Skip to main content
All docs

Domain allowlist and customer consult URLs

Porchlight only starts buyer sessions from hosts that belong to the customer. This protects source attribution and prevents another site from pretending to send traffic for the org.

Use this guide when the widget works in one place but not another, when Verify install reports a blocked host, or when a customer-owned consult URL should send buyers into Porchlight.

Website host allowlist

In Settings -> Branding, save the exact hosts that may load Porchlight:

  • Main website host, such as www.example.com.
  • Apex domain, such as example.com, if buyers also use that version.
  • Customer-owned booking or consult host, such as book.example.com.
  • Any production landing page host that will embed the widget.

Avoid staging, preview, or agency sandbox hosts unless they are intentionally part of launch testing.

Common blocked-host causes

  • The setting has example.com, but the live site is www.example.com.
  • The setting has the old staging domain.
  • The site redirects buyers through a different host before loading Porchlight.
  • A CMS preview or page-builder domain is being tested instead of production.
  • A contractor installed the snippet on a microsite that was not added to Porchlight.

Customer-owned consult URL

A customer consult URL is a buyer-facing URL on the customer's domain, such as:

https://book.example.com/site-visit

The web person can make that URL redirect to the Porchlight hosted intake page. Preserve the original host, path, URL, source, campaign, and UTM fields so the lead handoff shows where the buyer started.

Example target:

https://porchlight.cymbalabs.com/embed/your-org-slug?source=customer_domain&host=book.example.com&path=/site-visit&url=https%3A%2F%2Fbook.example.com%2Fsite-visit

Use the customer's org slug in place of your-org-slug.

Verification

  1. Open the customer site or customer consult URL in a private browser window.
  2. Start a test conversation.
  3. Confirm it reaches the Porchlight Inbox.
  4. Open the lead or conversation handoff.
  5. Confirm the source shows the expected website, customer-domain consult link, campaign, host, path, and URL.

Send Porchlight this context

If the domain is still blocked, open support and include:

  • The buyer-facing URL.
  • The URL it redirects to, if any.
  • The exact host saved in Settings -> Branding.
  • Whether the buyer starts from the website widget, Google Business Profile, a QR code, or a campaign link.