Skip to main content
TrackPlay’s domain whitelist feature allows you to control which websites can embed and stream your videos. This provides security and prevents unauthorized use of your content on unwanted domains.
Domain whitelisting is available for workspace owners and admins. When no domains are configured, videos can be embedded anywhere.

How It Works

Default Behavior

  • No domains configured: Videos can be embedded on any website
  • Domains configured: Only whitelisted domains can stream videos
  • Blocked domains: Show a user-friendly “Video Unavailable” message

Validation Process

  1. Video starts playing immediately for the best user experience
  2. Domain validation runs asynchronously in the background
  3. The validation request is sent to https://e.trackplay.io/check
  4. If the domain is not whitelisted, video playback is stopped and blocked
  5. If validation fails (network issues), videos continue playing as fallback

Managing Your Whitelist

Accessing Domain Settings

  1. Navigate to your workspace settings
  2. Click the “Domain Whitelist” tab
  3. Add, edit, or remove domains as needed

Adding Domains

1

Click Add Domain

Click the ”+ Add domain to whitelist” button
2

Enter Domain

Enter the exact domain name (e.g., example.com)
  • Do not include http:// or https://
  • Subdomains must be added separately
3

Add Description

Optionally add a description to help identify the domain
4

Save

Click “Add Domain” to save the whitelist entry

Domain Format Examples

Each subdomain must be added separately. Adding example.com does not automatically allow www.example.com or shop.example.com.

Managing Existing Domains

Edit Domain

  • Click the “Edit” button next to any domain
  • Modify the hostname, description, or active status
  • Click “Update Domain” to save changes

Deactivate Domain

  • Edit the domain and uncheck “Active”
  • Inactive domains will block video playback
  • Useful for temporarily restricting access

Remove Domain

  • Click the “Remove” button next to any domain
  • Confirm the deletion in the popup
  • Domain will be permanently removed from whitelist

Integration Considerations

Player Behavior

When a domain is blocked:
  • Video starts playing normally for optimal user experience
  • Domain validation happens asynchronously in the background
  • If domain is not whitelisted, video playback is stopped and shows:
The validation component:
  • Destroys HLS instance to stop streaming
  • Resets video element source
  • Shows user-friendly blocked overlay
  • Tracks ‘domain-blocked’ event for analytics

Error Handling

The check blocks a real hostname that is not on your list. Everything else plays:
  • The browser cannot reach the check at all: the video plays, and the error is logged to the console
  • The page has no hostname to check, because someone saved your page and opened it from their own disk (file://), or the player is framed in an about:blank document: the video plays. There is no hostname, so there is nothing your list could match it against, and the server-side gate had already served this viewer anyway
  • The check itself errors server-side: playback is blocked, not allowed
This overlay is not the thing protecting your video. Playback is gated server-side, on every manifest request, and that gate fails closed. The overlay only explains to the viewer what happened, so a “blocked” message is never proof the video was actually served, and its absence is never proof the allowlist was bypassed.

Development & Testing

During development, you may want to:
  1. Add localhost to your whitelist
  2. Add your staging domain
  3. Test blocked domain behavior on unauthorized domains

Common Use Cases

E-commerce Store

Marketing Campaign

Content Protection

Troubleshooting

Videos Not Playing

  1. Check domain whitelist: Ensure the current domain is added
  2. Verify subdomain: www.example.com ≠ example.com
  3. Check domain status: Ensure domain is marked as “Active”

Common Issues

Getting Help

If you encounter issues:
  • Check browser console for validation errors
  • Verify domain format matches exactly
  • Contact support with your workspace code and domain details
Domain validation logs are available in your workspace analytics for monitoring and debugging purposes.