Why a CNAME cannot live at your domain's apex
8 September 2026 · Jimmy
You want example.com to point at a hostname your CDN or load balancer gave you. You add a CNAME. Your DNS provider refuses it — or worse, accepts it, and your email quietly stops arriving.
This is not your provider being awkward. It is a rule in the DNS standard, and understanding why it exists makes the workaround obvious.
What a CNAME actually means
A CNAME does not mean "also answer with this". It means "this name is an alias; go and ask about that other name instead." A resolver that finds a CNAME abandons the name it asked about and restarts its query at the target.
That is the whole problem. If a name is an alias, it cannot also be anything else — because a resolver that sees the CNAME never looks at the rest.
RFC 1034 puts it plainly: if a CNAME record is present at a node, no other data should be present. Every implementation enforces it, because a name that is simultaneously an alias and not an alias has no defined answer.
Why the apex is special
The apex is the bare domain — example.com, not www.example.com. It is special because it is required to carry records that make the zone a zone:
- SOA — the start of authority, which defines the zone's serial number and timing
- NS — the delegation, naming the nameservers authoritative for it
Those cannot be removed. So the apex always has other data, which means the apex can never hold a CNAME. Not on any provider, not ever.
A subdomain has no such obligation. www.example.com carries nothing by default, so www can be a CNAME quite happily. That is why the same record works one label down and fails at the top.
What goes wrong when a provider allows it anyway
Some providers accept the record and let the zone go out broken. The failure is rarely the one people expect. Your website may keep working, because the CNAME resolves to something with an address. What breaks is everything else at the apex:
- MX records are ignored. Mail for the domain stops, or bounces at the sending server with no message on your side.
- TXT records disappear. SPF and DKIM lookups fail, so mail you do send starts landing in spam.
- CAA is unreadable, so certificate issuance may fail at renewal — weeks later, with no obvious cause.
The reason it is hard to diagnose is that nothing logs an error. Resolvers are behaving correctly. They were told the name is an alias, so they stopped reading.
The three ways around it
1. An A or AAAA record, if you have a stable address
If the thing you are pointing at has an IP address that does not change, use an A record. This is the simplest answer and it is often dismissed too quickly. Plenty of services publish stable addresses precisely so the apex can work.
The catch is obvious: if the provider changes the address, your domain breaks until you notice.
2. ALIAS, if your DNS provider offers it
An ALIAS record — some providers call it ANAME or CNAME flattening — looks like a CNAME to you and an A record to the world. The DNS provider resolves the target itself and answers with the addresses it finds, so the apex never carries a CNAME and nothing at the apex is shadowed.
Worth knowing: ALIAS is not in any standard. It is a feature of the authoritative server, which is why it must be resolved by your DNS host rather than by the resolver asking. That also means the resolution happens from your provider's network, not the visitor's — so for a service that returns different addresses in different regions, everyone may get the answer your provider sees.
For most people, on a CDN with a global anycast address, that does not matter. For a service that steers by geography, it can.
3. Redirect the apex instead
If the apex only ever needs to send people to www, you do not need a DNS answer at all — you need an HTTP redirect. Point the apex at something small that returns 301 https://www.example.com/, and put the real CNAME on www where it is legal.
This is the right answer more often than people admit. It also means one canonical hostname, which is better for search engines anyway.
The short version
| You want | At www | At the apex |
|---|---|---|
| Point at a hostname | CNAME | ALIAS, or redirect |
| Point at an address | A / AAAA | A / AAAA |
| Point at a hostname that moves | CNAME | ALIAS |
If you take one thing away: the apex is not an ordinary name. It carries the records that make the zone exist, and a CNAME would tell the world to ignore all of them.
KumoDNS supports ALIAS at the apex on Growth and above. The record types by plan chart shows what each tier can create.
Need somewhere to put these records?
KumoDNS hosts one zone free — no card, no time limit.