Skip to main content

CNAME (Canonical Name)

A DNS CNAME record states that its owner name is an alias for another domain name.

What is CNAME (Canonical Name)?

A DNS CNAME record states that its owner name is an alias for another domain name. A resolver follows the alias and then resolves records for the canonical name. The two names do not promise one fixed IP address. Under DNS rules, a CNAME record cannot coexist with other record data at the same owner name. A zone apex therefore cannot normally be a CNAME because it must also contain SOA and NS records.

Why it matters

A CNAME separates a public service name from the DNS name that currently hosts the service. An operator can change the target without changing the name that users know.

How it works

  1. A resolver asks DNS for records at the alias name.
  2. DNS returns the CNAME target, and the resolver follows that name until it obtains the requested record data.
  3. The resolver caches each answer according to its time to live and repeats the lookup after the cached data expires.

Example

The record reports.example.com CNAME access.example.net makes reports.example.com an alias. The resolver then obtains the A or AAAA records for access.example.net.

Pomerium boundary

Pomerium Zero custom domains use a wildcard CNAME that points to the cluster starter domain. Pomerium can then create routes and manage certificates for names under that custom domain.

Limits and non-claims

  • A CNAME cannot coexist with other record data at the same owner name.
  • Long chains add lookup work, and a broken target or loop prevents resolution.
  • A CNAME does not transfer a TLS certificate, application identity, or access policy to the alias.

Evaluation checklist

  • Which alias, canonical name, address, and cache chain does the client resolve?
  • Which intended reference name does the TLS client validate after resolution?
  • Can a dangling alias, stale answer, wrong target, or direct origin change the security boundary?

Sources and further reading

Keep learning

Application and Service Access

Route

In Pomerium, a route defines how a requester reaches a service behind Pomerium.

Learn this term
Application and Service Access

Layer-7 Enforcement

Layer 7 enforcement uses protocol facts, such as host, route, method, tool name, and verified identity, to make access decisions.

Learn this term
Application and Service AccessNetwork and Infrastructure

Context-Aware Proxy

A context-aware proxy is a policy enforcement point placed between a requester and a protected service.

Learn this term

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo