Render Custom Domains
Render automatically provisions and renews TLS certificates (via Let's Encrypt and Google Trust Services) for all custom domains. All HTTP traffic is redirected to HTTPS. Custom domains work on web services and static sites only.
When to Use
- Adding a custom domain to a web service or static site
- Configuring DNS records (CNAME, A, or ALIAS) with a provider
- Setting up a wildcard domain (
*.example.com) - Troubleshooting certificate issuance or domain verification failures
- Choosing between apex (
example.com) and www (www.example.com) - Disabling the
onrender.comsubdomain after adding a custom domain
Domain Limits
Setup Steps
1. Add domain in Dashboard
- Go to your service's Settings > Custom Domains
- Click + Add Custom Domain
- Enter your domain (e.g.
app.example.com) - Click Save
Adding a www subdomain automatically adds the root domain (and vice versa) with a redirect between them.
2. Configure DNS
Add a DNS record with your provider pointing to your Render service:
Important: Remove any AAAA (IPv6) records for your domain. Render uses IPv4, and stale AAAA records cause unexpected behavior.
Provider-specific guides:
3. Verify domain
Click Verify in the Dashboard. If verification fails, DNS may not have propagated yet—wait a few minutes and retry.
Speed up verification by flushing DNS caches:
After verification, Render issues a TLS certificate automatically.
Wildcard Domains
Wildcard domains (*.example.com) route all matching subdomains to one service.
Requires three CNAME records:
Cloudflare users: If you add *.example.com without adding the root domain to Render, disable proxying (gray cloud) for the root domain to avoid routing conflicts.
CAA Records
If your domain has CAA records, add entries for Render's certificate authorities:
Without these, TLS certificate issuance fails silently.
Disabling the onrender.com Subdomain
After adding at least one custom domain, you can disable the default onrender.com subdomain:
- Settings > Custom Domains > Render Subdomain > toggle to Disabled
- All requests to the
onrender.comURL receive a 404 - Can be re-enabled at any time
Blueprint Configuration
Custom domains are specified in the domains field:
Blueprint domains only declare the domain association. You still need to configure DNS with your provider manually.
Common Mistakes
References
Related Skills
- render-web-services — Web service configuration, TLS, port binding
- render-static-sites — Static site domains, CDN, headers
- render-blueprints —
domainsfield inrender.yaml
