Skip to main content

Domain Restrictions and Website Security

Set an allowed domain so your NoForm AI chatbot only works on your own website, and learn the domain format rules, subdomain behavior, and what visitors see on a blocked site.

Written by NoForm Team

Each chatbot is licensed for use on one domain. The allowed domain setting records which website that is, and the chat loads only there and on its subdomains. You set it on the Installation page in a single field. If you need to cover more domains, create a new organization with its own assistant for each one, or contact us for assistance.

What the allowed domain setting does

The allowed domain is the one website address where your chatbot is permitted to run. Each time the widget loads on a page, it checks the page address against the domain you saved. If the address matches, the chat works as usual. If it does not match, visitors on that site see a short warning in place of the chat and cannot start a conversation.

The setting belongs to a single chatbot. If you manage several chatbots, each one has its own allowed domain, and changing one does not affect the others.

The default for a new chatbot

When you create a chatbot through onboarding, NoForm AI fills the allowed domain in for you using the address of the company website you entered. Check the value after setup, because the domain is copied exactly as it appeared in your URL. A website URL entered as https://www.example.com is saved as www.example.com, which does not cover the address example.com without the www prefix.

If the field is empty, no restriction applies. Keep the field set to your website’s domain so your chatbot runs where it is licensed to.

Set or change your allowed domain

To set the domain, open your chatbot in the NoForm AI dashboard and go to the Installation page. The “Organization website domain” section sits at the top of the “Installation instructions” panel.

The Organization website domain section on the Installation page, with the saved domain and its pencil edit icon highlighted
  1. Type your website domain into the field, for example example.com or shop.example.com. Leave out http:// and https://.

  2. Click “Save domain”.

  3. Confirm that the message “Domain saved successfully. The widget will only load on this domain and its subdomains.” appears.

To change a saved domain, click the pencil icon next to it. This turns the read-only field into an editable one. Edit the value and click “Save domain”, or click “Cancel” to discard your edit. The “Save domain” button stays disabled until you change the value.

The Organization website domain field with the pencil edit icon highlighted

Domain format rules

The field checks your entry before saving and shows a message when something is wrong. Use the table below to match the message to the fix.

Message

What to do

Domain is required

Enter a domain. The field cannot be saved empty.

No need to include http:// or https:// just the domain name.

Remove the protocol prefix and keep only the domain, for example example.com.

Only one domain is allowed per organization. Use subdomains if needed.

Enter a single domain. The field rejects comma-separated lists.

That doesn’t look like a valid domain. Use format like example.com or sub.example.com

Enter a domain that contains at least one dot and no spaces, slashes, or page paths.

This domain zone is not supported.

Your domain ending is outside the accepted list below.

Supported domain endings

The field accepts a fixed list of domain endings, and it checks the last part of your address. A domain such as example.co.uk passes on uk.

Group

Accepted endings

General

com, org, net, edu, gov, mil, int, co, io, app, dev, tech, info, biz, name, pro, museum, travel, jobs, mobi, tel, asia, cat, xxx, post, geo, aero, coop

Country

uk, us, ca, au, de, fr, jp, in, mx, es, it, nl, se, no, dk, fi, pl, cz, sk, hu, ro, bg, hr, si, ee, lv, lt, ua, am, az, ge, md

The field rejects any ending outside this list, and that includes .ai. If your website uses an ending the field does not accept, leave the domain empty so your chatbot keeps working, and contact NoForm AI support so the team can review your case.

How subdomains are handled

Saving example.com also covers every subdomain of that address, so the widget runs on www.example.com, shop.example.com, and blog.example.com without extra setup. Page paths make no difference either, so a single entry covers your whole site.

The reverse is not true. Saving shop.example.com limits your chatbot to that subdomain and blocks the rest of example.com. Enter the shortest form of your domain, without www, when you want full coverage.

Only one domain fits in the field, because each chatbot covers one domain. To cover another website, create a new organization with its own assistant, or contact us for assistance.

What visitors see on a domain that is not allowed

On a site outside your allowed domain, the chat bubble still appears in the corner of the page. Opening it shows a warning icon and the text “I can’t load on this domain. Please check the Installation tab in your NoForm.ai dashboard.” instead of the chat. The greeting popup shows the same warning, conversation starters are hidden, and the browser console records the line “NoForm.AI: Domain example.com is not allowed to use this bot.” with the blocked domain in place of the example.

Visitors on that site cannot send a message, so no conversations from it reach your account. The full-page chat experience shows the same warning when it loads on a domain that is not allowed.

Testing and previewing your chatbot

Two addresses always work, whatever you save in the field. Pages served from localhost stay open, so you can test the widget on a local copy of your site during development. Pages on noform.ai stay open as well, which keeps the preview inside your dashboard and your public share page working after you restrict the domain.

Frequently Asked Questions

Can I allow more than one website for a single chatbot?

Each chatbot accepts one domain. Use the parent domain when your sites are subdomains of the same address. For a separate website, create a new organization with its own assistant, or contact us for assistance.

Do I have to reinstall the snippet after changing the domain?

Changing the allowed domain takes effect on the next page load, and your install snippet stays the same. Reload a page on your website to confirm the chat works.

Why does my chatbot show the warning on my own website?

Compare the saved value with the address in your browser. A saved value of www.example.com blocks the shorter example.com, and a saved subdomain blocks the rest of your site. Remove the www prefix and any subdomain, then save again.

What happens if I clear the field?

An empty allowed domain removes the restriction, and your chatbot loads on any website that includes your snippet.

Benefits

  • Your chatbot answers visitors only on the website you approved.

  • Subdomain coverage is automatic, so one entry protects your main site, store, and blog.

  • Blocked sites get a clear warning instead of a broken widget, which makes an install mistake obvious.

  • Local development and the dashboard preview keep working, so restricting the domain does not slow your testing.

Did this answer your question?