Domain Security Feature
What is the main security feature for domain security?
The main security feature is dedicated to the securitization of the domain, ensuring that your campaign runs only on the defined domain. This feature is critical for maintaining the integrity and security of your campaigns.
This doesn't related to HTTPS which is enforced for all campaigns and domains.
What are the options available for domain security?
There are three options available for domain security:
- Default: This is applicable to all current customers. There is no additional security for the domain, meaning that campaigns can run on any platform, including any .qualifioRelatedDomain (e.g., .qualifioapp.com).
- Loose Mode: This option allows your campaign to run only on account-approved domains. Customers can request their Customer Success Manager (CSM) or the customer care team to add their domains to Qualifio, provided they have configured their domains to point to Qualifio servers. This setting enables a controlled environment where campaigns will need to operate within a set of pre-approved domains.
- Strict Mode: With this option, the campaign must run only on the domain specifically defined for the campaign, typically the website domain. This is the most secure option, ensuring that campaigns are tightly bound to a single, specified domain or subdomain used for publishing.
What does the default option imply in terms of security?
The default option does not grant additional security beyond the basic HTTPS protocol. It allows campaigns to be run on any platform without domain-specific restrictions.
How does the loose mode option enhance security?
The loose mode enhances security by limiting campaign execution to domains approved by the customer and added to Qualifio. This restricts campaign accessibility to a set of domains controlled and verified by the customer, reducing potential exposure to unauthorized domains.
What does the strict mode option offer?
The strict mode offers the highest level of domain security by restricting campaign execution to only the domain defined for the campaign. This ensures that campaigns are run exclusively on the intended domain, providing a significant security boost by preventing unauthorized domain usage.