# Custom Domains (/docs/guides/custom-domains)



Add a custom domain (e.g., `app.yourcompany.com`) to any service. Custom domains apply to stable deployments only - preview deployments always use auto-generated URLs.

## Add a Custom Domain [#add-a-custom-domain]

1. Open your service's **Deployments** → **Custom Domain** tab
2. In the Custom Domain section, enter your domain and click **Add Domain**
3. Copy the DNS target that appears:
   * **CNAME** hostname → create a **CNAME record** (recommended)
   * **IPv4** address → create an **A record**
   * **IPv6** address → create an **AAAA record** (optional, alongside the A record)
4. Copy the TXT challenge that appears for your domain:
   * **Host** looks like `_rock8cloud-challenge.app.yourcompany.com`
   * **Value** is the verification value shown next to it
   * Create a **TXT record** with that host and value at your DNS provider
5. Go to your DNS provider (Cloudflare, Namecheap, etc.) and add the records
6. Come back and click **Verify**

Once you add the domain, verification starts automatically. Your service is accessible from both its platform address (`*.rock8cloud.app`, or `*.apps.rock8.cloud` if created before that shipped) and your custom domain once DNS is confirmed. SSL certificates are provisioned automatically.

If verification fails, click **Verify** to retry manually.

## CNAME or A/AAAA? [#cname-or-aaaaa]

Use a **CNAME** when you can. It keeps working if our IP addresses ever change, so you never have to update your DNS again.

Use **A/AAAA** records for a root (apex) domain like `yourcompany.com`. Most DNS providers do not allow a CNAME there. Some providers offer CNAME flattening or ALIAS records as an apex alternative.

An **A (IPv4) record is required** when you point at IP addresses. An AAAA record on its own does not verify. Add AAAA next to the A record if you also want IPv6 routing.

## DNS Record Format [#dns-record-format]

CNAME (subdomains):

```
Type: CNAME
Name/Host: app
Value/Target: [CNAME hostname shown in Custom Domain section]
```

A/AAAA (root domains, or when no CNAME target is offered):

```
Type: A (add AAAA alongside it for IPv6)
Name/Host: app (for subdomain) or @ (for apex domain)
Value/Target: [IP address shown in Custom Domain section]
```

TXT challenge (required for ownership proof):

```
Type: TXT
Name/Host: _rock8cloud-challenge.app (for subdomain) or _rock8cloud-challenge (for apex domain)
Value/Target: [verification value shown in Custom Domain section]
```

Add the TXT record first and then click **Verify**. Verification also runs on its own after about 60 seconds.

## Verification Status [#verification-status]

| Status       | Meaning                                         |
| ------------ | ----------------------------------------------- |
| **Pending**  | Domain added, waiting for DNS verification      |
| **Verified** | DNS confirmed, custom domain is active          |
| **Failed**   | DNS check failed - verify your record and retry |

## Remove a Custom Domain [#remove-a-custom-domain]

Click **Remove** in the Custom Domain section. The service reverts to its default platform address (`*.rock8cloud.app`, or `*.apps.rock8.cloud` if created before that shipped).

## Troubleshooting [#troubleshooting]

| Problem                         | Solution                                                                                                   |
| ------------------------------- | ---------------------------------------------------------------------------------------------------------- |
| Verification fails              | Check the routing record and the TXT ownership challenge and wait for propagation (can take a few minutes) |
| Domain not loading              | Verify the status is "Verified" and SSL has been provisioned                                               |
| CNAME rejected by your provider | You are probably on a root domain. Use A/AAAA records instead                                              |
| Wrong target                    | Copy it from the Custom Domain section                                                                     |

## Current Limitations [#current-limitations]

* One custom domain per service
* Manual DNS configuration required
* No wildcard domains (e.g., `*.app.yourcompany.com`)
* Routing record (CNAME or A/AAAA) plus the required TXT ownership challenge

## Related [#related]

* [Service Configuration](/docs/guides/service-configuration)
* [FAQ](/docs/faq#can-i-use-my-own-domain)
