Domain allowlist and customer consult URLs
Porchlight only starts buyer sessions from hosts that belong to the customer. This protects source attribution and prevents another site from pretending to send traffic for the org.
Use this guide when the widget works in one place but not another, when Verify install reports a blocked host, or when a customer-owned consult URL should send buyers into Porchlight.
Website host allowlist
In Settings -> Branding, save the exact hosts that may load Porchlight:
- Main website host, such as
www.example.com. - Apex domain, such as
example.com, if buyers also use that version. - Customer-owned booking or consult host, such as
book.example.com. - Any production landing page host that will embed the widget.
Avoid staging, preview, or agency sandbox hosts unless they are intentionally part of launch testing.
Common blocked-host causes
- The setting has
example.com, but the live site iswww.example.com. - The setting has the old staging domain.
- The site redirects buyers through a different host before loading Porchlight.
- A CMS preview or page-builder domain is being tested instead of production.
- A contractor installed the snippet on a microsite that was not added to Porchlight.
Customer-owned consult URL
A customer consult URL is a buyer-facing URL on the customer's domain, such as:
https://book.example.com/site-visit
The web person can make that URL redirect to the Porchlight hosted intake page. Preserve the original host, path, URL, source, campaign, and UTM fields so the lead handoff shows where the buyer started.
Example target:
https://porchlight.cymbalabs.com/embed/your-org-slug?source=customer_domain&host=book.example.com&path=/site-visit&url=https%3A%2F%2Fbook.example.com%2Fsite-visit
Use the customer's org slug in place of your-org-slug.
Verification
- Open the customer site or customer consult URL in a private browser window.
- Start a test conversation.
- Confirm it reaches the Porchlight Inbox.
- Open the lead or conversation handoff.
- Confirm the source shows the expected website, customer-domain consult link, campaign, host, path, and URL.
Send Porchlight this context
If the domain is still blocked, open support and include:
- The buyer-facing URL.
- The URL it redirects to, if any.
- The exact host saved in Settings -> Branding.
- Whether the buyer starts from the website widget, Google Business Profile, a QR code, or a campaign link.