Vercel no longer gives every project the same two DNS values. The domain card under your project’s Settings → Domains, or vercel domains inspect, shows the A record or CNAME for that particular project. Vercel’s guidance is to copy that value rather than one from an older tutorial, because verification checks for the exact record your project expects.

Get the value from the project

  1. Add the hostname to the project under Settings → Domains → Add Domain, or run vercel domains add in a linked project. When you add an apex, Vercel suggests adding www as well.
  2. Read the records it asks for on the domain card or from the CLI.
  3. Create them at whichever provider dig NS reports as authoritative for the zone.
vercel domains add app.example.com
vercel domains inspect app.example.com
dig +short NS example.com

The shapes Vercel currently documents:

Hostname Record General-purpose value in Vercel’s docs Project-specific form (Vercel’s own examples)
Apex, example.com A 76.76.21.21 An address from a pool matched to plan and project, such as 216.198.79.1
Subdomain, app.example.com CNAME cname.vercel-dns-0.com A unique name such as d1d4fc829fe7bc7c.vercel-dns-017.com
Wildcard, *.example.com Vercel nameservers, or _acme-challenge NS records pointing to ns1.vercel-dns.com and ns2.vercel-dns.com plus a wildcard CNAME Not applicable Not applicable

The wildcard delegation route also needs Enable Vercel DNS switched on for the domain in your team’s Domains page, while the registrar keeps your current nameservers.

Vercel displays CNAME values with a trailing dot and asks you to copy them exactly, dot included, because the dot marks a fully qualified name. Any hostname can also be served by moving the whole domain to Vercel’s nameservers; if you go that way, copy MX and verification TXT records across first.

What the targets resolve to today

Live capture, 26 September 2026. Three consecutive queries to Vercel’s authoritative server for the general-purpose CNAME target, then the same name through 1.1.1.1 and 8.8.8.8:

$ dig +nocmd @ns1.vercel-dns-0.com cname.vercel-dns-0.com A +noall +answer
cname.vercel-dns-0.com.	300	IN	A	76.76.21.22
cname.vercel-dns-0.com.	300	IN	A	66.33.60.129
$ dig +nocmd @ns1.vercel-dns-0.com cname.vercel-dns-0.com A +noall +answer
cname.vercel-dns-0.com.	300	IN	A	76.76.21.142
cname.vercel-dns-0.com.	300	IN	A	66.33.60.66
$ dig +nocmd @ns1.vercel-dns-0.com cname.vercel-dns-0.com A +noall +answer
cname.vercel-dns-0.com.	300	IN	A	76.76.21.21
cname.vercel-dns-0.com.	300	IN	A	76.223.126.88
$ dig +nocmd @1.1.1.1 cname.vercel-dns-0.com A +noall +answer
cname.vercel-dns-0.com.	300	IN	A	66.33.60.194
cname.vercel-dns-0.com.	300	IN	A	76.76.21.93
$ dig +nocmd @8.8.8.8 cname.vercel-dns-0.com A +noall +answer
cname.vercel-dns-0.com.	300	IN	A	76.76.21.164
cname.vercel-dns-0.com.	300	IN	A	66.33.60.34

Five queries, five different pairs. The authoritative server rotates its answer, so two people checking the same correct CNAME can see different addresses at the same moment. This is the flexibility Vercel cites when it recommends CNAMEs: no address is hard-coded in your zone, so Vercel can steer traffic.

Live capture, 26 September 2026. Vercel’s example project-specific target, and cname.vercel-dns.com, the older name many tutorials still show:

$ dig +nocmd @1.1.1.1 d1d4fc829fe7bc7c.vercel-dns-017.com A +noall +answer
d1d4fc829fe7bc7c.vercel-dns-017.com. 300 IN A	64.29.17.65
d1d4fc829fe7bc7c.vercel-dns-017.com. 300 IN A	216.198.79.65
$ dig +nocmd @1.1.1.1 cname.vercel-dns.com A +noall +answer
cname.vercel-dns.com.	287	IN	A	76.76.21.164
cname.vercel-dns.com.	287	IN	A	66.33.60.34

Both names resolve. The current docs no longer list the older one, though, and a record that happens to resolve to Vercel is not the same as the record your project’s verification looks for.

Live capture, 26 September 2026. Who registers the addresses in the captures above, according to ARIN’s RDAP service:

$ for ip in 76.76.21.22 66.33.60.129 216.198.79.65 64.29.17.65 76.223.126.88; do curl -s https://rdap.arin.net/registry/ip/$ip | jq -r '"\(.startAddress)-\(.endAddress) \(.name) \(.entities[0].vcardArray[1][] | select(.[0]=="fn") | .[3])"'; done
76.76.21.0-76.76.21.255 VERCEL-01 Vercel, Inc
66.33.60.0-66.33.60.255 VERCEL-02 Vercel, Inc
216.198.79.0-216.198.79.255 VERCEL-05 Vercel, Inc
64.29.17.0-64.29.17.255 VERCEL-12 Vercel, Inc
76.223.0.0-76.223.175.255 AMAZO-4 Amazon.com, Inc.

Four blocks are registered to Vercel and one to Amazon, and all five addresses came from answers to Vercel’s own names. An IP-ownership lookup is therefore a weak test of whether a hostname points at Vercel. Compare the CNAME text with your domain card, then check the HTTP response as shown below.

Leave out AAAA records

Vercel’s troubleshooting page says it does not support IPv6 yet, so a custom domain on third-party DNS can’t point an AAAA record at Vercel. Its A-record guide adds that an AAAA record pointing at another host splits traffic between providers and can stall SSL provisioning.

Live capture, 26 September 2026. Asking for an IPv6 address for the general-purpose target:

$ dig +nocmd @1.1.1.1 cname.vercel-dns-0.com AAAA +noall +comments
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 36464
;; flags: qr rd ra; QUERY: 1, ANSWER: 0, AUTHORITY: 1, ADDITIONAL: 1

;; OPT PSEUDOSECTION:
; EDNS: version: 0, flags:; udp: 1232

NOERROR with ANSWER: 0 means the name exists but has no AAAA data. The same query for vercel.com also came back empty. At cutover, delete any AAAA record that a previous host left on the apex or on www, then confirm that dig +short AAAA example.com prints nothing.

Confirm that Vercel is answering

Vercel’s troubleshooting page checks the nameservers, the apex A record, and the subdomain CNAME with dig. Add an HTTP request at the end:

dig +short NS example.com
dig +short A example.com
dig +short CNAME www.example.com
curl -sI https://www.example.com/

Live capture, 26 September 2026. Headers from vercel.com, which Vercel serves itself:

$ curl -sI https://vercel.com/ | grep -iE "^(HTTP|server|x-vercel-id|x-vercel-cache|strict-transport-security)"
HTTP/2 200 
server: Vercel
strict-transport-security: max-age=31536000; includeSubDomains; preload
x-vercel-cache: HIT
x-vercel-id: icn1::iad1::zzwx4-1790434252398-3f8e650268c6

server: Vercel and x-vercel-id are the identifying pair. Vercel documents x-vercel-id as the list of Vercel regions the request hit plus the region where the function ran; this request shows icn1 and iad1. x-vercel-cache: HIT means the CDN served a cached copy. The HSTS line is vercel.com’s own policy; Vercel’s documented default for deployments is max-age=63072000.

Treat these headers as evidence, not proof. Vercel notes that a proxy such as Cloudflare can replace the server header, and that seeing Vercel’s headers doesn’t guarantee certificate validation will succeed.

Ownership checks use TXT records

Serving records don’t prove ownership, so editing the A or CNAME record again won’t clear an ownership prompt. Vercel runs two separate checks:

  • Project level. If another Vercel account already uses the hostname, the Domains page asks for a TXT record. Verifying lets you use the domain in your project; it does not move the domain into your account. Vercel notes that only one such TXT record can be set up at a time.
  • Team level. Connect External on your team’s Domains page detects a domain registered with another Vercel account and shows a TXT record such as _vercel.example.com with a vc-domain-verify=… value. Verify & Claim then moves the domain to your team. Claiming the root domain does not skip project-level verification for a hostname that another project uses.
dig +short TXT _vercel.example.com

Certificates: Let’s Encrypt over HTTP-01

  • Issuer and timing. Vercel requests a Let’s Encrypt certificate for every domain added to a project. Issuance succeeds once DNS points at Vercel, typically within a few minutes of DNS verification.
  • Validation method. Non-wildcard names are validated with HTTP-01, which Vercel answers itself, so the hostname must already route to Vercel. The /.well-known path is reserved and can’t be redirected or rewritten.
  • Wildcards. These need DNS-01: use Vercel’s nameservers, or delegate _acme-challenge with NS records. Vercel warns that the delegation can stop other providers from issuing certificates that use the same challenge name.
  • Renewal. Vercel renews 14 to 30 days before expiry and notifies team owners if renewal fails.
  • CAA. A restrictive policy must include 0 issue "letsencrypt.org", and an issuewild policy must allow Let’s Encrypt as well. CAA lookups follow your CNAME to Vercel’s target, where Vercel’s policy applies; if you need your own CAA at a hostname, switch that hostname to the A record from your domain card. CAA records and Let’s Encrypt explains the lookup rules.
  • Leftovers. An _acme-challenge record from a previous provider can send DNS-01 validation elsewhere. Check with dig +short TXT _acme-challenge.example.com before assuming Vercel is at fault.

Putting Cloudflare in front of Vercel

Vercel’s troubleshooting guidance is to route /.well-known/acme-challenge/* to Vercel on port 80 without caching, authentication, rewrites, or proxy-level redirects, or to point DNS straight at Vercel, which on Cloudflare means a DNS-only record. Validation has to keep working for every renewal, not only the first issuance. Cloudflare DNS records: proxied vs DNS only shows how to tell from the outside which mode a record is in.

www or apex as the primary

Vercel recommends www as the primary domain, with the apex redirecting to it. The CNAME behind www lets Vercel steer traffic, and browsers cache the redirect. An apex primary also works and is served from anycast A records. Either way, add both names to the project and set the direction under Settings → Domains, then Edit and Redirect to. Vercel attempts a redirect between the www and bare forms on its own, but its docs recommend configuring it explicitly. www vs apex canonical redirects covers the trade-offs beyond Vercel.

For how Vercel’s apex, IPv6, and certificate handling compare with Netlify, GitHub Pages, and Cloudflare Pages, see the comparison table in the GitHub Pages custom domain guide.