With the Summer '25 release, the setting "Redirect legacy (non-enhanced) My Domain hostnames" in My Domain Setup has been disabled. This change is part of Salesforce's preparation for the end of redirections for non-enhanced domains.
When this setting is disabled, legacy non-enhanced force.com site URLs no longer automatically resolve to the org's enhanced domain (*.my.site.com or *.my.salesforce.com), resulting in 404 errors for users or integrations still using the old URLs.
For organizations using legacy LiveAgent or Chat deployments, users may also encounter the following error in the browser console when attempting to initiate a chat session:
This CORS error occurs because the aura_prod.js file is loaded from the legacy force.com domain in the chat deployment code on the third-party site. The legacy domain performs a redirect to the new enhanced domain but does not set the required CORS headers, causing the browser to block the request and prevent the chat from launching.
As a temporary workaround, re-enable "Redirect legacy (non-enhanced) My Domain hostnames" in My Domain Setup (Setup > My Domain > My Domain Settings).
Only use this as a temporary measure. Ensure that end users and stakeholders are informed that the affected legacy URLs will no longer be supported after the Spring '26 major release, at which point this redirect setting will be permanently removed.
Use one of the following options in conjunction with re-enabling the legacy redirect setting to resolve the CORS issue for Chat:
Enable "Enable content delivery network (CDN) for Lightning Component Framework" via Setup > Session Settings.
When Lightning CDN is enabled, Salesforce loads the aura_prod.js file from the CDN rather than from the legacy force.com site domain. This eliminates the CORS issue caused by the redirect from the legacy domain to the enhanced domain without CORS headers.
Important: Review the considerations in Enable the Lightning CDN to Load Applications Faster before enabling CDN in your org.
Update your chat deployment on your third-party site to use current, non-legacy URL references:
*.force.com site URLs to use *.my.site.com URLs for your Experience sites.This eliminates the root cause by removing the dependency on the legacy force.com domain entirely.
005036916

We use three kinds of cookies on our websites: required, functional, and advertising. You can choose whether functional and advertising cookies apply. Click on the different cookie categories to find out more about each category and to change the default settings.
Privacy Statement
Required cookies are necessary for basic website functionality. Some examples include: session cookies needed to transmit the website, authentication cookies, and security cookies.
Functional cookies enhance functions, performance, and services on the website. Some examples include: cookies used to analyze site traffic, cookies used for market research, and cookies used to display advertising that is not directed to a particular individual.
Advertising cookies track activity across websites in order to understand a viewer’s interests, and direct them specific marketing. Some examples include: cookies used for remarketing, or interest-based advertising.