> ## Documentation Index
> Fetch the complete documentation index at: https://docs.wegive.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Installation & Domain Setup Guide

> WeGive Help Center article: Installation & Domain Setup Guide

## Overview

The **Installation** section in the WeGive dashboard (found under **Settings → Installation**) is where organizations connect a custom domain to their WeGive-powered checkout pages and donor portal. Instead of donors seeing `app.wegive.com`, they'll see your branded URL like `donate.yourchurch.org`.

This guide walks through the full setup process and covers every troubleshooting scenario we see in support.

**Note:** This guide covers your **vanity domain** (checkout + donor portal) only. Setting up a custom **email sending domain** is a separate process with its own DNS records — see the Custom Email Domain guide for that.

## What Connecting a Domain Does

Once a custom domain is fully set up, it applies to two areas of your WeGive experience:

* **Checkout pages** — Donation forms load under your branded URL instead of `app.wegive.com`.
* **Donor portal** — Donors log in, manage recurring gifts, and view history at your domain.

Connecting a vanity domain here does **not** change the address your emails send from. Email sending is controlled separately by the Custom Email Domain feature.

## Before You Start

You'll need access to two things:

* **Your WeGive dashboard** — Specifically the **Settings → Installation** page. You need admin-level access to your organization.
* **Your DNS provider** — Wherever your domain's DNS is managed (GoDaddy, Cloudflare, Namecheap, Google Domains, etc.). You'll need permission to add DNS records.

## Step-by-Step Setup

### Step 1: Add Your Domain

1. Go to **Settings → Installation** in the dashboard.
2. Click **Add Vanity Domain**.
3. Enter your desired subdomain — for example, `donate.yourwebsite.org` or `give.yourchurch.com`.
4. Click **Save**.

Your new domain will appear in the list with a status of **Unauthenticated**. That's expected — you haven't pointed the DNS yet.

**Important:** You must use a subdomain (like `donate.` or `give.`). Top-level domains (like `yourwebsite.org` by itself) cannot be set up as CNAME records and won't work.

### Step 2: Get Your DNS Records

1. Find your newly added domain in the list.
2. Click the arrow icon next to the unauthenticated domain to expand it.
3. Under **Add DNS Records**, locate the CNAME record details.
4. Copy both the **Name** and **Value** fields exactly.

The CNAME target depends on when your domain was created:

| Domain Created | CNAME Value |
| - | - |
| After September 27, 2024 | `proxy-fallback.wegive.com` |
| Before September 27, 2024 | `wegive-production.netlify.app` |

The dashboard displays the correct value for your domain automatically — just copy what's shown.

### Step 3: Add the CNAME Record in Your DNS Provider

1. Log into your DNS provider.
2. Navigate to DNS settings for your root domain.
3. Create a new **CNAME** record.
4. Paste the **Name** and **Value** exactly as shown in WeGive.
5. Save.

**Provider-specific notes:**

* **GoDaddy** — Only enter the subdomain portion in the Name field (e.g., `donate`, not `donate.yourwebsite.org`). GoDaddy appends the root domain automatically.
* **Cloudflare** — Make sure the proxy toggle (orange cloud) is turned **off** for this record. Cloudflare's proxy can interfere with SSL certificate provisioning. Set it to "DNS only" (gray cloud).
* **Google Domains / Squarespace** — Enter the full subdomain in the Host field. Trailing dots are added automatically.
* **Namecheap** — Use the subdomain only in the Host field. Namecheap appends the domain.

### Step 4: Wait for DNS Propagation and Verify

1. Return to **Settings → Installation** in WeGive.
2. Click **Refresh Status** next to your domain.
3. If the status changes to **Valid**, DNS is propagated and you're ready for the next step.

DNS propagation typically takes 5–30 minutes but can take up to 24–48 hours depending on your provider and TTL settings. If it's still showing unauthenticated after a few minutes, wait and try again later — don't change anything yet.

### Step 5: Issue the SSL Certificate and Complete TXT Validation

Once DNS status shows **Valid**:

1. Click the **Issue SSL Certificate** button.
2. WeGive requests a certificate from Cloudflare using TXT-record validation. Expand your domain again in **Settings → Installation** and check for any listed **TXT validation records** alongside the CNAME.
3. If a TXT record is shown, add it at your DNS provider the same way you added the CNAME — as a new record, at the exact name and value shown, without replacing any TXT record already in place for this domain.
4. Wait for the status to turn green / **Issued**.

<Warning>
  **You may be asked to add more than one TXT value, or see a value change, before the certificate finishes issuing.** This does not mean your previous entry was wrong. Certificate issuance can request two separate certificate types for broader browser compatibility, and each type validates with its own TXT value — so it's normal to see a second value appear after you've already published the first one. Add each value you're shown as its own TXT record and keep any earlier value that's still listed as required; only remove a TXT record once it no longer appears in WeGive's displayed requirements.

  Some DNS providers (notably Azure DNS) group multiple TXT records at the same name into one **record set** rather than showing them as separate rows. If your provider works this way, add each additional value as its own entry inside that same record set — don't try to combine two values into a single TXT string, which can concatenate them into one incorrect value.
</Warning>

A green **Issued** status confirms the certificate is active. SSL is required for HTTPS security and PCI compliance — without it, browsers will show security warnings to your donors.

### Step 6: Set as Default Domain

1. Use the **Default Domain** selector at the bottom of the Installation section.
2. Select your custom **Vanity domain** as the default.
3. Save.

Your checkout forms and donor portal will now load under your branded URL.

## Understanding Domain Statuses

The Installation page shows a combined status for each domain based on two checks — DNS and SSL:

| DNS Status | SSL Status | Overall Status | What It Means |
| - | - | - | - |
| Valid | Issued | **Authenticated** (green) | Fully set up and working |
| Checking | Checking | **Checking** (yellow) | Verification in progress — wait |
| Checking | Issued | **Checking** (yellow) | DNS re-verification in progress |
| Valid | Not issued | **Unauthenticated** (red) | DNS is good, but SSL still needs to be issued |
| Not valid | Not issued | **Unauthenticated** (red) | DNS not configured or not propagated yet |

A domain only reaches **Authenticated** status when DNS is valid **AND** SSL is issued. If either check is still in progress, the overall status shows **Checking**.

## Troubleshooting

### DNS Won't Verify

*"I added the CNAME but status still shows unauthenticated"*

* **Wait longer.** DNS propagation can take up to 48 hours. Most resolve within 30 minutes, but some providers are slower.
* **Check for conflicting records.** If an A record already exists for the same subdomain, it will conflict with your CNAME. Delete the A record first.
* **Verify the CNAME value is exact.** Copy-paste from WeGive — don't type it manually. Extra spaces or typos will cause failure.
* **Check your provider's formatting.** Some providers want just the subdomain (`donate`), others want the full hostname (`donate.yoursite.org`). See the provider notes in Step 3.
* **Use a DNS lookup tool** to confirm your record is live. Search "DNS lookup" online and check that your subdomain returns the correct CNAME target.

### SSL Certificate Won't Issue

*"I clicked Issue SSL but it's stuck or failed"*

* **Make sure DNS is verified first.** SSL provisioning requires a valid DNS record. If DNS status isn't "Valid," fix that first.
* **Check for a TXT validation record.** Expand your domain in Settings → Installation — if a TXT record is listed, add it exactly as shown. A certificate won't issue until any listed TXT record is published and detected.
* **A newly-requested or changed TXT value is normal, not a sign of failure.** See "Why am I being asked for another TXT value?" in the FAQ below.
* **Wait a few minutes.** Certificate provisioning isn't instant. Give it 5–10 minutes before retrying.
* **Cloudflare users:** Turn off the orange proxy cloud for your CNAME record. Cloudflare's proxy intercepts the SSL challenge and prevents WeGive from issuing the certificate.
* **Still stuck after 30 minutes?** Contact [help@wegive.com](mailto:help@wegive.com). There may be a provisioning issue on the backend.

### "Record Already Exists" Error

Your DNS provider is telling you there's already a record for that subdomain. You need to delete the existing record if not in use (usually an A record or a different CNAME) before adding the WeGive CNAME.

### Donor Portal Shows the Wrong Domain

If donors are seeing `app.wegive.com` instead of your custom domain:

* Confirm your custom domain is set as the **default** in Settings → Installation.
* The donor portal uses whichever domain is associated with the donor's login session. If a donor bookmarked the old URL, they may still land on `app.wegive.com`. The experience still works, but the URL won't match your brand.
* Have the donor clear their browser cache or use the new branded link directly.

### Domain Was Working but Stopped

* **DNS record was changed or deleted.** Check your DNS provider — someone may have modified or removed the CNAME record.
* **SSL certificate expired.** WeGive handles automatic renewal, but if something went wrong, contact support to re-issue.
* **Refresh the status** in Settings → Installation. If the domain went from Authenticated back to Unauthenticated, the DNS record is the most likely culprit.

## Switching or Removing a Domain

To remove a custom domain, use the **Remove Domain** option next to the domain in the Installation list. If you're switching to a new domain:

1. Add the new domain and complete setup (Steps 1–6).
2. Set the new domain as default.
3. Delete the old domain.
4. Remove the old CNAME record from your DNS provider.

Keep the old domain active until the new one is fully authenticated to avoid downtime.

## FAQ

**Can I use my root domain (e.g.,** `yoursite.org`**) instead of a subdomain?**\
No. Root domains cannot be configured as CNAME records — this is a DNS standard limitation. Use a subdomain like `donate.yoursite.org` or `give.yoursite.org`.

**How long does the whole process take?**\
If DNS propagates quickly, you can be fully set up in 10–15 minutes. In the worst case, DNS propagation can take up to 48 hours.

**Does this cost extra?**\
Custom domain setup is included with your WeGive plan. SSL certificates are provisioned and renewed at no extra charge.

**What happens if my domain setup breaks?**\
WeGive falls back gracefully. Checkouts and the donor portal will still work on `app.wegive.com`, so donors won't experience downtime — they just won't see your branded URL until the issue is resolved.

**Can I have multiple custom domains?**\
Yes, you can add multiple domains, but only one can be set as the default at a time.

**Does this change the address my emails come from?**\
No. The vanity domain here only controls your checkout and donor portal URLs. Your email sending domain is configured separately — see the Custom Email Domain guide.

**I use Cloudflare — anything special I need to do?**\
Yes. Turn off the proxy (orange cloud → gray cloud) for your WeGive CNAME record. Cloudflare's proxy interferes with both DNS verification and SSL certificate provisioning.

**Why am I being asked to add another TXT value?**\
A TXT validation record proves you control the domain. It's normal to see an additional or changed value appear after you've already published one — this isn't a sign your earlier entry failed. Certificate issuance can request validation for more than one certificate type (for broader browser compatibility), and each type uses its own separate TXT value. Add each value WeGive currently shows as its own TXT record, and keep any earlier value that's still listed as required. If your DNS provider groups same-name TXT records into one record set (Azure DNS does this), add each value as its own entry inside that set rather than combining values into one string.

**Can I password-protect my domain while I'm still setting it up, so donors don't stumble onto it before launch?**\
There's no built-in password or login gate for a vanity domain — WeGive doesn't offer domain-level basic authentication for checkout or donor portal pages. In practice this isn't needed: a domain you've added and pointed DNS at is safe from real donor traffic as long as you simply don't publish or share the URL anywhere public until you're ready to go live. Once DNS and SSL are both set up, the domain is live and reachable by anyone who has the exact URL, but nobody will stumble onto it without being given the link. If you want a hard technical barrier during setup, you'll need to add access control at your own DNS/hosting layer (e.g. a redirect rule or gate in front of the CNAME target) — WeGive itself doesn't provide one.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.