VM Domain Lock

Pro
v6.13.0+

Watch

Obfuscator.io Advanced Defenses: Self-Defending, Debug Protection, Domain Lock

Watch on YouTube

The vmDomainLock option restricts the obfuscated code to a list of specific domains and subdomains. When the protected code runs on a domain that is not allow-listed, the default reaction (break) redirects the browser to vmDomainLockRedirectUrl (default about:blank), and protected calls stop working even if that redirect is suppressed. With decoy there is no redirect and protected calls return incorrect results. The reaction follows the domain category of vmDefenseReaction (break, decoy, or none), so you can tune or observe it rather than take only the redirect.

This is the VM-aware counterpart of the non-VM domainLock option. When vmObfuscation is on, the non-VM domainLock is ignored - use vmDomainLock instead.

Browser-only feature

VM Domain Lock relies on window.location and has no effect when target is node, bytenode, or service-worker. A service worker is the subtle case: it has no window, so VM Domain Lock does not apply - but it is still fetched over HTTP(S), so browserEnvironment still does.

Supported entry shapes:

  • Exact host - example.com
  • Wildcard subdomain - .example.com matches example.com and any subdomain
  • Specific subdomain - app.example.com

Leaving vmDomainLock empty disables the check entirely - every domain runs. See also non-VM domainLock for non-VM builds.