Skip to content

The collection domain

The script and the collection endpoint are served at the COLLECT_URL address: by default, the administration address (PUBLIC_URL). This is the one the Installation tab puts in the tag.

<script defer src="https://stats.example.com/a.js" data-site="s_arvordemo001"></script>

Many publishers prefer to serve collection from a subdomain of their own site: stats.maison-arvor.fr.

  • Trust: the visitor, and their browser, see a request to the site they are visiting, not to a third party.
  • Blockers: blocklists target the known domains of measurement tools; a subdomain of the site is less known. It is not a way to get around a refusal: optOut() and the Global Privacy Control signal are still respected.
  • The measurement cookie is set by the script on the page’s domain anyway: the collection domain does not change its scope.
  1. With the site’s DNS provider, a CNAME record:

    stats.maison-arvor.fr. CNAME stats.example.com.
  2. In front of the instance, the proxy must serve this name over HTTPS. With the bundled Caddy, add the name to the site block in docker/Caddyfile (stats.example.com, stats.maison-arvor.fr { … }): Caddy obtains a certificate for each. Only /a.js, /p.js and /collect* need to respond there.

  3. Set COLLECT_URL to this address, if a single site uses it:

    Fenêtre de terminal
    COLLECT_URL=https://stats.maison-arvor.fr

    With several sites, each on its own subdomain, leave COLLECT_URL on the shared address and simply change the address in each site’s tag: the collection endpoint responds the same way under all its names.

  4. Update the site’s security policy: script-src and connect-src to the subdomain.

The collection endpoint still checks that the page belongs to the site’s declared domains (Origin header), whatever name it is called under. A collection subdomain does not allow another site to send data in its place.

eodia analytics is free software by Eodia.