Skip to main content

Organisation administration · Public

Manage enterprise domains

Add, verify, select, and retire the domains that define an enterprise tenant namespace and member email addresses.

Enterprise domains are the verified internet domains an organisation controls inside ONE. They replace the old single email domain field. A tenant can have several domains, but exactly one is always the primary domain. The primary domain is the tenant namespace shown during enterprise setup and used as the default domain for new member addresses.

Domain management is available in IAM → Organisation → Domains. Members need the domains:manage permission, or a wildcard permission that includes it.

What domains are used for

ONE uses verified tenant domains in four places:

Area Behaviour
Enterprise setup The account creator's email domain is required, verified, and stored as the first primary tenant domain. It is called the tenant namespace, not the email domain.
Sign-in routing Each verified domain has its own lookup by email setting. When it is enabled for a domain, addresses on that domain are blocked from direct consumer-style sign-in and routed through the enterprise sign-in flow.
Member and invite emails Member creation, member editing, invites, and account security email changes require a local part and a separate verified-domain dropdown.
Managed-domain protection A verified domain prevents users outside the tenant from creating or changing an account to an address on that domain.

Add a domain

  1. Open IAM → Organisation → Domains.
  2. Enter the domain without a protocol, for example example.com.
  3. Choose Add domain.
  4. Review the available verification methods.

ONE normalises domains to lowercase and removes protocols or trailing slashes. A domain can be added only once per tenant.

New domains inherit the organisation's default lookup by email setting. You can change lookup by email individually for each domain after it has been added.

Verification methods

Every root domain must be verified before it can be used for member emails or made primary. ONE shows the available verification methods after the domain is added. Choose one method to complete verification.

Whois is not always available. Registrars may redact contact details, privacy services may hide the registrant, and some TLDs do not expose useful administrative contacts. When Whois is unavailable or redacted, use TXT verification.

Method When available What ONE stores
TXT record at domain root Always available A skyfallen-domain-verification=... TXT value and the root record name.
Whois email code Available only when a registrant or administrative contact email can be found The Whois contact email and the generated code sent to that address.

Subdomains

Subdomains of a verified domain inherit verification. For example, if example.com is verified, engineering.example.com can be added without a new verification challenge. ONE records the inherited parent in domain metadata and marks the subdomain verified.

This inheritance works only inside the same tenant. A verified domain on one tenant does not allow another tenant to add its subdomains.

Primary domain

The primary domain is the tenant namespace. During enterprise setup, it must match the domain of the account creator's email address.

You can make another verified domain primary from the Domains page. When changing the primary domain, you can also choose the option to update existing users from the old primary domain to the new primary domain. Only users whose current email address used the old primary domain are changed; users on other verified domains stay as they are.

Delete a domain

The primary domain cannot be deleted. Make another verified domain primary first.

Non-primary domains can be deleted only when one of these is true:

Replacement domains must already be verified and belong to the same tenant.

Condition Result
No users have an address on that domain ONE deletes the domain.
Users still have addresses on that domain and a replacement domain is supplied ONE rewrites those users to the replacement domain, then deletes the old domain.
Users still have addresses on that domain and no replacement domain is supplied Deletion fails with a validation error.
Problem What to check
A member cannot sign in directly at the general auth page Their email domain may be verified on an enterprise tenant and have lookup by email enabled. They must use the enterprise flow.
Whois verification is unavailable Use TXT verification. The Whois contact may be redacted or unavailable.
A domain cannot be deleted It may be primary, or users may still have email addresses on that domain.
A member email cannot be changed The selected domain must be verified for the tenant, and the editor must have the required profile or IAM permission.

Email domains vs HTTP hostnames

Verified tenant domains control your organisation's email namespace — member addresses, lookup by email, and sign-in routing. They do not by themselves publish sign-in on your own hostname.

To serve enterprise sign-in and the workforce portal on a custom hostname such as workforce.example.com, configure a separate HTTP hostname under Organisation → Profile → Custom domain. The hostname must belong to a verified domain you already manage here.

English