---
name: azion-match-subdomains-with-a-wildcard-record
description: >-
  Answer every subdomain that has no record of its own with one Edge DNS wildcard record, from Azion Console, the Azion CLI, or the API.
---

# Match subdomains with a wildcard record

You can add a wildcard record to a zone in [Edge DNS](/en/documentation/platform/edge-dns/) from Azion Console, the Azion CLI, or the Azion API. The record below answers `192.0.2.31` for every name of `example.com` that has no record of its own. To answer one named host instead, refer to [Add, edit, or delete a record](/en/documentation/guides/application-security/dns/add-records/).

---

Select your interface once. The prerequisites and the procedure below show only that path.

## Prerequisites

- A zone in Edge DNS for your domain. To create one, refer to [Create, edit, or delete a zone](/en/documentation/guides/application-security/dns/edge-dns-configure-main-settings/).
- The **Edit Edge DNS** permission. Refer to [Teams permissions](/en/documentation/fundamentals/teams-permissions/).
- `dig` on your machine, to check the answer. To install it, refer to [Query a zone with dig](/en/documentation/guides/application-security/dns/run-the-dig-command/).

**Console**

- Access to Azion Console. To sign in, refer to [Access Azion Console](/en/documentation/guides/platform/account-and-billing/how-to-access-azion-console/).

**CLI**

- The [Azion CLI](/en/documentation/devtools/cli/) installed and authorized.

**API**

- A [personal token](/en/documentation/guides/platform/account-and-billing/personal-tokens/) and `curl`.

---

## Add a wildcard record

A record named `*` answers every name of the zone that has no record of its own, however many labels deep. To answer only the names under one label, such as `apps`, name the record `*.apps` instead. Use your own domain wherever this page shows `example.com`.

**Console**

To add the wildcard record in Azion Console:

1. **Open the Edge DNS page**

   Access [Azion Console](https://console.azion.com/) > **Edge DNS**.

2. **Open the zone**

   On the **Zones** page, select the row of the zone.

3. **Open the Records tab and select + Record**

   On the **Records** tab, select **+ Record**. The **Create Record** drawer opens.

4. **Enter the wildcard name**

   In **Name**, enter `*`. The Console shows your domain after the field and adds it for you, so never type the domain.

5. **Keep the A record type**

   Keep **Record Type** set to *A - IPv4 Address*.

6. **Keep the TTL**

   Keep **TTL (seconds)** at `3600`.

7. **Enter the value**

   In **Value**, enter `192.0.2.31`.

8. **Select Save**

The Console shows `Edge DNS Record has been created`, and the `*` record appears in the **Records** table.

**CLI**

To add the wildcard record with the Azion CLI, replace `<zone-id>` with the ID of your zone. Quote the asterisk so your shell passes it unchanged:

```bash
azion create dns-record --zone-id <zone-id> --name "*" --type A --rdata 192.0.2.31 --ttl 3600
```

The command prints the ID of the record:

```text
Created DNS record with ID 100778
```

The zone holds the wildcard record. Never include the domain in `--name`: Edge DNS adds it.

**API**

To add the wildcard record with the Azion API, send a `POST` request to the zone's records endpoint. Replace `<zone-id>` with the `id` of your zone and `[TOKEN VALUE]` with your personal token:

```bash
curl -X POST https://api.azion.com/v4/workspace/dns/zones/<zone-id>/records \
  -H "Authorization: Token [TOKEN VALUE]" \
  -H "Content-Type: application/json" \
  -d '{"name":"*","type":"A","rdata":["192.0.2.31"],"ttl":3600}'
```

A `201` returns the record:

```json
{
  "state": "executed",
  "data": {
    "id": 100253,
    "description": "",
    "name": "*",
    "ttl": 3600,
    "type": "A",
    "rdata": ["192.0.2.31"],
    "policy": "simple",
    "weight": 255
  }
}
```

The zone holds the wildcard record. Never include the domain in `name`: Edge DNS adds it.

A name with its own record keeps its own answer: if the zone holds an A record for `www`, a query for `www.example.com` returns that record, not `192.0.2.31`. For which names a wildcard matches and which it does not, refer to [Record types](/en/documentation/platform/edge-dns/record-types/#wildcards).

---

## Check the answer

Ask Azion's nameserver directly, without your resolver's cache, for a name that has no record of its own.

> **Caution**
>
> Save the wildcard record before you query any name it covers. Edge DNS answers `NXDOMAIN` for up to one hour, the SOA minimum, to a name you queried before the record existed.

To query `ns1.aziondns.net` for a name with no record, such as `ghost`, run:

```bash
dig +short @ns1.aziondns.net ghost.example.com A
```

The nameserver returns the value of the wildcard record:

```text
192.0.2.31
```

The wildcard answers for `ghost.example.com`. If the command prints nothing, refer to [A new record returns NXDOMAIN](/en/documentation/platform/edge-dns/troubleshooting/#a-new-record-returns-nxdomain).

---

## Next steps

- [Record types](/en/documentation/platform/edge-dns/record-types.md#wildcards): Which names a wildcard matches, and which it does not.
- [Add, edit, or delete a record](/en/documentation/guides/application-security/dns/add-records.md): Give a name its own record, or change the wildcard.
- [Point a subdomain with a CNAME record](/en/documentation/guides/application-security/dns/cname-subdomain.md): Send one subdomain to another host by name.
- [Troubleshoot Edge DNS](/en/documentation/platform/edge-dns/troubleshooting.md): Fix a name that returns NXDOMAIN or a stale answer.
