---
title: Manage email domains
description: >-
  Add, remove, and sync the email domains that route users to an SSO connection,
  enable per-connection auto-sync for new members, and understand public-domain
  restrictions.
sidebar:
  order: 2
---

**Email domains** decide who uses an SSO connection. When someone enters an email address, Fuxam checks its domain (the part after the @). If it matches a domain on an active [enterprise connection](/docs/fuxam-web/settings/single-sign-on/set-up-sso), Fuxam routes them to that connection's identity provider. If it matches nothing, the person signs in with a Fuxam password.

This guide covers adding and removing domains, syncing them from your existing users, keeping them in sync automatically as people join, and the limits Fuxam places on public domains.

:::info
Domains are managed per connection under **Settings → Subdomain SSO**. You need the **Update settings** permission.
:::

## Add or remove domains manually

1. Open **Settings → Subdomain SSO** and select the connection you want to edit.

2. In the **Email domains** field, type a domain (for example, `university.edu`) and press Enter. It appears as a badge.

3. To remove a domain, select the × on its badge.

4. Save your changes.

When a connection has many domains, only the first few show as badges and the rest collapse into a **+N more** badge. Hover or focus that badge to see — and remove — the remaining domains.

:::note
A domain can belong to only one connection at a time. If you try to add a domain that another connection already claims, Fuxam skips it and tells you which domains were left out so routing stays unambiguous.
:::

## Sync domains from your existing users

Instead of typing every domain, you can let Fuxam discover them from the people already in your institution. This is the fastest way to seed a connection's domains accurately.

1. Open the connection and find the **Email domains** field.

2. Select the **Sync email domains** button (the refresh icon at the end of the field).

3. Fuxam scans your institution's users, collects the domains from their email addresses, and adds the ones that are available.

4. Review the result and save.

Domains that are already claimed by another connection, or are otherwise unavailable, are **skipped** — Fuxam tells you which ones and why, so nothing is silently dropped.

## Auto-sync new users

Manual and one-off syncing keep a connection current only until the next person joins with a new domain. **Auto-sync new users** keeps it current going forward: when a new member is added to your institution, Fuxam adds their email domain to the connection automatically — no manual step.

New members trigger auto-sync when they are added through the usual paths, including creating an admin user, creating an institution user with immediate activation, and accepting an application in Apply.

1. Open the connection under **Settings → Subdomain SSO**. The connection must be **active** to enable auto-sync.

2. Enable the **Auto-sync new users** switch.

3. Confirm the prompt. Fuxam explains what will happen before turning it on.

:::info
Auto-sync is set **per connection**. Turning it on for one connection does not affect others. Deleting a connection clears its auto-sync setting automatically.
:::

:::tip
Enable auto-sync on the connection that represents your main organizational identity provider. Leave it off for narrow, special-purpose connections where you want to control the domain list by hand.
:::

## Public email domains

Public providers — such as `gmail.com`, `outlook.com`, or `yahoo.com` — are shared by people all over the world, so routing them to your identity provider would send strangers to your login. To prevent that, Fuxam restricts public email domains: unless your institution is explicitly allowed to use them, public domains are not added by manual entry, by **Sync email domains**, or by **Auto-sync new users**.

The domains field and the auto-sync switch show a short note when public domains are restricted, so you know why a `gmail.com` address was skipped. Use domains your organization actually controls.

## How routing decisions are made

If **Allow subdomains** is enabled on a connection, sub-domains of its listed domains (for example, `mail.university.edu`) also match. See [Set up an SSO connection](/docs/fuxam-web/settings/single-sign-on/set-up-sso) for that and other per-connection options.

## Troubleshooting

| Symptom | Likely cause | What to check |
|---|---|---|
| A domain won't add | Already claimed by another connection, or it's a public domain | Fuxam names skipped domains and the reason; remove it from the other connection or use a domain you control |
| **Sync email domains** added fewer domains than expected | Some were skipped as claimed, unavailable, or public | Read the skip summary shown after syncing |
| New members still land on password sign-in | Auto-sync is off, or the connection is inactive | Enable **Auto-sync new users** on an active connection |
| A `gmail.com` (or similar) address never routes to SSO | Public domains are restricted for your institution | Expected — route only domains your organization owns |

## Related pages

**[Set up an SSO connection](/docs/fuxam-web/settings/single-sign-on/set-up-sso)**

Create, configure, and activate the connection your domains route to.

**[Single sign-on (SSO)](/docs/fuxam-web/settings/single-sign-on)**

How SSO, connections, and domains fit together.

**[Create a user](/docs/fuxam-web/base/user-management/create-a-user)**

How new members are added — the events that can trigger domain auto-sync.
