<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
0D5WR000010FPIh0AOOkta Classic EngineCustom URL DomainsAnswered2025-11-29T11:00:49.000Z2025-11-21T08:12:08.000Z2025-11-29T11:00:49.000Z
Brand custom domain redirecting to ".okta.com"

In the Okta Admin Console, under Customizations / Brands, we have some brands set up. For each of the brands we have a custom domain on our own domain.

The certificates had expired, and due to a setup issue with CloudFlare on our DNS the certificates did not renew. We fixed the CloudFlare DNS issue (the CNAMES were proxied), and now all the custom domains are in "pending" status. If I try to visit one of the domains it redirects to ".okta.com".

This is a trial we're running: trial-9326820

I am not sure how else to request support.


  • Albertd.38306 (Customer)

    I tried recreating all the custom domains, but all of them are now broken and redirecting to ".okta.com". This is really hampering our integration effort.

  • DianaL.19788 (Customer Support Online Community and Social Care)

    Hello @Albertd.38306 (Customer)​ , thank you for contacting Okta Community.

     

    You can try removing all custom domains from Okta, then removing all DNS settings that send to Okta, as well as any type of certificates with Okta. Try to manage your own certificate, as your integration is behind a proxy (CloudFlare). The auto-renewal would fail every time.

    Wait for a few days, then try to re-implement.

     

    Otherwise, I recommend that you open a Support ticket (Customer Support Account ID number required) so one of our engineers can analyze it and provide in-depth troubleshooting.

    Please note that opening a support ticket is a feature available only to paid accounts. If you do not have a paid account, but are interested in upgrading, you can contact our Sales team

     

    Regards. 

    --

    Help others in the community by liking or hitting Select as Best if this response helped you.

    Expand Post
  • Albertd.38306 (Customer)

    Hi Diana - CloudFlare is only hosting our DNS, and is *not* a proxy for Okta. This worked before and has stopped working.

     

    image.png

    Expand Post
    • DianaL.19788 (Customer Support Online Community and Social Care)

      Hello @Albertd.38306 (Customer)​ , in this situation, I recommend that you open a Support ticket (Customer Support Account ID number required) so one of our engineers can analyze it and provide in-depth troubleshooting. You could also provide more details in a ticket that shouldn’t be given here, as this is a public space.

      Please note that opening a support ticket is a feature available only to paid accounts. If you do not have a paid account, but are interested in upgrading, you can contact our Sales team

       

      Regards. 

      --

      Help others in the community by liking or hitting Select as Best if this response helped you.

      Expand Post
  • KathyT.73511 (Anthropic Identity)

    Maybe you did this when you recreated your domains, but try re-applying the certificates again.

  • Albertd.38306 (Customer)

    I deleted two of the problematic domains (okta-dev, okta-qa) on Saturday, and only created them again today. The redirect is still broken on Okta's side so I have no idea of how to fix this.

    I am not sure how an integrator is intended to try and use Okta if there is zero support.

  • KathyT.73511 (Anthropic Identity)

    Have you opened a support ticket with Okta? Okta Support is really good about helping with these edge cases.

     

    This site is a community site where others can provide suggestions based on their experience. Since this is such an odd issue, it's likely that many of the community has not run into this issue before, but we have provided troubleshooting suggestions based on what we would try if we ran into the issue. If it was my issue, at this point I would open an Okta Support ticket.

     

    The other things I would try is to use a new domain, or apply for a new Okta trial org, but I don't know what your use case is nor if that is feasible.

     

    Expand Post
10 of 11

Loading
Brand custom domain redirecting to ".okta.com"