For IT teams owning the domain behind your GeoSwap links
Your branded link domain (say, go.yourcompany.com) lives in your own registrar and DNS account. GeoSwap doesn't need access to your registrar, your DNS login, or ownership of the domain. All we need are two DNS records, which your team adds and can remove whenever you like.
This guide is for the IT team looking after that domain. It covers how to set it up securely, what to test before launch, and what happens if things change later. For the DNS setup itself, see Custom Domains.
_geoswap-verification.<your-domain> with a code GeoSwap gives you. This proves you control the domain. Only someone with access to your DNS can add it, which is one more reason to keep DNS access with your IT team.
Points your link domain at GeoSwap's edge network. SSL certificates are set up and renewed for you automatically (TLS 1.2 or newer), so there's nothing to upload or keep track of.
We recommend a subdomain like go. or link. rather than your main website domain. It keeps your links separate from your website and email.
These settings live on your side, in your registrar and DNS account. We can't change them for you, but they're what keep your links safe for years to come.
Register the domain under a company admin account
Use your IT or admin account at the registrar (e.g. Cloudflare Registrar) rather than someone's personal login. That way nobody loses access when people change roles or leave.
Turn on auto-renew with a company payment method
If the domain expires, every short link on it stops working. Auto-renew on a company card means it never lapses by accident.
Send renewal and security notices to a shared mailbox
Something like it-domains@yourcompany.com, so reminders don't get lost in one person's inbox.
Enable registrar lock (transfer lock)
This stops anyone moving the domain to another registrar unless your admin unlocks it first.
Require MFA on the registrar and DNS account
Whoever controls DNS controls where your links go, so treat this login like any other important admin account.
Limit who can edit DNS
Only your IT or admin team needs DNS access. Your marketing team works in GeoSwap and never needs to touch DNS.
Only admins and owners can add, verify or remove domains. Editors can create and change links, but they can't touch domains, members or billing. The full breakdown is in Team Management.
Every change is recorded in the audit log, so you can always see who added a domain, edited a link or changed someone's role, and when they did it.
People sign in with a one-time email code (no passwords) or with Google or Microsoft. Enterprise workspaces can also use SSO (SAML / OIDC).
Before a link goes into a campaign, run through these with your engineering or QA team:
Decide who on your team can create, change and delete links.