# LetsEncrypt ssl on email tracking domain

**URL:** <https://meta.discourse.org/t/letsencrypt-ssl-on-email-tracking-domain/80859>\
**Category:** Support\
**Created:** [February 18, 2018, 3:08am UTC](https://meta.discourse.org/t/letsencrypt-ssl-on-email-tracking-domain/80859 "2018-02-18T03:08:32Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Umashankar\_Ankuri](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/umashankar_ankuri/32/150996_2.png) [@Umashankar\_Ankuri](https://meta.discourse.org/u/Umashankar_Ankuri)\
**Post date:** [February 18, 2018, 3:08am UTC](https://meta.discourse.org/t/letsencrypt-ssl-on-email-tracking-domain/80859/1 "2018-02-18T03:08:32Z")

</div>

Hi Team,

Some of the providers like [elasticemail.com](http://elasticemail.com) rewriting email content links.  
Example. elasticemail requires tracking CNAME to be configured while verifying/adding sending domain also don’t allow verifying sub domains

actual link  
[https://discourse.domain.com/u/activate-account/9c9f071732482a63ef28591e4ef5017d](https://discourse.domain.com/u/activate-account/9c9f071732482a63ef28591e4ef5017d)

Rewriting email link for account activation email look like below

[http://tracking.domain.com/tracking/click?d=yExJPVlLMbyKmyDMop0JMq3ZHFfxA0TPZhe0Dy6Osv7iSNeDEk\_1YGRZuQPwP1YTRIWALOBW-3a-mSMo0qq7qDC\_W6tBz4gqSpvAUgaJZR4nqhe6fjoRW4vNnZB\_u1GnzhYWK1xV-KBHPacw2mGlxR6-6Sza2dieOrdQeyRq35xkMSY9L2ND6D\_2riBkYCGD9A2](http://tracking.domain.com/tracking/click?d=yExJPVlLMbyKmyDMop0JMq3ZHFfxA0TPZhe0Dy6Osv7iSNeDEk_1YGRZuQPwP1YTRIWALOBW-3a-mSMo0qq7qDC_W6tBz4gqSpvAUgaJZR4nqhe6fjoRW4vNnZB_u1GnzhYWK1xV-KBHPacw2mGlxR6-6Sza2dieOrdQeyRq35xkMSY9L2ND6D_2riBkYCGD9A2)

as discourse install didn’t install cert on [tracking.domain.com](http://tracking.domain.com) leaving an insecure message on browser when we set force ssl setting.

As Discourse LetsEncrypt module will install certs on configured domain, Is there any way that installing certs on tracking domain

This is not a multisite.

Also LetsEncrypt is going to issue wildcard ssl in a week.(ETA: February 27, 2018 from LetsEncrypt forums) incorporating that to letsencrypt module is good choice to avoid these instances

Thank you.

---

<div class="post-metadata">

**Author:** ![codinghorror](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/codinghorror/32/110067_2.png) [@codinghorror](https://meta.discourse.org/u/codinghorror)\
**Post date:** [February 18, 2018, 4:37am UTC](https://meta.discourse.org/t/letsencrypt-ssl-on-email-tracking-domain/80859/2 "2018-02-18T04:37:35Z")

</div>

Sorry, how does this relate to Discourse in any way? I am not seeing anything relevant to Discourse here.

---

<div class="post-metadata">

**Author:** ![Umashankar\_Ankuri](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/umashankar_ankuri/32/150996_2.png) [@Umashankar\_Ankuri](https://meta.discourse.org/u/Umashankar_Ankuri)\
**Post date:** [February 18, 2018, 4:59am UTC](https://meta.discourse.org/t/letsencrypt-ssl-on-email-tracking-domain/80859/3 "2018-02-18T04:59:16Z")

</div>

Hi @codinghorror

Thank you for the reply.

There is nothing wrong with discourse. This is because of third party email service provider tracking smtp emails. but, is there any way in app.yml or ssl template for installing LetsEncrypt ssls on other sub domains? Please let me know.  
I have seen some setup for multi-site with after ssl hooks. not sure if this works with single install.

---

<div class="post-metadata">

**Author:** ![mpalmer](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/mpalmer/32/45740_2.png) [@mpalmer](https://meta.discourse.org/u/mpalmer)\
**Post date:** [February 18, 2018, 9:03pm UTC](https://meta.discourse.org/t/letsencrypt-ssl-on-email-tracking-domain/80859/4 "2018-02-18T21:03:15Z")

</div>

What? Of course not. You don’t run the tracking domain, therefore you can’t install certs on it. Tell your e-mail provider to get off their chunk and setup HTTPS.

---

<div class="post-metadata">

**Author:** ![Umashankar\_Ankuri](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/umashankar_ankuri/32/150996_2.png) [@Umashankar\_Ankuri](https://meta.discourse.org/u/Umashankar_Ankuri)\
**Post date:** [February 19, 2018, 5:36am UTC](https://meta.discourse.org/t/letsencrypt-ssl-on-email-tracking-domain/80859/5 "2018-02-19T05:36:50Z")

</div>

Hi @mpalmer

Thank you for the reply.

Yes. I have worked out with elasticemail, just got a reply. they disabled tracking. this is the default setting with them when subscribed.

---

<div class="post-metadata">

**Author:** ![JammyDodger](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/jammydodger/32/254611_2.png) [@JammyDodger](https://meta.discourse.org/u/JammyDodger)\
**Post date:** [June 8, 2024, 12:37pm UTC](https://meta.discourse.org/t/letsencrypt-ssl-on-email-tracking-domain/80859/6 "2024-06-08T12:37:48Z")

</div>

This topic was automatically closed after 2302 days. New replies are no longer allowed.
