How to control which sites can embed your forms (Allowed Domains) in CornerSpot

When you embed a Cornerspot form on an external website, the form only loads and submits on the domains you've authorized. This allowlist is your main lever for controlling where a form can be used: a form embedded on any origin that isn't on the list is rejected. Your own Cornerspot website, subdomain, and verified custom domain are always allowed automatically — so single-page links and website-builder embeds work with nothing added here. The allowlist is shared across your whole team, so you only need to set it up once.

How to control which sites can embed your forms

Only team admins can manage this list, and changes take effect within about five minutes (origin checks are cached). Here's the full flow — reach the allowlist, add a domain, fine-tune it, and remove it.

1. Open Publish & Share → Embed on any website

Open any form, click Publish & Share at the top, and choose Embed on any website. The embed channel includes an Allowed domains card with your Allowlisted domains — every authorized hostname lives here. (This list is shared by your whole team, so it doesn't matter which form you open.)

The Publish and Share dropdown open on a Cornerspot form
Opening the Publish & Share dropdown on a form.
Choosing Embed on any website in the Cornerspot form Publish and Share menu
Choosing Embed on any website to reach the allowlist.
The Allowlisted domains card in the Embed on any website channel in Cornerspot
The Allowlisted domains card in the Embed on any website channel.

2. Add a hostname

Type the website's hostname into the add field — for example shop.example.com. Enter just the domain itself: no scheme (no https://) and no path.

Typing a hostname into the add field on the Cornerspot Allowed domains card
Typing a hostname into the add field — just the domain, no scheme or path.

3. Click "Add"

Select Add and the domain joins your allowlist immediately, marked Active. Forms embedded on that domain can now load and submit.

The Add button on the Cornerspot Allowed domains card
The Add button allowlists the domain.
A newly added allowed domain shown as Active in Cornerspot
The new domain in the allowlist, shown as Active.

4. Fine-tune the entry

Click Edit on a domain's row to open its settings. Here you can:

  • Include subdomains — match *.example.com too, handy for staging and preview hosts.
  • Enabled — turn this off to revoke access temporarily without deleting the entry.
  • Note — an internal reminder for your team; it's never shown to visitors.
The Edit domain panel for an allowed domain in Cornerspot
The Edit domain panel, where you fine-tune an entry.
Include subdomains turned on and an internal note added for an allowed domain in Cornerspot
Turning on Include subdomains and adding an internal note.

5. Save your changes

Click Save changes to apply the update.

The Save changes button in the Edit domain panel in Cornerspot
The Save changes button applies your edits.

6. Remove a domain

To stop a site from running your forms, click Remove on its row and confirm in the Remove domain? dialog. Forms embedded on that domain will stop loading and submitting within about five minutes.

The Remove action on an allowed domain row in Cornerspot
The Remove action on a domain row.
The Remove domain? confirmation dialog in Cornerspot
Confirming removal in the Remove domain? dialog.
The Cornerspot allowlist after the demo domain has been removed
The allowlist after the domain has been removed.

Good to know

  • The allowlist is shared across your whole team, not tied to one form — you reach it through any form's Publish & Share → Embed on any website, and a change applies to every embedded form.
  • Your own Cornerspot site, subdomain, and verified custom domain are already allowed — you only need this list for external, third-party sites.
  • Add the hostname as bare text: shop.example.com, not https://shop.example.com/contact.
  • Use Include subdomains to cover staging and preview environments without a separate entry for each.
  • Prefer Enabled off over deleting if you want to revoke access but keep the entry for later.
  • Changes are cached, so allow up to about five minutes for them to take effect.

Was this article helpful?