# Prevent Unauthorized Domains from Pointing to Our Discourse Instance

**URL:** <https://meta.discourse.org/t/prevent-unauthorized-domains-from-pointing-to-our-discourse-instance/351330>\
**Category:** Support\
**Created:** [February 9, 2025, 1:21pm UTC](https://meta.discourse.org/t/prevent-unauthorized-domains-from-pointing-to-our-discourse-instance/351330 "2025-02-09T13:21:57Z")\
**Posts on this page:** 1\
**Showing post:** 1

<div class="post-metadata">

**Author:** ![Abdelrahman\_MoHamed](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/abdelrahman_mohamed/32/467712_2.png) [@Abdelrahman\_MoHamed](https://meta.discourse.org/u/Abdelrahman_MoHamed)\
**Post date:** [February 9, 2025, 1:21pm UTC](https://meta.discourse.org/t/prevent-unauthorized-domains-from-pointing-to-our-discourse-instance/351330/1 "2025-02-09T13:21:57Z")

</div>

We are running a Discourse instance on our server, but we’ve encountered an issue where anyone can take our server’s public IP and create an A record on their own domain, effectively pointing their domain to our forum.

We want to ensure that only our authorized domain can be used to access the forum and prevent unauthorized domains from working.

What are the recommended ways to enforce domain restrictions in Discourse? Is there a configuration, Nginx setting, or other method to achieve this?

Any guidance would be appreciated.

---

_[View the full topic](https://meta.discourse.org/t/prevent-unauthorized-domains-from-pointing-to-our-discourse-instance/351330)._
