document.domain in new projects. Use location.hostname when you only need the current hostname, and use controlled cross-origin messaging rather than weakening origin checks.document.domain historically exposed the domain portion of the document origin and also allowed pages on related subdomains to alter their effective domain. That origin-relaxation behavior is the main reason the API is deprecated.
const hostname = location.hostname;
console.log(hostname);
Older code may still contain:
const domain = document.domain;
If the goal is only to identify the host on which the script is running, use:
const hostname = location.hostname;
For more address properties, see document.URL and location.
Legacy applications sometimes set both subdomains to a shared parent domain:
// Legacy pattern — do not use in new code
document.domain = "example.com";
This weakens the normal same-origin boundary and complicates modern browser isolation. It can also fail in sandboxed or origin-isolated contexts. Do not add this pattern to new applications.
When two windows or frames from different origins must exchange controlled data, use postMessage() with an explicit target origin and validate the sender.
otherWindow.postMessage({ type: "status" }, "https://app.example.com");
window.addEventListener("message", (event) => {
if (event.origin !== "https://app.example.com") return;
console.log(event.data);
});
| Property | Example result |
|---|---|
location.hostname | www.example.com |
location.host | www.example.com:8080 when a port is present |
location.origin | https://www.example.com |
Author & Instructor at plus2net
I write and maintain practical tutorials on Python, PHP, SQL, JavaScript, HTML, jQuery, and web development at plus2net. The tutorials focus on clear explanations, working examples, and code that readers can test and adapt while learning.
| danish | 19-03-2015 |
| Thanks very much solve the problem :) God bless you | |