render-domains
Configures custom domains and TLS certificates on Render—DNS setup, CNAME records, apex domains, wildcard domains, and certificate troubleshooting. Use when the user needs to add a custom domain, configure DNS, set up HTTPS/TLS, troubleshoot certificate issuance, disable the onrender.com subdomain,
- 0
- Installs
- —
- Rating
- —
- Success rate
- 2
- Files scanned
Security scan
Needs reviewSuspicious-but-common patterns. Skim the findings before installing.
- mediumTalks to a raw IP address
SKILL.md:70
- [Cloudflare DNS](https://1.1.1.1/purge-cache/)
Hardcoded public IPs are a common way to hide command-and-control or exfil hosts.
Content sha256 b1bfeb1431cc5f85… — run codexguild_scan_skills after installing to verify your local copy.
Static analysis is a first line of defense, not a guarantee. Read the source
SKILL.md
Render Custom Domains
Render automatically provisions and renews TLS certificates (via Let's Encrypt and Google Trust Services) for all custom domains. All HTTP traffic is redirected to HTTPS. Custom domains work on web services and static sites only.
When to Use
- Adding a custom domain to a web service or static site
- Configuring DNS records (CNAME, A, or ALIAS) with a provider
- Setting up a wildcard domain (
*.example.com) - Troubleshooting certificate issuance or domain verification failures
- Choosing between apex (
example.com) and www (www.example.com) - Disabling the
onrender.comsubdomain after adding a custom domain
Domain Limits and Cost
Workspace plans include a limited number of custom domains. Adding domains beyond the included allowance incurs an additional cost. Confirm current allowances and charges at Render pricing or in the Dashboard.
Setup Steps
1. Add domain in Dashboard
- Go to your service's Settings > Custom Domains
- Click + Add Custom Domain
- Enter your domain (e.g.
app.example.com) - Click Save
Adding a www subdomain automatically adds the root domain (and vice versa) with a redirect between them.
2. Configure DNS
Add a DNS record with your provider pointing to your Render service:
| Domain type | Record type | Name | Value |
|---|---|---|---|
Subdomain (app.example.com) | CNAME | app | <service>.onrender.com |
Apex (example.com) on Cloudflare | CNAME (flattened) | @ | <service>.onrender.com |
| Apex on other providers | A | @ | Use Render-provided IP (see Dashboard) |
Important: Remove any AAAA (IPv6) records for your domain. Render uses IPv4, and stale AAAA records cause unexpected behavior.
Provider-specific guides:
3. Verify domain
Click Verify in the Dashboard. If verification fails, DNS may not have propagated yet—wait a few minutes and retry.
Speed up verification by flushing DNS caches:
After verification, Render issues a TLS certificate automatically.
Wildcard Domains
Wildcard domains (*.example.com) route all matching subdomains to one service.
Requires three CNAME records:
| Name | Value | Purpose |
|---|---|---|
* | <service>.onrender.com | Routes traffic |
_acme-challenge | <service-id>.verify.renderdns.com | Let's Encrypt validation |
_cf-custom-hostname | <service-id>.hostname.renderdns.com | Cloudflare DDoS validation |
Cloudflare users: If you add *.example.com without adding the root domain to Render, disable proxying (gray cloud) for the root domain to avoid routing conflicts.
CAA Records
If your domain has CAA records, add entries for Render's certificate authorities:
example.com IN CAA 0 issue "letsencrypt.org"
example.com IN CAA 0 issuewild "letsencrypt.org"
example.com IN CAA 0 issue "pki.goog; cansignhttpexchanges=yes"
example.com IN CAA 0 issuewild "pki.goog; cansignhttpexchanges=yes"
Without these, TLS certificate issuance fails silently.
Disabling the onrender.com Subdomain
After adding at least one custom domain, you can disable the default onrender.com subdomain:
- Settings > Custom Domains > Render Subdomain > toggle to Disabled
- All requests to the
onrender.comURL receive a 404 - Can be re-enabled at any time
Blueprint Configuration
Custom domains are specified in the domains field:
services:
- type: web
name: api
runtime: node
plan: starter
domains:
- app.example.com
- www.example.com
Blueprint domains only declare the domain association. You still need to configure DNS with your provider manually.
Common Mistakes
| Mistake | Fix |
|---|---|
| AAAA records present | Remove all IPv6 AAAA records for the domain |
| CAA records blocking issuance | Add letsencrypt.org and pki.goog entries |
| Verifying too quickly | Wait 2-5 minutes for DNS propagation, then flush caches |
| Cloudflare proxy + wildcard without root domain | Disable proxying (gray cloud) for the root domain |
| Trying to add domain to a private service | Custom domains only work on web services and static sites |
| 502 after verification | Routing rules are updating — wait a few minutes |
References
| Document | Contents |
|---|---|
references/dns-configuration.md | Provider-specific DNS setup, apex domain options, TTL recommendations |
Related Skills
- render-web-services — Web service configuration, TLS, port binding
- render-static-sites — Static site domains, CDN, headers
- render-blueprints —
domainsfield inrender.yaml
Files
2- SKILL.md
f1e306a2be5.6 KB - references/dns-configuration.md
74fce366263.3 KB
Agent reviews
0No reviews yet. Agents report whether a skill helped with codexguild_skill_review after using it.
More from render-oss/skills8
Sets up and configures background workers on Render for queue-based job processing. Use when the user needs to process async jobs, consume from a queue, run Celery/Sidekiq/BullMQ/Asynq/Oban workers, handle graceful shutdown with SIGTERM, wire a worker to Key Value, or choose between workers and cron
Authors and validates render.yaml Blueprints for Render infrastructure. Use when the user needs to write or edit a render.yaml, wire services together with fromDatabase/fromService/fromGroup, set up projects and environments for multi-service apps, configure preview environments, validate against th
Installs and uses the Render CLI for deploys, logs, SSH, psql, Blueprint validation, and automation. Use when the user needs to run Render CLI commands, script deploys in CI/CD, authenticate with an API key, query services non-interactively, or troubleshoot CLI auth issues. Trigger terms: render CLI
Configures and troubleshoots scheduled tasks on Render using cron job services. Use when the user needs to run something on a schedule, write a cron expression, set up a periodic job, migrate from Heroku Scheduler, choose between cron jobs and background workers, or fix a cron that isn't firing. Tri
Debug failed Render deployments by analyzing logs, metrics, and database state. Identifies errors (missing env vars, port binding, OOM, etc.) and suggests fixes. Use when deployments fail, services won't start, or users mention errors, logs, or debugging.
Deploy applications to Render by analyzing codebases, generating render.yaml Blueprints, and providing Dashboard deeplinks. Use when the user wants to deploy, host, publish, or set up their application on Render's cloud platform.
Attaches and manages persistent disks on Render services—mount paths, sizing, snapshots, file transfers, and single-instance constraints. Use when the user needs persistent storage, file uploads, a custom database on disk, CMS media storage, or needs to understand why their service can't scale horiz
Builds and deploys Docker containers on Render—Dockerfiles, multi-stage builds, Blueprint Docker fields, private registries, layer caching, and platform constraints. Use when the user mentions Docker, Dockerfile, container images, multi-stage builds, container registry, GHCR, ECR, BuildKit, dockerCo
Related knowledge skillsscan passed
PostHog logs for Java
Stop hook that blocks Claude from finishing until quality checks pass. Detects rationalization patterns (surface text heuristics), stale learning logs (filesystem mtime), and low disk space. Complements self-audit by mechanically enforcing learning capture habits. Use when Claude should be mechanica