formbasedocs
Go to appApp

Branding & Domains

The Domains page

Where a workspace manages every branded domain it owns — the ones that serve forms, the ones that send email, and the Turnstile keys that protect them.


Pro feature

This needs the Pro plan or higher. Compare plans →

Finding it

Open Domains from the workspace sidebar. Its subtitle says what it covers: Manage branded domains for form sharing and email sending. The page holds three cards, in this order.

1. Domains that serve forms

The first card lists the domains your forms are served from, and lets you add one and see which forms use it. This is the setup side of custom domains, which walks through DNS records and verification.

2. Bot Protection

The second card is Bot Protection, and it is the part most people miss. Its description is exact: Provide your own Cloudflare Turnstile keys for bot protection on custom domain forms.

Forms on a formbase link are covered by formbase’s own Turnstile keys. A form served from your domain is not — Turnstile keys are tied to the hostname, so formbase’s keys do not apply there. Until you add your own keys, a form on a custom domain has no bot protection available to turn on.

The card offers Get keys (to Cloudflare) and Read more. Paste the Site key and Secret key and choose Save keys. Once saved it reads Keys configured — edit below to rotate, and the secret field shows Leave blank to keep existing, so you can rotate the site key without re-entering the secret. Remove clears both.

Add a domain first

With no custom domain in the workspace the card shows Add a custom domain first and nothing to fill in. The keys only ever apply to custom-domain forms, so there is nothing to configure until one exists.

The effect shows up in a form’s own settings. Under Bot protection (Turnstile), a form on a custom domain without workspace keys reads Configure Turnstile keys in Workspace Domains to enable bot protection and links straight here. Once the keys are saved it reads Using your workspace Turnstile keys for custom domain forms. See Captcha & bot protection.

3. Email sending domains

The third card holds the domains formbase sends email from, so invitations, reminders and notifications come from your address rather than a formbase one. See custom email domains for the DNS setup.

Two different kinds of domain

A domain that serves forms and a domain that sends email are configured separately, with different DNS records, on two different cards. Setting up one does not set up the other, even for the same domain name.

Next steps