CNAME at zone apex
A CNAME is placed at the zone apex where other record types are also required.
Problem summary
A CNAME is placed at the zone apex where other record types are also required.
Symptoms
- MX, NS, or SOA conflicts with an apex CNAME
- Mail or delegation breaks after apex CNAME publication
Possible causes
- Misconfiguration
- Incomplete rollout
- DNS propagation delay
How to diagnose
- Confirm the symptom in headers or reports
- Inspect the relevant DNS records
- Validate with a trusted checker
How to fix
- Correct the DNS or signing configuration
- Re-test and confirm alignment where required
How to verify
- Re-check DNS
- Send a test message
- Confirm expected authentication results
Prevention
- Document changes
- Monitor reports after deployment
When to escalate
- Production mail is failing authentication after a change window