What is CNAME Record?
Definition
A CNAME (canonical name) record is a DNS record that points a name at another domain name instead of an IP address; the resolver continues the lookup at the target and returns its A/AAAA records. It is typically used to connect subdomains such as www or shop to a hosting, CDN or SaaS provider. By standard, a CNAME cannot coexist with other records on the same name, so it cannot sit at the zone apex.
Also known as: CNAME, canonical name record, DNS alias, alias record

Pointing at a name, not an address
An A record binds a name to an IP address. A CNAME says “the real name for this is over there,” and the resolver restarts the lookup at the target:
shop.example.com. 3600 IN CNAME stores.provider-example.net.
stores.provider-example.net. 300 IN A 198.51.100.25The benefit is that the provider keeps control of the addresses. When your store platform, host or CDN renumbers its servers, you change nothing. That is why SaaS products almost always ask for a CNAME when you connect a custom domain.
Why the zone apex cannot be a CNAME
RFC 1034 requires that a name holding a CNAME hold no other data. The zone apex (example.com itself) must carry SOA and NS records, and usually MX for mail and TXT for verification too. A CNAME cannot live alongside them, so a standards-compliant zone has no CNAME at the apex. Some control panels let you enter one anyway; the outcome can be mail or verification quietly breaking.
The same rule applies further down. If www is a CNAME, do not try to add TXT or MX records to www. And MX and NS targets should be names with address records, not aliases.
CNAME flattening and ALIAS records
Pointing an apex at a provider hostname is such a common need that DNS providers built their own workarounds. You enter something CNAME-like at the apex; the authoritative server resolves the target behind the scenes and answers queries with plain A/AAAA records. Resolvers never see a CNAME, so the zone stays valid.
- Cloudflare calls this CNAME flattening, and its documentation states it is applied by default on all plans when the zone apex uses a CNAME.
- Other providers offer the same idea as ALIAS or ANAME records.
None of these is a standard record type; they are provider behaviour. If you ever move DNS providers, confirm the new one offers an equivalent before migrating the zone.
Dangling CNAMEs and subdomain takeover
Suppose promo.example.com was created for a campaign and still points via CNAME at a cloud service you have since cancelled. The target name is now unclaimed, and anyone who registers it on that platform can publish content on your subdomain. This “subdomain takeover” can be used for phishing or cookie-scoped attacks against your main site. The defence is procedural: when you decommission a service, remove the DNS records pointing at it the same day, and review the zone periodically for orphaned aliases.
Quick checks
- In zone files, write targets as fully qualified names with a trailing dot, or the zone name may be appended.
- Keep alias chains short; every hop is another lookup and another place to fail.
dig shop.example.com CNAME +shortshows the target;dig shop.example.com +shortshows the final resolved address.

