Vercel no longer gives every project the same two DNS values. The domain card under your project’s Settings → Domains, or vercel domains inspect, shows the A record or CNAME for that particular project. Vercel’s guidance is to copy that value rather than one from an older tutorial, because verification checks for the exact record your project expects.
Get the value from the project
- Add the hostname to the project under Settings → Domains → Add Domain, or run
vercel domains addin a linked project. When you add an apex, Vercel suggests addingwwwas well. - Read the records it asks for on the domain card or from the CLI.
- Create them at whichever provider
dig NSreports as authoritative for the zone.
vercel domains add app.example.com
vercel domains inspect app.example.com
dig +short NS example.com
The shapes Vercel currently documents:
| Hostname | Record | General-purpose value in Vercel’s docs | Project-specific form (Vercel’s own examples) |
|---|---|---|---|
Apex, example.com |
A | 76.76.21.21 |
An address from a pool matched to plan and project, such as 216.198.79.1 |
Subdomain, app.example.com |
CNAME | cname.vercel-dns-0.com |
A unique name such as d1d4fc829fe7bc7c.vercel-dns-017.com |
Wildcard, *.example.com |
Vercel nameservers, or _acme-challenge NS records pointing to ns1.vercel-dns.com and ns2.vercel-dns.com plus a wildcard CNAME |
Not applicable | Not applicable |
The wildcard delegation route also needs Enable Vercel DNS switched on for the domain in your team’s Domains page, while the registrar keeps your current nameservers.
Vercel displays CNAME values with a trailing dot and asks you to copy them exactly, dot included, because the dot marks a fully qualified name. Any hostname can also be served by moving the whole domain to Vercel’s nameservers; if you go that way, copy MX and verification TXT records across first.
What the targets resolve to today
Live capture, 26 September 2026. Three consecutive queries to Vercel’s authoritative server for the general-purpose CNAME target, then the same name through 1.1.1.1 and 8.8.8.8:
$ dig +nocmd @ns1.vercel-dns-0.com cname.vercel-dns-0.com A +noall +answer
cname.vercel-dns-0.com. 300 IN A 76.76.21.22
cname.vercel-dns-0.com. 300 IN A 66.33.60.129
$ dig +nocmd @ns1.vercel-dns-0.com cname.vercel-dns-0.com A +noall +answer
cname.vercel-dns-0.com. 300 IN A 76.76.21.142
cname.vercel-dns-0.com. 300 IN A 66.33.60.66
$ dig +nocmd @ns1.vercel-dns-0.com cname.vercel-dns-0.com A +noall +answer
cname.vercel-dns-0.com. 300 IN A 76.76.21.21
cname.vercel-dns-0.com. 300 IN A 76.223.126.88
$ dig +nocmd @1.1.1.1 cname.vercel-dns-0.com A +noall +answer
cname.vercel-dns-0.com. 300 IN A 66.33.60.194
cname.vercel-dns-0.com. 300 IN A 76.76.21.93
$ dig +nocmd @8.8.8.8 cname.vercel-dns-0.com A +noall +answer
cname.vercel-dns-0.com. 300 IN A 76.76.21.164
cname.vercel-dns-0.com. 300 IN A 66.33.60.34
Five queries, five different pairs. The authoritative server rotates its answer, so two people checking the same correct CNAME can see different addresses at the same moment. This is the flexibility Vercel cites when it recommends CNAMEs: no address is hard-coded in your zone, so Vercel can steer traffic.
Live capture, 26 September 2026. Vercel’s example project-specific target, and cname.vercel-dns.com, the older name many tutorials still show:
$ dig +nocmd @1.1.1.1 d1d4fc829fe7bc7c.vercel-dns-017.com A +noall +answer
d1d4fc829fe7bc7c.vercel-dns-017.com. 300 IN A 64.29.17.65
d1d4fc829fe7bc7c.vercel-dns-017.com. 300 IN A 216.198.79.65
$ dig +nocmd @1.1.1.1 cname.vercel-dns.com A +noall +answer
cname.vercel-dns.com. 287 IN A 76.76.21.164
cname.vercel-dns.com. 287 IN A 66.33.60.34
Both names resolve. The current docs no longer list the older one, though, and a record that happens to resolve to Vercel is not the same as the record your project’s verification looks for.
Live capture, 26 September 2026. Who registers the addresses in the captures above, according to ARIN’s RDAP service:
$ for ip in 76.76.21.22 66.33.60.129 216.198.79.65 64.29.17.65 76.223.126.88; do curl -s https://rdap.arin.net/registry/ip/$ip | jq -r '"\(.startAddress)-\(.endAddress) \(.name) \(.entities[0].vcardArray[1][] | select(.[0]=="fn") | .[3])"'; done
76.76.21.0-76.76.21.255 VERCEL-01 Vercel, Inc
66.33.60.0-66.33.60.255 VERCEL-02 Vercel, Inc
216.198.79.0-216.198.79.255 VERCEL-05 Vercel, Inc
64.29.17.0-64.29.17.255 VERCEL-12 Vercel, Inc
76.223.0.0-76.223.175.255 AMAZO-4 Amazon.com, Inc.
Four blocks are registered to Vercel and one to Amazon, and all five addresses came from answers to Vercel’s own names. An IP-ownership lookup is therefore a weak test of whether a hostname points at Vercel. Compare the CNAME text with your domain card, then check the HTTP response as shown below.
Leave out AAAA records
Vercel’s troubleshooting page says it does not support IPv6 yet, so a custom domain on third-party DNS can’t point an AAAA record at Vercel. Its A-record guide adds that an AAAA record pointing at another host splits traffic between providers and can stall SSL provisioning.
Live capture, 26 September 2026. Asking for an IPv6 address for the general-purpose target:
$ dig +nocmd @1.1.1.1 cname.vercel-dns-0.com AAAA +noall +comments
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 36464
;; flags: qr rd ra; QUERY: 1, ANSWER: 0, AUTHORITY: 1, ADDITIONAL: 1
;; OPT PSEUDOSECTION:
; EDNS: version: 0, flags:; udp: 1232
NOERROR with ANSWER: 0 means the name exists but has no AAAA data. The same query for vercel.com also came back empty. At cutover, delete any AAAA record that a previous host left on the apex or on www, then confirm that dig +short AAAA example.com prints nothing.
Confirm that Vercel is answering
Vercel’s troubleshooting page checks the nameservers, the apex A record, and the subdomain CNAME with dig. Add an HTTP request at the end:
dig +short NS example.com
dig +short A example.com
dig +short CNAME www.example.com
curl -sI https://www.example.com/
Live capture, 26 September 2026. Headers from vercel.com, which Vercel serves itself:
$ curl -sI https://vercel.com/ | grep -iE "^(HTTP|server|x-vercel-id|x-vercel-cache|strict-transport-security)"
HTTP/2 200
server: Vercel
strict-transport-security: max-age=31536000; includeSubDomains; preload
x-vercel-cache: HIT
x-vercel-id: icn1::iad1::zzwx4-1790434252398-3f8e650268c6
server: Vercel and x-vercel-id are the identifying pair. Vercel documents x-vercel-id as the list of Vercel regions the request hit plus the region where the function ran; this request shows icn1 and iad1. x-vercel-cache: HIT means the CDN served a cached copy. The HSTS line is vercel.com’s own policy; Vercel’s documented default for deployments is max-age=63072000.
Treat these headers as evidence, not proof. Vercel notes that a proxy such as Cloudflare can replace the server header, and that seeing Vercel’s headers doesn’t guarantee certificate validation will succeed.
Ownership checks use TXT records
Serving records don’t prove ownership, so editing the A or CNAME record again won’t clear an ownership prompt. Vercel runs two separate checks:
- Project level. If another Vercel account already uses the hostname, the Domains page asks for a TXT record. Verifying lets you use the domain in your project; it does not move the domain into your account. Vercel notes that only one such TXT record can be set up at a time.
- Team level. Connect External on your team’s Domains page detects a domain registered with another Vercel account and shows a TXT record such as
_vercel.example.comwith avc-domain-verify=…value. Verify & Claim then moves the domain to your team. Claiming the root domain does not skip project-level verification for a hostname that another project uses.
dig +short TXT _vercel.example.com
Certificates: Let’s Encrypt over HTTP-01
- Issuer and timing. Vercel requests a Let’s Encrypt certificate for every domain added to a project. Issuance succeeds once DNS points at Vercel, typically within a few minutes of DNS verification.
- Validation method. Non-wildcard names are validated with HTTP-01, which Vercel answers itself, so the hostname must already route to Vercel. The
/.well-knownpath is reserved and can’t be redirected or rewritten. - Wildcards. These need DNS-01: use Vercel’s nameservers, or delegate
_acme-challengewith NS records. Vercel warns that the delegation can stop other providers from issuing certificates that use the same challenge name. - Renewal. Vercel renews 14 to 30 days before expiry and notifies team owners if renewal fails.
- CAA. A restrictive policy must include
0 issue "letsencrypt.org", and anissuewildpolicy must allow Let’s Encrypt as well. CAA lookups follow your CNAME to Vercel’s target, where Vercel’s policy applies; if you need your own CAA at a hostname, switch that hostname to the A record from your domain card. CAA records and Let’s Encrypt explains the lookup rules. - Leftovers. An
_acme-challengerecord from a previous provider can send DNS-01 validation elsewhere. Check withdig +short TXT _acme-challenge.example.combefore assuming Vercel is at fault.
Putting Cloudflare in front of Vercel
Vercel’s troubleshooting guidance is to route /.well-known/acme-challenge/* to Vercel on port 80 without caching, authentication, rewrites, or proxy-level redirects, or to point DNS straight at Vercel, which on Cloudflare means a DNS-only record. Validation has to keep working for every renewal, not only the first issuance. Cloudflare DNS records: proxied vs DNS only shows how to tell from the outside which mode a record is in.
www or apex as the primary
Vercel recommends www as the primary domain, with the apex redirecting to it. The CNAME behind www lets Vercel steer traffic, and browsers cache the redirect. An apex primary also works and is served from anycast A records. Either way, add both names to the project and set the direction under Settings → Domains, then Edit and Redirect to. Vercel attempts a redirect between the www and bare forms on its own, but its docs recommend configuring it explicitly. www vs apex canonical redirects covers the trade-offs beyond Vercel.
For how Vercel’s apex, IPv6, and certificate handling compare with Netlify, GitHub Pages, and Cloudflare Pages, see the comparison table in the GitHub Pages custom domain guide.