🚀App Platform (PaaS)

Custom Domains & SSL

By the Domain India teamPublished 6 min read
Knowledge base article
Contents (9 sections)

Every App Platform app gets a default web address the moment it is created. To serve it on your own name, such as app.example.com or example.com, you add the domain in the app's Domains tab and create two DNS records. SSL is issued and renewed for you.

Key takeaways

Add the domain in the Domains tab. The tab then shows two records to create: a TXT record that proves the domain is yours, and a traffic record that sends visitors to your app. That is a CNAME for a subdomain such as app.example.com, or A records for a whole domain such as example.com. Press Check verification once the records are in place. The SSL certificate is issued automatically on the first visit after verification, and renews itself.

Copy every value from the Domains tab

The TXT name, the TXT value and the traffic target are specific to your app and your domain. Copy them from the Domains tab exactly as shown. Don't type them from memory or reuse values from another app or guide: a wrong value is the most common reason a custom domain never verifies.

1. Add the domain to your app

  1. Open your app
    from Services › App Platform, then open Configure › Domains.
  2. Enter the domain
    you want to use, for example app.example.com, and click Add Domain.
  3. Read the records panel.
    It lists the exact records to create for that name, numbered by purpose: ownership, traffic and, for some names, an optional extra record.

If you see "That domain is already linked to another app", the name is attached elsewhere on the platform. Remove it from the other app first, or contact support if it isn't yours to remove.

2. Create the DNS records

Create the records at whichever DNS provider your domain's nameservers point to. That may be Domain India, your hosting company or a service such as Cloudflare.

RecordPurposeWhere the value comes from
TXTProves you control the domainName and value shown in the Domains tab
CNAME (subdomains)Sends traffic for app.example.com to your appYour app's default address, shown in the Domains tab
A (whole domains)Sends traffic for example.com to the platformIP addresses shown in the Domains tab
Optional extra recordAttaches the other form of the name, such as wwwShown in the Domains tab when it applies

Subdomain or whole domain?

A subdomain like app.example.com can point at your app with a CNAME. A whole domain like example.com can't hold a CNAME, because the top of a DNS zone can only use A records. The Domains tab works out which case applies to the name you entered and shows the right record type. If your domain is registered elsewhere and isn't on our DNS, the tab may recommend A records even for a subdomain, because an A record is correct at any name.

If the tab offers to add the records for you

When the domain's DNS is managed in your Domain India account, the records panel may show Add these records for me. It replaces what that name points to today and doesn't touch your email records. Afterwards, press Check verification. If verification still reports that the TXT record isn't found, check which DNS provider your nameservers actually point to, and add the records there. The nameserver guide explains how to see this.

3. Verify the domain

After you create the records, go back to the domain's row in the Domains tab and press Check verification.

  • Verified: the domain is attached to your app.
  • "TXT record not found yet": DNS hasn't caught up, or the TXT name or value doesn't match. The records panel says DNS changes can take up to an hour to be visible. Wait, then check again.

You can check the TXT record yourself from a terminal:

bash
dig +short TXT <the TXT name shown in the Domains tab>

The answer should contain exactly the value the tab shows.

4. SSL certificates

You don't configure SSL. Once the domain is verified, a free Let's Encrypt certificate is issued automatically on the first request to that name, and it renews itself before it expires.

If a browser warns about "mixed content" after the certificate is in place, your app is loading some images, scripts or styles over http://. Change those links to https:// or to relative paths.

5. Several domains on one app

You can attach more than one domain to the same app, each with its own certificate, for example example.com, www.example.com and api.example.com. Repeat the steps above for each name. Where the tab shows the optional extra record, adding it attaches the other form of your domain (with or without www) automatically when you verify.

6. Removing a domain

Click the remove button on the domain's row. The app stops answering on that address and its certificate is no longer renewed. Your DNS records are not changed, so delete them at your DNS provider if you no longer need them.

7. Troubleshooting

What you seeWhat to check
"TXT record not found yet"The TXT name and value match the Domains tab exactly; the record is at the DNS provider your nameservers use; allow up to an hour
Domain "does not look registered"Register the domain first; records can't be created for a name nobody owns
Verified, but the wrong site loadsThe CNAME or A records point somewhere else; compare them with the Domains tab
Verified, but no padlock yetVisit the domain once to trigger the certificate, then reload
Mixed-content warningsYour app loads http:// resources; switch them to https://
Which DNS records does an App Platform custom domain need?

Two: a TXT record that proves you own the domain, and a traffic record that sends visitors to your app. The traffic record is a CNAME for a subdomain, or A records for a whole domain. The exact names and values are shown in your app's Domains tab.

Can I use my root domain, such as example.com?

Yes. The top of a DNS zone can't hold a CNAME, so the Domains tab shows A records for a root domain instead. Create those along with the TXT record, then press Check verification.

Do I have to buy or install an SSL certificate?

No. A free certificate is issued automatically on the first request after the domain is verified, and it renews itself. There is nothing to configure.

How long does verification take?

It depends on your DNS provider. The Domains tab notes that DNS changes can take up to an hour to be visible. Press Check verification again after waiting.

Does removing a domain delete my DNS records?

No. Removing a domain stops your app answering on it and stops certificate renewal, but your DNS records stay as they are until you delete them at your DNS provider.

Ready to go live on your own name? Open your App Platform apps, read the App Platform overview, or ask us in a support ticket if verification won't complete.

Run your app on your own domain

Every App Platform plan includes custom domains with free, automatically renewed SSL.

See App Platform plans

Ready when you are

Get the App Platform from ₹100/mo + GST

See plans

Was this article helpful?

Your answer helps us decide what to improve next.

Still need help? Open a support ticket and our team will reply.

Prefer an app? Add this site to your home screen.Get the app
App Platform custom domains and free SSL | Domain India