DNS records
The records a custom domain needs, what each one does, and how Modulify reports on them.
On this page
When you connect a custom domain, Modulify shows you the exact records to create at your DNS host. A root domain such as example.com needs one record. The www hostname, or a subdomain such as blog.example.com, needs one too. A hostname reads Connected once its record resolves to Modulify and its certificate has been issued.
A root domain: one A record
The table below is what the Domain tab shows for example.com. Names are displayed relative to your domain, so the apex reads @.
| Type | Name | Value | Why it is there |
|---|---|---|---|
| A | @ |
Modulify's IPv4 address, shown in the tab | Sends every visitor to your site |
Every Modulify site shares this address, and Modulify routes each visitor to the right site by its domain name. No AAAA record is needed.
www or a subdomain: one CNAME
For www.example.com, or any subdomain you connect, the table shows a single row.
| Type | Name | Value | Why it is there |
|---|---|---|---|
| CNAME | www |
cname.modulify.website |
Sends every visitor to your site, and keeps working if Modulify's addresses ever change |
Modulify checks where the name ends up, not which record type got it there. The row also reads Valid if your DNS host points www at your root domain, or if you used an A record with the same value as the root.
Click any name or value in the tab to copy it.
Why these are enough
The record carries traffic, and it is also what the certificate is issued through. Once it points at Modulify, the certificate is issued within a minute or so and renewed automatically, so no separate validation records are needed.
If your DNS host still has _acme-challenge or _fly-ownership records for this domain from an earlier setup, they are no longer required. Leaving them in place is harmless.
A domain connected before these records existed points straight at its site, with A and AAAA records or a CNAME under cname.modulify.website. Those records keep working and still read Valid. You can switch to the records in the table at any time.
Extra records at the same name
Everything at the name must point at Modulify. If your DNS host also has another A record for @, for example a parking page your registrar created, or an AAAA record left over from an earlier host, some visitors reach that address instead of your site. The row reads Invalid and the red Extra record notice under it names the record: "This name also has an AAAA record pointing at <address>, so some visitors never reach your site. Delete it."
At Namecheap an extra A address at @ usually comes from a URL Redirect Record left by the parking page. Advanced DNS lists it as URL Redirect Record rather than A Record; deleting it clears the banner.
Cloudflare's proxy
If Modulify detects that your nameservers are Cloudflare, the table gains a Proxy column that reads Off on every row. Create each record as DNS only (grey cloud) and keep it that way until the domain shows Connected. You can turn the proxy on after that.
With the proxy on, public DNS shows Cloudflare's addresses instead of the record you created, so Modulify checks the domain over the web instead. It requests a small file from your domain and expects Modulify to answer it. When that works, the row reads Valid with the proxy on. Set Cloudflare's SSL/TLS encryption mode to Full or Full (strict).
If the check does not get through, the row reads Invalid with a Cloudflare proxy detected notice: "Set this record to DNS only (grey cloud) until the domain connects. You can turn the proxy back on after that." This happens most often when the proxy is on before the first certificate exists and Cloudflare's Always Use HTTPS is enabled. Switching to DNS only lets the certificate be issued. Turn the proxy back on once the domain reads Connected.
The Status column
Each row carries a status once the records exist. Modulify resolves every name through public DNS while the Domain tab is open.
| Status | Meaning |
|---|---|
| Valid | The name resolves to Modulify |
| Pending | The record does not resolve yet, which is normal right after you add it |
| Invalid | Something is at that name, but not what is needed. A red banner under the row says what |
| Unknown | The lookup itself did not come back. Nothing is known about the record either way |
A row turns Invalid only after the same problem shows up on three checks in a row. Modulify also asks your DNS host's own nameservers before it reports a problem, so an old answer still cached somewhere on the internet does not flag a record you already fixed. Until then the row reads Pending.
Where to add them
The line above the table names the zone: "Add the following record at the DNS host that manages example.com (not any other domain). DNS changes can take a few minutes to propagate." That is the host whose nameservers your domain currently uses, which is not always the company you bought the domain from. Each domain on the site can sit with a different DNS host, so read the line on each domain's card.
Relative and absolute names
Most DNS panels expect the name relative to your zone, which is what Modulify displays. A few expect the full hostname. If your provider's form already appends your domain for you, paste www, not www.example.com, or you end up with www.example.com.example.com, which resolves to nothing and is invisible unless you look for it.
One click setup
For some DNS providers Modulify can write the records for you. When a domain's provider supports it, a strip appears at the top of that domain's card, carrying the provider's icon and a Connect with <your provider> button. It reads "One step at <your provider> adds every record below, for your domain and its www variant", or the same sentence without the www clause when no variant is attached. Clicking it opens a popup at your provider where you approve the change. When you finish or close the popup, Modulify re-checks that domain's records. The strip shows for every provider that supports Domain Connect, the standard behind one-click setup, even before that provider has switched it on for Modulify. Until it has, clicking shows One-click setup not ready yet with "<your provider> has not switched on one-click setup for Modulify yet. Add the records below by hand." and opens nothing.
One click covers the hostnames on that card, the domain and its www variant, which is why the strip sits above both rows rather than inside one of them. It writes the same records as the table. Every domain has its own strip because each one can sit with a different DNS provider, so a site with two domains at the same provider still takes one click for each.
The strip only appears on a card while that domain's provider supports Modulify's setup and at least one of its hostnames is still unconnected. When it does not appear, add the records by hand.
What connecting a domain never asks you to change
Connecting a custom domain only ever asks for the records above: one for a root domain, one for www or a subdomain. It does not ask for nameserver changes, MX records, or anything to do with your email. Records at other names in the same zone are left alone and do not affect the connection.
Email is set up apart from the website. To have the site send email from your domain, add the domain under Email domains on the Settings tab of the Emails tab, which lists its own records: an ownership TXT record, three CNAME records for sending and a recommended DMARC record, and an MX record only once you turn on receiving. See Use your own domain.
None of those records replace the one that connects the site, but the MX record sits at the email domain itself, and a name that holds a CNAME cannot hold an MX record as well. So for a site connected at a subdomain such as blog.example.com, never delete its CNAME to make room for the MX record, because the site goes offline without it. Receive mail at your domain covers receiving mail at such a subdomain.
Next
- Connect a custom domain walks the setup end to end.
- Troubleshoot a domain covers a domain that stays Pending.
- www and apex domains explains the www record.