Here's an overview of the Secure Sockets Layer (SSL) security protocol certification and how you can set up an SSL certificate in your Organization.
SSL certificates keep online interactions private even though they travel across the public Internet, and they give your visitors the confidence to transact with your website. SSL validates site identity and secures data in transit. All Marketing Cloud domains should be secured with SSL before use.
| cloud.<custom domain>.com | cloud subdomains serve pages from the CloudPages landing pages product |
| click.<custom domain>.com | click subdomains are used to generate subscriber-specific click-tracking URLs |
| view.<custom domain>.com | view subdomains are used to generate 'View in Browser' links when the %%view_email_url%% Personalization String is called |
| image.<custom domain>.com | image subdomains serve images and related assets stored in Content Builder |
SSL is not included in our Sender Authentication Package but can be purchased as an add-on to secure the URLs described above.
NOTE: You will need to complete the configuration of your Sender Authentication Package (SAP) before you can set up SSL for those domains.
a. Marketing Cloud purchases the SSL certificate on your behalf via DigiCert
b. Provide your own certificate (Not supported on image subdomains)
We recommend allowing Marketing Cloud purchase the certificate on your behalf. This has the quickest turnaround, and makes renewal seamless.
An SSL SKU purchase is required even if the certificate is customer-supplied.
If you plan to use Marketing Cloud-purchased certificates, use the Domain SSL Certificates page in Setup to quickly secure your domain.
CAA records control the list of certificate authorities (CAs) allowed to issue certificates on behalf of a domain. When no CAA records exist, all CAs can issue on a domain's behalf. When any CAA record exists, the CAs allowed to issue on behalf of that domain and its children are limited to those explicitly allowed by these records.
If CAA records exist and Salesforce-supplied certificates are used to secure custom domains on self-hosted DNS, ensure that this record is placed:
CAA 0 issue "digicert.com"
The record should be inserted at the SAP domain level or higher.
CAA record restrictions can sometimes be inserted by network administrators unbeknownst to Marketing Cloud SAP owners. If you are using Salesforce-supplied certificates, it's recommended that your DNS or security admins be made aware of this so that any CAA record changes are made in accommodation of this requirement.
000387921

We use three kinds of cookies on our websites: required, functional, and advertising. You can choose whether functional and advertising cookies apply. Click on the different cookie categories to find out more about each category and to change the default settings.
Privacy Statement
Required cookies are necessary for basic website functionality. Some examples include: session cookies needed to transmit the website, authentication cookies, and security cookies.
Functional cookies enhance functions, performance, and services on the website. Some examples include: cookies used to analyze site traffic, cookies used for market research, and cookies used to display advertising that is not directed to a particular individual.
Advertising cookies track activity across websites in order to understand a viewer’s interests, and direct them specific marketing. Some examples include: cookies used for remarketing, or interest-based advertising.