Domain masking proxy for cold outreach

Cold email runs on secondary domains: you send from yourbrand-hq.com so that yourbrand.com — the domain your business, your deliverability, and your Google Workspace depend on — never accumulates spam complaints. But a secondary domain that hosts nothing looks exactly like what it is. Spam filters visit the links in your emails; prospects check the domain before they reply. A parked page or a naked redirect to your primary site undoes the separation the secondary domain was supposed to create.

A domain masking proxy closes that gap. Twins Proxy serves your primary website's landing pages under each secondary domain's own hostname, behind a valid wildcard certificate. The visitor sees yourbrand-hq.com in the address bar, a padlock, and your real content. Your primary domain appears nowhere — not in a redirect chain, not in the certificate, not in the DNS.

Why redirects give the game away

The common shortcut is domain forwarding: a 301 redirect from every secondary domain to the primary site. It works for a human on a good day, and it fails everywhere that matters:

Filters follow redirects. Corporate gateways like Proofpoint, Barracuda, and Mimecast resolve the links in inbound mail. A redirect hands them the mapping from every secondary domain to your primary — turning one domain's reputation problem into everyone's.

Spoofing alerts. When many domains forward to one site, providers can flag the pattern to the primary domain's owner as suspected spoofing — an alarming notice generated by your own infrastructure.

The address bar changes. A prospect who clicked yourbrand-hq.com and landed on yourbrand.com just learned your outreach and your business are two different domains — the question you least want raised mid-deal.

Masking has none of these failure modes, because there is no redirect: the response is served under the hostname that was requested. The full comparison is in Domain masking vs domain forwarding.

What Twins Proxy automates

DNS, four ways. Connect Cloudflare and records are created and verified for you; or delegate one permanent CNAME and never touch DNS again; or paste TXT records by hand. Every path ends with the same verified, routed domain.

Wildcard certificates, hands off. Each domain gets an apex + wildcard certificate from Let's Encrypt, ZeroSSL, or Google Trust Services — issued via DNS-01, renewed automatically, revoked cleanly when a domain is removed. You can also import certificates you already own.

Per-domain hostnames. Serve exactly the hostnames you want — apex, www, a tracking subdomain like go.yourbrand-hq.com, or an opt-in wildcard that catches every subdomain. Hostnames are added and removed through the dashboard or the API, and the wildcard certificate already covers all of them.

Origin flexibility. Point each domain at any landing page or site. Origins behind a WAF or bot protection can allowlist the proxy with a per-site identity header.

Search engines kept out, by default. Masked domains send X-Robots-Tag: noindex, nofollow on every response — including the HTTP redirect — so they're never indexed as duplicate content of your primary site. Indexing is a per-domain toggle if you ever want it on.

Your infrastructure, if you want it. On the Freedom plan a one-line installer turns any VM into a serving node: your IP, your bandwidth, an effectively unlimited domain count — while DNS, certificates, and routing stay automated in the control plane. Or add a dedicated static edge IP to any paid plan for $25/month.

API-first. Everything the dashboard does — domains, hostnames, DNS checks, certificates — is a documented REST API, built for agencies managing domains in bulk.

Pricing that scales like outreach does

Domain masking here is the product, not a feature gated behind a deliverability suite. Free gets your first domain live — no card required. Basic is $15/month for 10 domains, Pro is $39/month for 25, and Freedom is $25/month with your own node and no per-domain ceiling that outreach volume will realistically hit. Extra domain packs, bandwidth, and dedicated IPs stack as add-ons. Full details on the pricing section.

Frequently asked questions

What is a domain masking proxy?

A service that serves your primary website's content under a secondary domain's own hostname. The visitor — human or spam filter — sees the secondary domain, a valid certificate, and a real website. No redirect to the primary domain ever happens.

Is this the same as "masked domains" for cold email?

Yes — masked domains, secondary domains, alias domains, and outreach domains all describe the same setup: alternate domains used for sending so the primary stays clean. The masking proxy is what makes those domains look and behave like real websites.

Will Google index my masked domains as duplicate content?

No — by default, Twins Proxy sends X-Robots-Tag: noindex, nofollow on every response from a masked domain, so search engines skip it and your primary domain stays the only indexed copy. Masked domains exist for the links in your email, not for ranking — but if you do want one indexed, it's a per-domain toggle.

How long does setup take?

With a connected Cloudflare zone: minutes — DNS records, validation, and certificate issuance are fully automated. Manual DNS adds however long your records take to propagate.

Can I bring existing certificates?

Yes — import any certificate + key pair and Twins Proxy serves it, or let it issue and renew wildcards automatically.

Put your first masked domain live →