September 30, 2026 · 6 min read
How to use your own domain for bucket file links
A link like https://files.example.com/report.pdf looks trustworthy, survives a change of storage provider, and doesn't leak your bucket name. Every major provider can serve a bucket on your own domain with HTTPS, but each does it differently.
Cloudflare R2
The simplest of all. The domain must be a zone in the same Cloudflare account as the bucket.
- Open the bucket's Settings and select Add under Custom Domains.
- Enter
files.example.com, review the DNS record and select Connect Domain.
Cloudflare creates the DNS record and certificate for you. Details in making an R2 bucket public.
Amazon S3 with CloudFront
S3 can't serve HTTPS on a custom domain by itself, so you put CloudFront in front of it:
- Request a certificate for
files.example.comin AWS Certificate Manager in the us-east-1 region (CloudFront only uses certificates from there) and validate it through DNS. - Create a CloudFront distribution with your bucket as the origin and Origin access control, so the bucket can stay private. Apply the bucket policy CloudFront suggests.
- Add
files.example.comas an alternate domain name and choose the certificate. - At your DNS provider, create a CNAME from
filesto the distribution'sd….cloudfront.netaddress.
The S3 static website endpoint also accepts a CNAME, but only over plain HTTP and only when the bucket is named exactly like the domain, so CloudFront is the better route.
DigitalOcean Spaces
Enable the CDN for the Space and add a custom subdomain in its settings. If your domain's DNS is managed by DigitalOcean, it can issue a Let's Encrypt certificate automatically; otherwise upload your own certificate. Files are then served from https://files.example.com/key.
Backblaze B2
B2 serves public files at a URL like https://f003.backblazeb2.com/file/your-bucket/key. To use your own domain, the common approach is Cloudflare: add a proxied CNAME from files.example.com to your bucket's f00X.backblazeb2.com host, then a rewrite rule that adds /file/your-bucket in front of the path. Backblaze documents this setup and doesn't charge download fees for traffic served through Cloudflare.
After the domain works
- Open a file at
https://files.example.com/<key>in a private browser window to confirm it's public. - Use the domain as the base URL wherever you build links, so every link you share uses it.
- Keep uploading through the provider's API endpoint. The custom domain is only for reading.
Common questions
Can I use the root domain instead of a subdomain?
Usually yes on Cloudflare R2, which can attach an apex domain. Most other setups rely on a CNAME, which is simpler on a subdomain like files.example.com.
Do old links break if I add a custom domain?
No. The provider's original address keeps working next to the custom domain. Only links you create afterwards use the new domain.
Can I move to another provider and keep my links?
Yes, that's one of the best reasons to use your own domain. Copy the files to the new bucket with the same keys, point the domain at it, and existing links keep working.