver caching. Typical range: 1–30 minutes with modern DNS providers. Cloudflare is usually under 5 minutes. Elido checks the CNAME every 30 seconds during the verification window; the dashboard shows live verification status. If verification hasn't passed in 2 hours, double-check the record type and target — the most common issue is adding a CNAME at apex where the DNS provider requires ALIAS.
Do you support wildcard subdomains for multi-tenant SaaS tools?
Yes, on Business. One wildcard claim (*.go.yourcompany.com) covers all subdomains of that pattern. You don't need a separate DNS record or CNAME per customer subdomain — the wildcard DNS entry and cert cover them all. The edge routes requests for any matching hostname to your workspace's redirect fleet. New customer subdomains go live as soon as their short links are created; no additional setup per customer.
Can I use my custom domain for both short links and deep links?
Yes — that's the intended setup. The same custom domain handles short-link redirects (via the edge) and serves the apple-app-site-association and assetlinks.json files at the well-known paths. iOS and Android check those paths against your app's bundle ID; Elido generates the files from your domain settings. No separate hosting for the manifest files is required.
What happens to my links if I remove the custom domain?
Links on a removed domain still exist in your workspace. They fall back to Elido's shared domain (s.elido.me for Pro, b.elido.me for Business) until you either reassign them to a new custom domain or delete them. There's no automatic 404 on removal; we give a 30-day grace period where the old domain still resolves, then it stops being claimed by Elido's edge. Remove domains deliberately; don't let them lapse without updating existing links.
Is there a limit on the number of links per custom domain?
No limit on links per domain. You can have 1,000,000 short links on a single custom domain. The limit is on the number of custom domains per workspace (1 on Pro, 5 + wildcard on Business), not on links per domain.
Can different workspaces share the same custom domain?
No. A domain is claimed by one workspace. Once claimed, no other workspace can claim the same hostname. If you need two teams to use the same short domain, they need to be in the same workspace (or use subdomains of the same domain in separate workspaces).
Do you support HTTP-to-HTTPS redirects on custom domains?
Yes — Caddy handles HTTP → HTTPS redirect automatically on all custom domains. HTTP requests are redirected to HTTPS with a 301. There's no configuration needed. Plain HTTP short links in the wild (printed, emailed, etc.) automatically upgrade to HTTPS on the redirect.
Keep reading
Universal Links and App Links manifests — how your custom domain serves them automatically.
Custom portal hostnames for the dashboard — different from short-link domains but uses the same TLS stack.
How agencies use wildcard subdomains to mint per-client short domains without per-launch DNS changes.
Routing rules that run on top of your custom domain — geo, device, time, and more.