Type something to search...
How to Point a Domain to Vercel or Netlify Using DNS?

How to Point a Domain to Vercel or Netlify Using DNS?

Deploying a site to Vercel or Netlify gives you a working URL in seconds — something like my-site.vercel.app or my-site.netlify.app. Putting it on your own domain takes a few DNS records, and the right ones depend on two choices: whether you keep your current DNS provider or hand DNS over to the platform, and whether visitors should land on the root domain (example.com) or on www.example.com. The root domain is the tricky part, because it can't hold a normal CNAME record — the reason is covered in can you use a CNAME record on the root domain.

This guide shows the exact records to add for both platforms, how HTTPS certificates get issued once DNS is right, how to verify each step from the command line, and the mistakes that most often leave a domain stuck on "Invalid Configuration."

Two Ways to Connect a Domain

Both platforms support the same two approaches:

ApproachWhat you changeProsCons
External DNS (records only)Add A/CNAME (or ALIAS) records at your current DNS hostKeep your existing email, records, and DNS providerApex domains need an A record or ALIAS support
Platform nameserversPoint the domain's nameservers to Vercel DNS or Netlify DNSPlatform manages records automatically, including apexYou must recreate every other record (MX, TXT, etc.) on the platform

If your domain already handles email or other services through a DNS provider you're happy with, the external DNS approach is usually simpler and lower-risk. Moving nameservers is a bigger change — see how to update nameservers for a domain if you go that route.

Pointing a Domain to Vercel

Add the domain in Vercel first

Always add the domain to your project before (or at the same time as) creating DNS records:

  1. Open your project in the Vercel dashboard and go to Settings, then Domains.
  2. Enter example.com and add it. Vercel suggests also adding www.example.com and setting one to redirect to the other.
  3. Vercel then shows the records it expects and marks the domain as Invalid Configuration until they're in place.

You can do the same with the Vercel CLI from the project directory:

vercel domains add example.com
vercel domains inspect example.com

vercel domains add attaches the domain to the linked project, and vercel domains inspect shows its configuration status, including which nameservers and records Vercel sees.

Records for external DNS

For the apex domain, add an A record:

example.com.      3600  IN  A      76.76.21.21

For www (and any other subdomain), add a CNAME:

www.example.com.  3600  IN  CNAME  cname.vercel-dns.com.

Vercel's dashboard may show a project-specific CNAME target instead of cname.vercel-dns.com for newer domains. If it does, use the exact value shown — both are documented, but the dashboard value is what Vercel will validate against.

If your DNS host supports ALIAS, ANAME, or CNAME flattening at the apex, you can use that instead of the A record, pointing it at the CNAME target. Either way works; the A record is the most widely supported option.

Using Vercel nameservers

To let Vercel manage DNS, set the domain's nameservers at your registrar to:

ns1.vercel-dns.com
ns2.vercel-dns.com

Vercel then creates the website records automatically. You must add any other records yourself — the CLI can do this:

vercel dns add example.com @ MX smtp.google.com 1
vercel dns add example.com @ TXT "v=spf1 include:_spf.google.com ~all"
vercel dns ls example.com

These commands add an MX record and an SPF TXT record to the Vercel-managed zone, then list every record in it. Recreate all existing records before switching nameservers, or email and other services will break.

Domains used in another Vercel account

If the domain (or a subdomain) is already attached to a project in another Vercel account or team, Vercel asks you to prove ownership with a TXT record at _vercel.example.com. The value is shown in the dashboard; add it, wait for it to resolve, and refresh. Ownership verification with TXT records is covered more generally in how to verify domain ownership with a TXT record.

Pointing a Domain to Netlify

Add the domain in Netlify first

  1. In the Netlify dashboard, open your site and go to Domain management (under the site's configuration).
  2. Choose Add a domain and enter example.com.
  3. Netlify typically adds both example.com and www.example.com and lets you choose a primary domain. The other one redirects to it automatically.
  4. Netlify then offers to set up Netlify DNS, or shows the records needed for external DNS.

Records for external DNS Netlify

For www and other subdomains, point a CNAME at your site's Netlify subdomain:

www.example.com.  3600  IN  CNAME  my-site.netlify.app.

For the apex domain, Netlify's preferred option is an ALIAS, ANAME, or flattened CNAME pointing to its apex load balancer hostname:

example.com.      3600  IN  ALIAS  apex-loadbalancer.netlify.com.

If your DNS host doesn't support ALIAS-style records, use an A record pointing to Netlify's load balancer IP:

example.com.      3600  IN  A      75.2.60.5

The ALIAS option is better when available, because it lets Netlify route visitors through its CDN more efficiently than a single fixed IP. How ALIAS records work, and why they exist, is explained in what an ALIAS or ANAME record is.

Netlify recommends making www the primary domain when you use external DNS, because a CNAME on www gets the full benefit of its CDN while an apex A record doesn't. The apex then redirects to www.

Using Netlify DNS

Choosing Set up Netlify DNS creates a DNS zone for your domain and assigns a set of nameservers (such as dns1.p01.nsone.net through dns4.p01.nsone.net). The exact names vary by account, so copy them from the dashboard. Update the nameservers at your registrar, and recreate your MX, TXT, and other records in Netlify's DNS panel before the switch.

How HTTPS Certificates Get Issued

Both platforms issue free TLS certificates automatically — but only after DNS points at them. The certificate authority (Let's Encrypt on both platforms) must reach the platform when it requests your domain, so certificate provisioning waits until your records resolve correctly.

Two things can block issuance:

  • CAA records that don't allow the platform's certificate authority. If you've published CAA records, they must include an entry for letsencrypt.org (example below). More on how these restrictions work is in what a CAA record is.
  • Stale AAAA records pointing to an old host. If a resolver gets an IPv6 address for your apex from a previous provider, validation (and visitors on IPv6) go to the wrong server. Remove AAAA records that don't belong to the platform.

A CAA record that permits Let's Encrypt looks like this:

example.com.  3600  IN  CAA  0 issue "letsencrypt.org"

Once DNS is correct, certificates are usually issued within minutes. If a domain stays on "pending" for more than an hour or so, re-check the records rather than waiting.

Verifying Your Configuration

Check what public DNS returns:

dig example.com A +short
dig example.com AAAA +short
dig www.example.com CNAME +short
dig example.com CAA +short

For Vercel with external DNS, you'd expect 76.76.21.21 for the apex and cname.vercel-dns.com. (or your project-specific value) for www. For Netlify, the apex shows 75.2.60.5 or the addresses behind the load balancer, and www returns your netlify.app hostname. The AAAA query should return nothing, or only platform-owned addresses.

Then confirm HTTP behaviour and the redirect between apex and www:

curl -sI http://example.com | grep -iE "^(HTTP|location)"
curl -sI https://www.example.com | grep -iE "^(HTTP|server)"

The first request should return a redirect to the HTTPS primary domain; the second should return 200 with a server header identifying the platform (Vercel or Netlify). If DNS looks right on your machine but the dashboard still reports a problem, the platform's resolver may have cached an earlier answer — see how to check if DNS changes have propagated.

You can also check that the certificate covers the right names:

echo | openssl s_client -connect example.com:443 -servername example.com 2>/dev/null \
  | openssl x509 -noout -subject -issuer -ext subjectAltName

This prints the certificate's subject, issuer, and the hostnames it's valid for.

Subdomains, Previews, and Wildcards

  • Subdomains such as docs.example.com or app.example.com each need their own CNAME to the platform target (Vercel's CNAME target, or the Netlify site's netlify.app name), and must be added to the matching project or site. The general rules for subdomains are in how to set up subdomains in DNS settings.
  • Wildcard domains (*.example.com) on Vercel require using Vercel's nameservers, because issuing a wildcard certificate requires the platform to complete a DNS-based challenge. Netlify supports wildcard subdomains on certain plans with Netlify DNS.
  • Branch and preview deployments use the platform's own domains by default. Custom preview domains require additional records and configuration in the dashboard.

Common Mistakes

  1. Adding DNS records before adding the domain in the dashboard. The records resolve, but the platform has no project associated with the hostname and returns a 404. Add the domain in the dashboard first.
  2. CNAME at the apex on a provider that doesn't flatten. Many DNS hosts reject it or break other records at the apex, including MX. Use the A record or an ALIAS.
  3. Leftover A or AAAA records. Old records for the apex from a previous host cause intermittent failures, because resolvers return both old and new addresses.
  4. Switching nameservers without recreating email records. Mail stops the moment the new nameservers take effect.
  5. Proxying through another CDN. Putting Cloudflare's orange-cloud proxy in front of Vercel or Netlify can interfere with certificate issuance and caching. Both platforms recommend DNS-only records.
  6. Forgetting to remove records after deleting a site. A CNAME still pointing to an abandoned netlify.app or Vercel project is a takeover risk — read what a dangling DNS record is.

Vercel and Netlify Domain FAQ

Vercel's documented apex A record value is 76.76.21.21. Subdomains use a CNAME to cname.vercel-dns.com or the project-specific value shown in your dashboard.

Netlify's load balancer IP for apex A records is 75.2.60.5. If your DNS host supports ALIAS or ANAME records, Netlify prefers pointing the apex to apex-loadbalancer.netlify.com instead.

Either works on both platforms. Netlify recommends www as the primary when you use external DNS, because the CNAME gives better CDN routing. Pick one and redirect the other to it.

No. You can keep your current DNS provider and add A and CNAME records. Moving nameservers is optional and mainly useful if you want the platform to manage records or need wildcard domains.

Vercel can't see the expected records yet. Check that the apex A record and www CNAME match the values in the dashboard, that there are no conflicting A or AAAA records, and that enough time has passed for caches to expire.

Usually a few minutes after DNS resolves correctly. If it stays pending, check for CAA records that don't allow Let's Encrypt and for stale AAAA records pointing elsewhere.

Not if you only add A and CNAME records for the website. Email is affected only if you change nameservers without recreating your MX, SPF, DKIM, and DMARC records on the new DNS host.

Yes. Add the records in Cloudflare as DNS only rather than proxied. Cloudflare's CNAME flattening also lets you use a CNAME at the apex.

Conclusion

Pointing a domain to Vercel or Netlify comes down to a small set of records. For Vercel, an apex A record to 76.76.21.21 and a www CNAME to cname.vercel-dns.com (or the project-specific target in the dashboard). For Netlify, an apex ALIAS to apex-loadbalancer.netlify.com or an A record to 75.2.60.5, plus a www CNAME to your netlify.app hostname. Alternatively, hand the whole zone to the platform's nameservers — but only after recreating every other record.

Add the domain in the dashboard first, remove conflicting A and AAAA records, make sure CAA records permit Let's Encrypt, and verify with dig and curl. Once DNS checks out, both platforms take care of HTTPS automatically and your site is live on its own domain.

Here are some useful references for connecting domains to Vercel and Netlify:

  1. Vercel Documentation: Domains — Vercel's official guide to adding, configuring, and troubleshooting custom domains.
  2. Netlify Documentation: Netlify Docs — Netlify's documentation hub, including custom domain, external DNS, and Netlify DNS setup.
  3. Let's Encrypt: Challenge Types — how certificate authorities validate domains, which explains why DNS must be correct before HTTPS works.
  4. RFC 8659: DNS Certification Authority Authorization (CAA) Resource Record — the specification for CAA records that can block certificate issuance.
  5. RFC 1034: Domain Names - Concepts and Facilities — defines the rule that a CNAME can't coexist with other records, which is why apex domains need A or ALIAS records.
Tags :
Share :

Related Posts

What Is the Difference Between Authoritative and Recursive DNS Servers?

What Is the Difference Between Authoritative and Recursive DNS Servers?

When someone says "the DNS server," they could mean two completely different machines doing two completely different jobs. One kind of server holds t

Continue Reading
Can DNS settings affect website speed?

Can DNS settings affect website speed?

Yes, DNS settings can significantly affect the speed at which a website loads for its users. DNS, or Domain Name System, is often likened to the inte

Continue Reading
Can You Use a CNAME Record on the Root Domain?

Can You Use a CNAME Record on the Root Domain?

It is one of the most common DNS questions there is. Your hosting platform says "add a CNAME pointing to myapp.example-cdn.net," it works perfectly

Continue Reading