September 30, 2026 · 6 min read

How to use your own domain for bucket file links

A link like https://files.example.com/report.pdf looks trustworthy, survives a change of storage provider, and doesn't leak your bucket name. Every major provider can serve a bucket on your own domain with HTTPS, but each does it differently.

Cloudflare R2

The simplest of all. The domain must be a zone in the same Cloudflare account as the bucket.

  1. Open the bucket's Settings and select Add under Custom Domains.
  2. Enter files.example.com, review the DNS record and select Connect Domain.

Cloudflare creates the DNS record and certificate for you. Details in making an R2 bucket public.

Amazon S3 with CloudFront

S3 can't serve HTTPS on a custom domain by itself, so you put CloudFront in front of it:

  1. Request a certificate for files.example.com in AWS Certificate Manager in the us-east-1 region (CloudFront only uses certificates from there) and validate it through DNS.
  2. Create a CloudFront distribution with your bucket as the origin and Origin access control, so the bucket can stay private. Apply the bucket policy CloudFront suggests.
  3. Add files.example.com as an alternate domain name and choose the certificate.
  4. At your DNS provider, create a CNAME from files to the distribution's d….cloudfront.net address.

The S3 static website endpoint also accepts a CNAME, but only over plain HTTP and only when the bucket is named exactly like the domain, so CloudFront is the better route.

DigitalOcean Spaces

Enable the CDN for the Space and add a custom subdomain in its settings. If your domain's DNS is managed by DigitalOcean, it can issue a Let's Encrypt certificate automatically; otherwise upload your own certificate. Files are then served from https://files.example.com/key.

Backblaze B2

B2 serves public files at a URL like https://f003.backblazeb2.com/file/your-bucket/key. To use your own domain, the common approach is Cloudflare: add a proxied CNAME from files.example.com to your bucket's f00X.backblazeb2.com host, then a rewrite rule that adds /file/your-bucket in front of the path. Backblaze documents this setup and doesn't charge download fees for traffic served through Cloudflare.

After the domain works

  • Open a file at https://files.example.com/<key> in a private browser window to confirm it's public.
  • Use the domain as the base URL wherever you build links, so every link you share uses it.
  • Keep uploading through the provider's API endpoint. The custom domain is only for reading.

Common questions

Can I use the root domain instead of a subdomain?

Usually yes on Cloudflare R2, which can attach an apex domain. Most other setups rely on a CNAME, which is simpler on a subdomain like files.example.com.

Do old links break if I add a custom domain?

No. The provider's original address keeps working next to the custom domain. Only links you create afterwards use the new domain.

Can I move to another provider and keep my links?

Yes, that's one of the best reasons to use your own domain. Copy the files to the new bucket with the same keys, point the domain at it, and existing links keep working.