You shipped the app. Now you need to share it, and the address your hosting platform gave you is a long, hashed string that looks like a phishing link. A custom domain with HTTPS makes a project look finished, builds trust with clients and users, and is easier to remember.
Behind every "https://your-app.example" are four moving parts. This guide explains each one, walks through the do-it-yourself route, and shows how DomainDock automates the whole thing in under 30 seconds.
The four pieces behind a custom domain
Every secure custom domain relies on the same building blocks:
- DNS, the internet's phone book, which maps your domain name to a server IP address. Cloudflare's guide to what DNS is is a clear introduction.
- A reverse proxy, a server in front of your app that receives requests for your domain and forwards them to the right upstream. See what a reverse proxy is.
- A TLS certificate, the proof of identity that enables HTTPS encryption. Learn more about SSL certificates.
- HSTS, a response header that tells browsers to only ever use HTTPS for your domain (MDN reference).
The DIY route, step by step
If you want to wire it up yourself on a VPS, the classic setup looks like this:
- Register a domain and create an A (or AAAA) record pointing to your server's IP address.
- Install a reverse proxy such as nginx or Traefik and route the hostname to your app's port.
- Obtain a free certificate from Let's Encrypt using an ACME client, proving control of the domain with an HTTP-01 or DNS-01 challenge.
- Redirect all HTTP traffic to HTTPS and add an HSTS header.
- Schedule automatic renewals, because Let's Encrypt certificates are short-lived by design.
- Add uptime monitoring so you learn about outages before your users do.
Common pitfalls
- DNS propagation: changes can take time to reach every resolver, so a new domain may work for you before it works for a client.
- Mixed content: an HTTPS page that loads HTTP scripts or images will show warnings or break.
- Forgotten renewals: a certificate that silently expires takes your site down with a scary browser error.
- Premature HSTS: enabling a long HSTS max-age before HTTPS is fully working can lock users out.
The 30-second route with DomainDock
DomainDock at digitalweb.host automates all four pieces as a single five-stage pipeline. You claim a project slug (or bring your own domain) and point it at any IP and port. DomainDock then provisions DNS on Cloudflare's anycast network, adds host-based routing to a Traefik reverse proxy with zero downtime, issues and installs a TLS certificate with HTTPS enforcement and HSTS, and starts health-checking your upstream.
Certificates renew automatically before expiry, failures are retried with exponential back-off and each route shows live ACTIVE, DEGRADED or DOWN status. The whole flow typically completes in under 30 seconds and is free forever. See how it works or create a free account.
Production-ready domain checklist
- Domain resolves correctly from multiple networks.
- HTTPS works and HTTP redirects to HTTPS.
- Certificate renewal is automated and monitored.
- HSTS is enabled once HTTPS is stable.
- No mixed-content warnings in the browser console.
- Uptime monitoring and alerting are in place.
Frequently asked questions
Can I get SSL for free?
Yes. Let's Encrypt issues free, trusted TLS certificates. Tools like DomainDock request, install and renew them for you automatically.
Why is my new domain not working yet?
Usually DNS propagation. New or changed records take time to reach every resolver. DomainDock uses Cloudflare's anycast network, which typically propagates globally in under a minute.
Do I need to buy a domain to use a custom URL?
Not with DomainDock. You can claim a free subdomain on digitalweb.host, or connect a domain you already own.