Skip to main content
There are three domains in play, and only two of them are yours to configure.
The sign-in address is a neutral domain that carries no Dialtu branding, shared across partners. Your users pass through it during login — the page itself shows your logo and colours. You don’t configure it and there are no DNS records for it.

Your own app domain

Settings → Customization → Custom domains. We provision the certificate and the CDN; you add two DNS records at your registrar.
Add a custom domain modal explaining that subdomains work with any DNS provider while apex domains need Cloudflare, Route 53 or DNSimple

Entering the domain — subdomains work anywhere, apex domains don't

Enter the domain

Something like app.yourcompany.com.
Use a subdomain, not your bare domain. Most registrars — GoDaddy, Namecheap — reject CNAME records at the apex. The panel will make you tick a box to confirm your DNS supports CNAME flattening or ALIAS records if you insist.

Add the DNS records, as they appear

Two CNAMEs are needed in all, but the panel reveals them one stage at a time:
Custom domains sub-tab with a domain awaiting DNS, a four-step tracker and the certificate validation CNAME record

Awaiting DNS — the validation record, with a progress tracker above it

Come back for the second record. If you add the validation CNAME and walk away, the certificate issues and setup then sits at CDN propagation indefinitely, waiting for an alias record nobody has added.

Wait

The status moves through Awaiting DNS → Validating → Cert issued → Deploying CDN → Live.You can close the page — it carries on in the background. CDN deployment usually takes 5 to 15 minutes.
Once it’s Live, invitation emails start pointing at your address instead of the dialtu.com one, automatically.
If the DNS records aren’t in place within 72 hours, the setup is marked failed. Check status resets it and tries again — no need to start over.
Removing a domain takes about 25 minutes to fully unwind, after which that address stops serving your workspace. The yourname.dialtu.com address keeps working throughout.

Sending invitations from your own domain

Settings → Customization → Sending domain. By default invitations come from a platform address. Verify a domain once and every invite goes out as you.
Sending domain sub-tab with an address pending DNS and its three DKIM CNAMEs, MAIL FROM MX, SPF and DMARC records

All six records, each with a copy button

You give a From addressinvites@yourcompany.com — and optionally a From name. In return you get up to six DNS records to add: Add them, click Verify, and the status moves Pending DNS → Verifying → Verified. DNS changes can take up to an hour to propagate.
Nothing changes until the domain is verified. The sender address only switches once verification succeeds, so a half-finished setup can’t break your invitations.
Remove the identity and invitations revert to the platform sender. You never need SMTP credentials — verification is all that’s required.

If you see a sandbox warning

A banner saying email is in limited or sandbox mode means invitations to new recipients may not deliver. That’s an account-level limit on the environment, not something you can fix — contact Dialtu.

What’s branded and what isn’t

Your logo, your primary colour, your company name, and a link to your address. This is the email your clients actually receive, so it’s the one that matters most.
They come from your address once your sending domain is verified, but the body uses the stock template — no logo, no colours. The web pages they lead to are branded.

Next step

People and access

Now invite someone and see the branding in action.