What is CNAME (Canonical Name)?
A DNS CNAME record states that its owner name is an alias for another domain name. A resolver follows the alias and then resolves records for the canonical name. The two names do not promise one fixed IP address. Under DNS rules, a CNAME record cannot coexist with other record data at the same owner name. A zone apex therefore cannot normally be a CNAME because it must also contain SOA and NS records.
Why it matters
A CNAME separates a public service name from the DNS name that currently hosts the service. An operator can change the target without changing the name that users know.
How it works
- A resolver asks DNS for records at the alias name.
- DNS returns the CNAME target, and the resolver follows that name until it obtains the requested record data.
- The resolver caches each answer according to its time to live and repeats the lookup after the cached data expires.
Example
The record reports.example.com CNAME access.example.net makes reports.example.com an alias. The resolver then obtains the A or AAAA records for access.example.net.
Pomerium boundary
Pomerium Zero custom domains use a wildcard CNAME that points to the cluster starter domain. Pomerium can then create routes and manage certificates for names under that custom domain.
Limits and non-claims
- A CNAME cannot coexist with other record data at the same owner name.
- Long chains add lookup work, and a broken target or loop prevents resolution.
- A CNAME does not transfer a TLS certificate, application identity, or access policy to the alias.
Evaluation checklist
- Which alias, canonical name, address, and cache chain does the client resolve?
- Which intended reference name does the TLS client validate after resolution?
- Can a dangling alias, stale answer, wrong target, or direct origin change the security boundary?
