# The Domains page

One workspace screen for sharing domains, bot-protection keys, and email sending domains.

## The Domains page

Where a workspace manages every branded domain it owns — the ones that serve forms, the ones that send email, and the Turnstile keys that protect them.

<h2 id="finding-it">Finding it</h2>

<p>
  Open <strong>Domains</strong> from the workspace sidebar. Its subtitle says what it covers:{' '}
  <em>Manage branded domains for form sharing and email sending</em>. The page holds three cards, in this order.
</p>

<h2 id="sharing-domains">1. Domains that serve forms</h2>

<p>
  The first card lists the domains your forms are served from, and lets you add one and see which forms use it. This is the setup side of{' '}
  <a href="/branding-domains/custom-domains">custom domains</a>, which walks through DNS records and verification.
</p>

<h2 id="bot-protection">2. Bot Protection</h2>

<p>
  The second card is <strong>Bot Protection</strong>, and it is the part most people miss. Its description is exact:{' '}
  <em>Provide your own Cloudflare Turnstile keys for bot protection on custom domain forms.</em>
</p>

<p>
  Forms on a formbase link are covered by formbase's own Turnstile keys. A form served from <strong>your</strong> domain is not — Turnstile
  keys are tied to the hostname, so formbase's keys do not apply there. Until you add your own keys, a form on a custom domain has no bot
  protection available to turn on.
</p>

<p>
  The card offers <strong>Get keys</strong> (to Cloudflare) and <strong>Read more</strong>. Paste the <strong>Site key</strong> and{' '}
  <strong>Secret key</strong> and choose <strong>Save keys</strong>. Once saved it reads <em>Keys configured — edit below to rotate</em>,
  and the secret field shows <em>Leave blank to keep existing</em>, so you can rotate the site key without re-entering the secret.{' '}
  <strong>Remove</strong> clears both.
</p>

> ℹ️ **Add a domain first**
> <p>
>     With no custom domain in the workspace the card shows <strong>Add a custom domain first</strong> and nothing to fill in. The keys only
>     ever apply to custom-domain forms, so there is nothing to configure until one exists.
>   </p>

<p>
  The effect shows up in a form's own settings. Under <strong>Bot protection (Turnstile)</strong>, a form on a custom domain without
  workspace keys reads <em>Configure Turnstile keys in Workspace Domains to enable bot protection</em> and links straight here. Once the
  keys are saved it reads <em>Using your workspace Turnstile keys for custom domain forms.</em> See{' '}
  <a href="/building-forms/captcha-bot-protection">Captcha &amp; bot protection</a>.
</p>

<h2 id="email-domains">3. Email sending domains</h2>

<p>
  The third card holds the domains formbase sends email from, so invitations, reminders and notifications come from your address rather than
  a formbase one. See <a href="/branding-domains/custom-email-domains">custom email domains</a> for the DNS setup.
</p>

> 💡 **Two different kinds of domain**
> <p>
>     A domain that <strong>serves</strong> forms and a domain that <strong>sends</strong> email are configured separately, with different DNS
>     records, on two different cards. Setting up one does not set up the other, even for the same domain name.
>   </p>

<h2 id="next-steps">Next steps</h2>
<div class="not-prose grid gap-3 sm:grid-cols-2">
  - [Custom domains](/branding-domains/custom-domains) — Point your own domain at your forms
  - [Custom email domains](/branding-domains/custom-email-domains) — Send email from your own domain
  - [Captcha & bot protection](/building-forms/captcha-bot-protection) — Turn Turnstile on for a form
  - [Workspace themes](/branding-domains/workspace-themes) — Share one brand across every form
</div>
