Contact

What is Subdomain?

Definition

A subdomain is a label added to the left of a domain name and defined in DNS as its own host, like "blog" in blog.example.com. Browsers and search engines treat a subdomain as a separate host: robots.txt, cookie scope and URL-prefix properties in Search Console all work at host level. Compared with a subfolder, a subdomain is more independent technically but more fragmented to manage.

Also known as: sub-domain, subdomain vs subfolder, subdomain vs subdirectory

Tree showing a registered domain with subdomains such as www, blog, shop and api, plus nested subdomains below api

Anatomy of a hostname

In help.example.co.uk, co.uk is the public suffix, example.co.uk is the registered domain and help is the subdomain. It is easy to forget that www is a subdomain too. Subdomains cost nothing extra to register; they are just records in the domain's DNS zone:

help.example.co.uk.  3600  IN  CNAME  example.helpdesk-vendor.example.
app.example.co.uk.   3600  IN  A      203.0.113.10

The first line hands the subdomain to a third-party service through a CNAME record; the second points it at an IP address. That flexibility is the main reason subdomains exist: each one can live on its own server, platform or vendor.

Subdomain or subfolder?

SEO folklore is full of absolutes, from "Google penalizes subdomains" to "subdomains are always stronger". Google has published no such rule. Its documentation on multi-regional sites lists the options with pros and cons: subdomains are easy to set up, allow different server locations and make it easy to separate sites; subdirectories are low maintenance because they share a host, but separating sites is harder.

The decision is better made on concrete, operational differences:

AreaSubdomain (blog.example.com)Subfolder (example.com/blog/)
robots.txtEach host needs its own fileThe main site's file applies
Search ConsoleSeparate URL-prefix property; a Domain property covers every subdomainPart of the main property
Favicon and site name in GoogleCan have its ownInherits the main site's
InfrastructureCan run on a separate server, CMS or SaaS productSame application, or a reverse proxy in front
AnalyticsMay need cross-domain measurement settingsStays in one property

In practice a subdomain makes sense when content and infrastructure really are separate: a SaaS application under app., a vendor-hosted help center, a status page. A blog or resource library that supports the main site's topics is usually simpler to run, link and measure in a subfolder. Language and country setups have their own trade-offs, covered under international SEO.

Subdomains and web security

Two browser concepts matter here. An origin is scheme plus host plus port, so www.example.com and app.example.com are different origins. A site is scheme plus registrable domain, so the same two hosts are same-site. That is why subdomains are not strangers to each other under SameSite cookie rules.

The common mistake is scoping cookies too broadly. A session cookie set with Domain=example.com is sent to every subdomain, so a single subdomain that hosts user content or is delegated to a vendor can see it. Omit Domain and the cookie stays host-only; cookies with the __Host- prefix are not allowed a Domain attribute at all.

The second risk is subdomain takeover. If a CNAME keeps pointing at a service you have shut down, someone else may be able to claim that name with the same provider and serve their own content on your subdomain. MDN's guide to subdomain takeovers gives a simple order of operations: when provisioning, claim the resource at the provider first and create the DNS record last; when deprovisioning, remove the DNS record first. An inventory of every subdomain and the provider behind it closes most of the gap.

Related terms

← Back to the glossary