Question
First-party CNAME: can server-set AMCV/s_ecid be scoped per subdomain, or always registrable domain?
Setup: one Org, five Launch properties serving five subdomains under one registrable domain (www, oem, my, … .example.com). First-party collection via CNAME smetrics.example.com. ECID v5.5.0, AppMeasurement 2.27.
Goal: each subdomain should start with no Adobe identity cookie before its own consent is given, and ideally identity should not be shared across the subdomains.
What I've confirmed:
- The server (CNAME) sets both
AMCVands_ecidwithDomain=example.com(registrable domain). These bleed to every subdomain. - The ECID
cookieDomainconfig scopes only the client-side AMCV to the subdomain; it has no effect on the server-set cookies. Setting it to the literal subdomain, the Set-Cookie response still returnsDomain=example.com. (Adobe docs also listcookieDomain/cookieDomainPeriodsas retired.)
My open question:
- If I provision a per-subdomain CNAME (e.g.
smetrics.oem.example.comas trackingServerSecure on the OEM property), will the collection server set the cookies on.oem.example.com, or does it always reduce to the registrable domain regardless of CNAME depth? - If per-subdomain scoping isn't possible: has anyone disabled the server-side first-party ECID cookie and relied only on the client-side host-scoped AMCV? What was the impact on identity persistence and ITP?
Has anyone achieved genuine per-subdomain cookie isolation under a single Org, or is shared identity across subdomains inherent to the ECID service?