---
name: azion-point-an-apex-domain-with-aname
description: >-
  Point your apex domain, such as example.com, at an Azion hostname with an Edge DNS ANAME record from Azion Console, the Azion CLI, or the API.
---

# Point an apex domain with ANAME

You can point an apex domain at an Azion hostname with an ANAME record in [Edge DNS](/en/documentation/platform/edge-dns/) from Azion Console, the Azion CLI, or the Azion API. Edge DNS then answers queries for the apex with the addresses of that hostname. To point a subdomain such as `www`, refer to [Point a subdomain with a CNAME record](/en/documentation/guides/application-security/dns/cname-subdomain/) instead.

The apex, also called the root or naked domain, is your domain with no subdomain, such as `example.com`. A CNAME record cannot sit at the apex, so the ANAME record takes its place there. For the reason, refer to [How Edge DNS works](/en/documentation/platform/edge-dns/how-it-works/#aname-at-the-apex).

---

Select your interface once. The prerequisites and the first task show only that path.

## Prerequisites

- A zone for your domain in Edge DNS. To create one, refer to [Create, edit, or delete a zone](/en/documentation/guides/application-security/dns/edge-dns-configure-main-settings/).
- The **Edit Edge DNS** permission, which requires **View Edge DNS**. Refer to [Teams permissions](/en/documentation/fundamentals/teams-permissions/).
- The Azion hostname the record points at, such as the workload domain `<your-workload>.map.azionedge.net`. To find it and make the workload accept your apex domain, refer to [Point a domain to a workload](/en/documentation/guides/platform/migration/point-domain-to-azion/).

**Console**

- Access to Azion Console. To sign in, refer to [Access Azion Console](/en/documentation/guides/platform/account-and-billing/how-to-access-azion-console/).

**CLI**

- The [Azion CLI](/en/documentation/devtools/cli/), installed and authorized.
- The ID of your zone. `azion list dns-zone` prints it in the `ID` column.

**API**

- A [personal token](/en/documentation/guides/platform/account-and-billing/personal-tokens/) and `curl`.
- The `id` of your zone. A `GET` request to `https://api.azion.com/v4/workspace/dns/zones` lists every zone with its `id`.
- For every endpoint and field of the API, refer to the [Azion API reference](https://api.azion.com/).

---

## Add the ANAME record at the apex

The record name `@` stands for the apex. The value is a hostname under `azioncdn.net`, `azionedge.net`, or `azionedge.com`, and the TTL is always `20`. To edit or delete the record later, refer to [Add, edit, or delete a record](/en/documentation/guides/application-security/dns/add-records/).

**Console**

To add the record in Azion Console:

1. **Open the Edge DNS page**

   Access [Azion Console](https://console.azion.com/) > **Edge DNS**.

2. **Open the zone**

   On the **Zones** page, select the row of the zone that holds your domain.

3. **Select the Records tab**

4. **Select + Record**

   The **Create Record** drawer opens.

5. **Enter @ as the name**

   In **Name**, enter `@`. The Console adds the domain for you, so the record answers for `example.com`.

6. **Select the ANAME record type**

   In **Record Type**, select *ANAME - Maps a name to another name*. The Console sets **TTL (seconds)** to `20`.

7. **Keep the TTL at 20**

   Leave **TTL (seconds)** at `20`. Edge DNS refuses any other TTL for an ANAME record.

8. **Enter the hostname**

   In **Value**, enter the Azion hostname, such as `<your-workload>.map.azionedge.net`. Enter a hostname, never an IP address.

9. **Keep the Simple policy**

   In the **Policy** section, keep **Policy Type** set to *Simple*. The **Weight** field stays unavailable for an ANAME record.

10. **Select Save**

The Console shows `Edge DNS Record has been created`, and the record appears in the **Records** table.

**CLI**

To add the record with the Azion CLI, replace `<zone-id>` with the ID of your zone and the value with your hostname:

```bash
azion create dns-record --zone-id <zone-id> --name @ --type ANAME --rdata <your-workload>.map.azionedge.net --ttl 20
```

The command prints the ID of the record:

```text
Created DNS record with ID 100779
```

The zone holds the ANAME record at the apex. In `--name`, `@` stands for the domain: never type the domain itself.

**API**

To add the record with the Azion API, send a `POST` request to the records endpoint of the zone. Replace `<zone-id>` with the `id` of your zone and the value in `rdata` with your hostname:

```bash
curl -X POST https://api.azion.com/v4/workspace/dns/zones/<zone-id>/records \
  -H "Authorization: Token [TOKEN VALUE]" \
  -H "Content-Type: application/json" \
  -d '{"name":"@","type":"ANAME","rdata":["<your-workload>.map.azionedge.net"],"ttl":20}'
```

A `201` returns the record:

```json
{
  "state": "executed",
  "data": {
    "id": 100186,
    "description": "",
    "name": "@",
    "ttl": 20,
    "type": "ANAME",
    "rdata": ["<your-workload>.map.azionedge.net"],
    "policy": "simple",
    "weight": 255
  }
}
```

The zone holds the ANAME record at the apex. In `name`, `@` stands for the domain: never send the domain itself.

The API refuses an ANAME record with any TTL other than `20` with `19011`, and a hostname outside the three Azion domains with `19016`. For every rule of the type, refer to [Record types](/en/documentation/platform/edge-dns/record-types/#aname).

---

## Query the apex at Azion's nameservers

Ask Azion's nameserver directly, without your resolver's cache, to confirm that it answers for the apex. This check works before your registrar delegates the domain to Azion.

To query `ns1.aziondns.net` for the apex, replace `example.com` with your domain:

```bash
dig +short @ns1.aziondns.net example.com A
```

The nameserver returns the addresses of the hostname, one per line:

```text
<address>
<address>
```

Edge DNS looks up the hostname itself and answers the apex with its addresses as A records. Without `+short`, the output shows `status: NOERROR`, the `aa` flag, a TTL of `20` on each A record, and no CNAME in the answer.

If the command prints nothing, wait a few minutes and run it again. After you add or change a record, it can take a few minutes to reach every nameserver. For more information, refer to [How Edge DNS works](/en/documentation/platform/edge-dns/how-it-works/#caching-and-propagation).

Resolvers on the internet use the record only once your registrar delegates the domain to the three Edge DNS nameservers. For the delegation, refer to [Migrate nameservers to Azion](/en/documentation/guides/platform/migration/migrate-ns-to-azion/).

---

## Next steps

- [Migrate nameservers to Azion](/en/documentation/guides/platform/migration/migrate-ns-to-azion.md): Delegate your domain to Edge DNS so resolvers use the record.
- [Point a domain to a workload](/en/documentation/guides/platform/migration/point-domain-to-azion.md): Make the workload accept your apex domain and check that it resolves.
- [Record types](/en/documentation/platform/edge-dns/record-types.md#aname): Every rule of the ANAME record and of the other types.
- [Point a subdomain with a CNAME record](/en/documentation/guides/application-security/dns/cname-subdomain.md): Send a name such as www to another host.
