Why you can't put a CNAME at the root of a domain
The apex is the bare domain, such as example.com rather than www.example.com. A CNAME says “this name is an alias for another name”, and the DNS rules say a name with a CNAME can have no other records. The apex always carries SOA and NS records, so a CNAME there contradicts the zone itself (RFC 1034 and RFC 1912).
Why it matters
Some DNS providers refuse the record outright. Others accept it, and resolvers then behave unpredictably: they may ignore your MX records, so mail stops arriving, or ignore TXT records such as SPF and domain verification. Different resolvers fail in different ways, which makes it look intermittent.
Common causes
- Pointing the bare domain at a hosting or CDN provider that only gave you a hostname, not an IP address.
- Copying the setup for
www, where a CNAME is fine, onto the apex.
How to fix it
- Run DNSLint and confirm the apex CNAME is flagged.
- If your host gave you IP addresses, replace the CNAME with A and AAAA records.
- If they only gave a hostname, use your DNS provider’s alias feature. It may be called ALIAS, ANAME or CNAME flattening. It looks like a CNAME to you but answers with plain address records.
- Alternatively, keep a CNAME on
wwwand redirect the bare domain towwwat your registrar or host. - Check that your MX and TXT records are still present and answer correctly.