---
name: azion-point-a-domain-to-a-workload
description: >-
  Create the DNS record that sends a hostname of your domain to a workload, at your DNS provider or in Edge DNS, and check that it resolves.
---

# Point a domain to a workload

You can send the traffic of a hostname you own to a [workload](/en/documentation/platform/workloads/) with a DNS record at your DNS provider or in [Edge DNS](/en/documentation/platform/edge-dns/). To make the workload accept the hostname first, refer to [Add a custom domain to a workload](/en/documentation/guides/platform/migration/configure-a-domain/).

Azion generates a hostname for every workload, the workload domain, in the form `<id>.map.azionedge.net` on the production infrastructure. Your DNS record sends resolvers from your hostname to that workload domain. The record and the workload work as a pair. The workload answers only the hostnames listed in its domains, and a listed hostname receives no traffic until DNS sends it there.

An account that runs on API v3 with Domains points its records at the address of each domain instead. For more information, refer to [Domains](/en/documentation/platform/workloads/domains/).

---

## Prerequisites

- A workload on the production infrastructure that lists your hostname in its domains. A staging workload, whose workload domain ends in `.preview.azionedge.net`, refuses every custom hostname.
- The workload domain. Azion Console shows it in the **Workload Domain** field of the workload, and the [Azion CLI](/en/documentation/devtools/cli/) and the [Azion API](https://api.azion.com/) return it in `workload_domain`.
- Access to the DNS records of your domain, at your DNS provider or in Edge DNS.

To test the workload on your hostname before you change any DNS record, refer to [Test an application through the hosts file](/en/documentation/guides/application-development/getting-started/stage-applications-through-hosts-file/).

---

## Create a CNAME record for a subdomain

A subdomain, such as `www.example.com`, reaches the workload through a `CNAME` record. The record tells resolvers that the hostname is an alias of the workload domain, so they continue the lookup there and return the addresses of Azion's distributed infrastructure.

The record takes these values:

| Field | Value                                                               |
| ----- | ------------------------------------------------------------------- |
| Name  | The host part of your hostname, such as `www` for `www.example.com` |
| Type  | `CNAME`                                                             |
| Value | The workload domain, such as `<id>.map.azionedge.net`               |

To create the record at your DNS provider:

1. **Sign in to your DNS provider**

2. **Open the DNS records of your domain**

   Select your domain, then open the page where your DNS provider manages its records.

3. **Create the CNAME record**

   Enter the name, type, and value from the table. If a record for the hostname already exists, edit it instead.

4. **Save the record**

Your DNS provider lists the `CNAME` record, with the workload domain as its value. When Edge DNS hosts the zone of your domain, create the same record in that zone instead.

Some DNS providers accept a wildcard record, `*`, that sends every subdomain, such as `www.example.com` and `blog.example.com`, to one target. A workload refuses a wildcard entry in its domains with `The domain does not conform to the format defined in RFC 1035.`, so list on the workload each hostname the wildcard record sends.

---

## Point an apex domain with Edge DNS

An apex domain is your domain with no subdomain, such as `example.com`. A workload takes an apex domain as a hostname, but some DNS providers do not let you point the apex at another hostname. A `CNAME` record at the apex is then not an option.

Edge DNS points the apex at the workload with an `ANAME` record instead. The record works once Edge DNS answers for your domain, which means the nameservers of your domain point to Azion. For more information, refer to [Edge DNS](/en/documentation/platform/edge-dns/).

To create the `ANAME` record, refer to [How to access addresses through a root domain (ANAME)](/en/documentation/guides/application-security/dns/access-root-domain/).

---

## Check that the hostname resolves

Resolvers can take some time to pick up a new or changed record. To check the answer for your hostname, query it with `dig`. Replace `www.example.com` with your hostname:

```bash
dig +short www.example.com
```

Once resolvers pick up a `CNAME` record, the answer lists the workload domain you entered as its value.

Requests to your hostname then reach the application in the workload's deployment. Azion spreads each workload update across its distributed infrastructure over several minutes. If you listed your hostname on the workload in the last few minutes, some requests can still get the previous configuration. Send the request again until every response matches.

An `https://` request to your hostname also needs a server certificate that covers the hostname, bound to the workload. To get one, refer to [Request a Let's Encrypt certificate](/en/documentation/guides/application-security/tls-and-certificates/how-to-generate-a-lets-encrypt-certificate/) or [Upload a digital certificate](/en/documentation/guides/application-security/tls-and-certificates/digital-certificates/).

---

## Next steps

- [Close the workload domain](/en/documentation/guides/platform/migration/configure-a-domain.md#close-the-workload-domain): Make the workload answer only on your hostnames once they resolve.
- [Request a Let's Encrypt certificate](/en/documentation/guides/application-security/tls-and-certificates/how-to-generate-a-lets-encrypt-certificate.md): Have Azion issue and renew the certificate that covers your hostname.
- [Upload a digital certificate](/en/documentation/guides/application-security/tls-and-certificates/digital-certificates.md): Bind a certificate you already hold for your hostname to the workload.
- [Troubleshoot Workloads](/en/documentation/platform/workloads/troubleshooting.md): Fix a hostname the workload refuses or a request that does not reach your application.
