Why you can't put a CNAME at the root of a domain

The apex is the bare domain, such as example.com rather than www.example.com. A CNAME says “this name is an alias for another name”, and the DNS rules say a name with a CNAME can have no other records. The apex always carries SOA and NS records, so a CNAME there contradicts the zone itself (RFC 1034 and RFC 1912).

Why it matters

Some DNS providers refuse the record outright. Others accept it, and resolvers then behave unpredictably: they may ignore your MX records, so mail stops arriving, or ignore TXT records such as SPF and domain verification. Different resolvers fail in different ways, which makes it look intermittent.

Common causes

How to fix it

  1. Run DNSLint and confirm the apex CNAME is flagged.
  2. If your host gave you IP addresses, replace the CNAME with A and AAAA records.
  3. If they only gave a hostname, use your DNS provider’s alias feature. It may be called ALIAS, ANAME or CNAME flattening. It looks like a CNAME to you but answers with plain address records.
  4. Alternatively, keep a CNAME on www and redirect the bare domain to www at your registrar or host.
  5. Check that your MX and TXT records are still present and answer correctly.

Check your domain