Relating to Lesson 1 - I wanted to show some images around what this actually looks like in HubSpot and a CDN acting as a proxy. The most important aspect of this - your active and live domain that users will see is also the domain you add to HubSpot but never ACTUALLY connect in your DNS. Instead, your proxy performs a request to the provided CNAME.
I’ve set up a proxy for a domain - tc.robertpainslie.com that points to an AWS Cloudfront CDN distribution. Depending on the URL path, it either proxies to an AWS S3 bucket or it proxies to HubSpot CMS.
So,[tc.robertpainslie.com/](http:// https://tc.robertpainslie.com/) shows a very simple web page originating from an S3 bucket and tc.robertpainslie.com/proxy-page shows a page served from HubSpot CMS
The pathway is:
Internet > tc.roberpainslie.com/proxy-page > AWS Cloudfront > HubSpot CMS
OR
Internet > tc.roberpainslie.com/ > AWS Cloudfront > AWS S3
1. In Cloudfront, I have an Origin that points to the proper HubSpot CNAME as directed by the HubSpot reverse proxy documentation

Then, there are Cloudfront behaviors that dictate which Origin is used for which paths:
2. In HubSpot, I have the domain tc.robertpainslie.com added to my Domain Manager - this is the exact domain I want to proxy! DO NOT create a new subdomain that is added to HubSpot - you want the initiating domain to be the exact same that you add to HubSpot. When connecting, the domain should already be live and hosting content over a secure connection. When this happens, HubSpot will detect the existing secure connection and ask you to pre-provision SSL - take the CNAME and TXT record and verify in your DNS. HubSpot provisions an SSL cert for the ‘tc.robertpainslie.com’ domain in the background even though this domain will never ACTUALLY be connected to HubSpot (because it will remain connected to your proxy).
![]()
You’ll see in the above screenshot that it says ‘Connected via reverse proxy’ - this will eventually show up (after successful requests are proxied and may take a few weeks to appear). But, it will initially show ‘Not connected’. To proceed with the process, for the specific domain:
- Edit > under, ‘Edit publishing status’ > Mark as ‘Ready for publishing’
- Under Domain Security Settings > ‘Require HTTPS’
and
3. Now, go to the HubSpot CMS page publisher and create and publish a page on the domain - (in my case, Proxy Page).
To get traffic to this page, a request routes to your proxy, and then you forward the request to the appropriate HubSpot CNAME. HubSpot CMS then looks up the appropriate page based on the domain and path in the HOST header, and boom - it routes back through your proxy and to the originating requester
Hope this helps anyone who is struggling with this setup



