MDN wants to learn about developers like you:

この記事はまだボランティアによって 日本語 に翻訳されていません。ぜひ MDN に参加して翻訳を手伝ってください!
この記事を English (US) で読むこともできます。


Gets/sets the domain portion of the origin of the current document, as used by the same origin policy.


var domainString = document.domain;
document.domain = string;


// for document,
// this script closes the window
var badDomain = "";

if (document.domain == badDomain)
   window.close(); // Just an example - window.close() sometimes has no effect.
// For the URI the
// following sets domain to the string ""
var domain = document.domain;


This property returns null if the domain of the document cannot be identified.

Mozilla will let you set it to a superdomain of the current value, constrained by its base domain. For example, on it is possible to set it to "" but not "" or "org".

If this property is successfully set, the port part of the origin is also set to null.

Mozilla distinguishes a document.domain property that has never been set from one explicitly set to the same domain as the document's URL, even though the property returns the same value in both cases. One document is allowed to access another if they have both set document.domain to the same value, indicating their intent to cooperate, or neither has set document.domain and the domains in the URLs are the same (implementation). Were it not for this special policy, every site would be subject to XSS from its subdomains (for example, could be attacked by bug attachments on https://bug*


See also