
If you have ever tried to add a CNAME record at the root domain — for example pointing yourdomain.com directly to yourapp.provider.com — and found that your DNS server refuses or breaks, that is because CNAME records at the apex domain are prohibited by RFC standards. This article explains why, and how to solve it using CNAME Flattening, ALIAS records, or Cloudflare.
Why CNAME at the Apex Domain Causes Problems
According to RFC 1034, a CNAME record cannot coexist with any other record types at the same name. However, the apex domain (also called root or naked domain, e.g., yourdomain.com) is always required to have NS and SOA records. This creates a direct conflict with any CNAME placed there.
Additionally, MX records for email are commonly added at the root domain, making it technically impossible to place a CNAME at @ in standard DNS.
Common Use Cases That Hit This Problem
Services that require pointing the root domain to a hostname rather than an IP:
- AWS Elastic Load Balancers (e.g.,
xxx.elb.amazonaws.com) - GitHub Pages (
yourusername.github.io) - Netlify, Vercel, or Cloudflare Pages
- CDN endpoints with frequently changing IPs
What is CNAME Flattening?
CNAME Flattening (also known as ANAME or ALIAS) is a technique where the DNS provider resolves the CNAME chain on the server side and returns the final A record to the client. From the client's perspective, it receives a normal A record response, while the DNS server handles the CNAME resolution internally in real time.
The process: Resolver queries yourdomain.com → DNS provider server looks up the IP from the CNAME target (yourapp.provider.com) in real time → Returns that IP as an A record → Client gets the correct IP without seeing any CNAME in the response.
Three Ways to Solve the Problem
Option 1 — Use Cloudflare (Recommended)
Cloudflare supports CNAME Flattening automatically for root domains on the Free Plan. When you use Cloudflare as your DNS provider:
- Add your domain to Cloudflare
- Go to DNS → Add Record
- Choose Type CNAME, set Name to
@, enter the target hostname - Toggle Proxy on (orange cloud) or DNS Only — both use CNAME Flattening at the apex
Option 2 — Use an ALIAS Record (Supported DNS Providers)
Some DNS providers such as DNSimple, Amazon Route 53, and Dyn support ALIAS records, which behave like CNAME Flattening but are exposed as a distinct record type. Check your DNS provider's documentation to see if ALIAS is supported.
Option 3 — Use an A Record with IP Monitoring
If the target's IP address rarely changes, you can manually query the IP of the target hostname, add it as an A record, and set up a monitoring script to update the record when the IP changes. This is the least elegant solution but works with any DNS provider.
Summary: The easiest and free solution is to use Cloudflare as your DNS provider. Cloudflare supports CNAME Flattening out of the box on the Free Plan. If your current DNS provider does not support ALIAS records, simply change your domain's nameservers to point to Cloudflare.
CNAME vs ALIAS vs ANAME: What's the Difference?
- CNAME — RFC standard, subdomains only, not root domain, client performs chain resolution
- ALIAS — DNSimple's name for CNAME Flattening at the root domain
- ANAME — The name used by DNS Made Easy and some other providers, works the same as ALIAS
- CNAME Flattening — Cloudflare's technique that resolves CNAME chains server-side automatically
How to Verify Whether Your DNS Provider Supports CNAME Flattening
Before migrating DNS or choosing a new provider, you can test whether CNAME Flattening is active using the dig command:
# Check whether the root domain returns an A record or a CNAME
dig yourdomain.com A
# If the answer section shows a CNAME, the provider is NOT flattening
# If it shows an A record directly, flattening is working
# Deeper trace for investigation
dig +trace yourdomain.com
If the response contains a CNAME record in the answer section when querying the root domain, the provider does not support flattening. Some strict RFC-compliant resolvers or email systems may reject or mishandle this. Switching to Cloudflare or another flattening-capable provider is the recommended fix.
Providers supporting CNAME Flattening / ALIAS: Cloudflare (free), DNSimple, Amazon Route 53, Dyn, NS1, and Bunny DNS. Check your current provider's documentation for the terms "ALIAS record" or "ANAME record."
DNS Provider Comparison for CNAME Flattening
| Provider | Flattening Support | Record Name | Cost |
|---|---|---|---|
| Cloudflare | ✓ Supported | CNAME (auto-flattened) | Free |
| DNSimple | ✓ Supported | ALIAS | Paid plans |
| Amazon Route 53 | ✓ Supported | Alias Record | Pay-per-use |
| Generic registrar DNS | ✗ Not supported | — | — |
CNAME Flattening and Email Records: What You Need to Know
A common misconception is that CNAME Flattening allows you to route MX records through a CNAME. This is incorrect. CNAME Flattening only solves the problem of pointing the root domain to a web service hostname — it does not change the rules for MX records.
- MX records must point directly to a hostname — RFC explicitly forbids CNAME as an MX target. Your email provider's hostname must be set as the MX value directly.
- SPF at the root domain — SPF uses a TXT record which coexists fine with ALIAS. No conflict.
- DKIM selectors — Always on a subdomain (e.g.,
mail._domainkey.yourdomain.com), so CNAME is allowed and no flattening is needed. - DMARC — Uses a TXT record at
_dmarc.yourdomain.com, also a subdomain. No issues.
In short: CNAME Flattening is the right tool for pointing your apex domain to a CDN, load balancer, or static hosting endpoint. Email routing (MX, SPF, DKIM, DMARC) operates independently and is unaffected by flattening.
Impact on SOA, MX Records, and DNSSEC
When using CNAME Flattening via Cloudflare or an ALIAS record, you can still have MX, SOA, TXT, and other records at the root domain simultaneously. Unlike a standard CNAME, ALIAS and CNAME Flattening do not break the co-existence rules. However, if you use DNSSEC, verify that your provider supports ALIAS combined with DNSSEC before proceeding.
Register a Domain with Flexible DNS Management
AsiaGB supports full DNS management for all record types across .com, .co.th, .in.th, and over 500 other domain extensions. Register a .com domain for just 500 THB/year.
Register a Domain