VM Domain Lock
Watch
Obfuscator.io Advanced Defenses: Self-Defending, Debug Protection, Domain Lock
The vmDomainLock option restricts the obfuscated code to a list of specific domains and subdomains. When the protected code runs on a domain that is not allow-listed, the default reaction (break) redirects the browser to vmDomainLockRedirectUrl (default about:blank), and protected calls stop working even if that redirect is suppressed. With decoy there is no redirect and protected calls return incorrect results. The reaction follows the domain category of vmDefenseReaction (break, decoy, or none), so you can tune or observe it rather than take only the redirect.
This is the VM-aware counterpart of the non-VM domainLock option. When vmObfuscation is on, the non-VM domainLock is ignored - use vmDomainLock instead.
Browser-only feature
VM Domain Lock relies on window.location and has no effect when target is node, bytenode, or service-worker. A service worker is the subtle case: it has no window, so VM Domain Lock does not apply - but it is still fetched over HTTP(S), so browserEnvironment still does.
Supported entry shapes:
- Exact host -
example.com - Wildcard subdomain -
.example.commatchesexample.comand any subdomain - Specific subdomain -
app.example.com
Leaving vmDomainLock empty disables the check entirely - every domain runs. See also non-VM domainLock for non-VM builds.
