DNS

Connect a Cloudflare API token and the zones on that account appear in the Console. From there you can edit records, let Depfloy open the record for a domain you add to a project, and apply a guided setup for Google Workspace, Microsoft 365 or a transactional mail provider without hand-writing the records.

Connecting Cloudflare #

Go to Configuration → Integrations and add a Cloudflare integration. It takes an API token, which you create in your Cloudflare dashboard.

The screen lists the two permissions the token needs, with the reason for each:

PermissionWhy
Zone / Zone / ReadList the zones on your account
Zone / DNS / EditRead and write the records in them

Depfloy asks for nothing beyond those two. The token is stored encrypted and can be replaced or removed from the same screen.

DNS is available on every plan.

DNS for custom preview domains #

Custom preview bases are a Business feature configured under Configuration → Preview domains. This is separate from adding a production domain to a project.

With Cloudflare manages DNS, Depfloy uses a connected, verified integration to create the ownership record and each project’s DNS-only CNAME. With I manage DNS, no provider credential is stored: add the displayed TXT record to verify the base, then add the displayed CNAME for each project and ask Depfloy to check it. See Custom preview domains for readiness, HTTPS, role access, and plan-change behavior.

Zones and records #

DNS in the Console top bar lists the zones read from your connected account, with a filter box for finding one. Open a zone for its records.

Seven record types can be created, edited and deleted: A, AAAA, CNAME, TXT, MX, NS and CAA.

  • The proxy switch appears on A, AAAA and CNAME records only — there is nothing to proxy on the others.
  • A record’s type is fixed once it exists. To change one, delete it and create the record you want.
  • A record Depfloy opened for you says so when you open it: “This record was opened by Depfloy when the domain was added.”

Adding a domain opens its record #

When you add a domain to a project and a connected zone covers it, the Add New Domain dialog changes: pick the zone, name the subdomain, and leave the first box empty to use the zone itself.

The dialog says what it is about to do before you press the button. With the server’s address known, it opens an A record for that name pointing at it, DNS-only rather than proxied, so a certificate can be issued. When the project’s server has no public address yet, it says that too, and leaves the record for you to add from the DNS screen once the server is up.

Verification is then read from Cloudflare rather than waited on: there is no propagation delay to sit through before the domain is usable.

Two rules govern what Depfloy touches afterwards:

  • It removes only records it opened itself. A record you created by hand is never deleted, even when it points at the same name.
  • If the server’s public address changes, the records Depfloy manages are updated to the new one.

Certificates and CAA #

A CAA record on a domain tells certificate authorities which of them may issue for it. If one exists and does not include Let’s Encrypt, no certificate can be issued — and a request that goes ahead anyway fails partway through, on the authority’s side, for a reason nothing in the request explains.

So the request is not started. Depfloy checks the CAA policy first and, when it blocks issuance, says which name carries the record, what it reads today, and what to add:

A CAA record on example.com does not authorise Let’s Encrypt, so no certificate can be issued for shop.example.com. It currently reads: 0 issue “digicert.com”. Add a CAA record on example.com with tag issue and value letsencrypt.org, then try again.

The check follows the same rule certificate authorities do: the policy comes from the closest ancestor that carries a CAA record, not from the apex alone. A record on example.com governs shop.example.com when shop.example.com has none of its own.

Guided setups #

Open a zone and choose Guided setup for a provider you are pointing the domain at:

  • Google Workspace — mail routing and SPF
  • Microsoft 365 — mail routing, autodiscover and SPF, with your tenant’s MX host
  • DMARC (monitoring only) — a p=none policy that reports where mail claiming to be from your domain is sent from, and changes nothing about delivery
  • Resend — sending domain records
  • Postmark — sending domain records

Nothing is written before you see it #

Preview changes shows the plan: every record that will be added, every one that will be changed with its current and new value, and the ones that are already correct, marked No change. Records the setup does not touch are not in the list.

Applying then walks the plan. If a write fails partway through, the writes already made are put back, so a half-finished mail setup is not left live on the domain. Cloudflare has no way to write records as one transaction, so this is Depfloy undoing its own work rather than a rollback the API performs.

DKIM values come from your provider #

A preset fills in everything it can compute. It cannot compute a DKIM key: that value is generated by the provider for your domain, so Resend and Postmark ask you to paste it, and Postmark asks for the selector alongside it. Take both from the provider’s own setup screen.

SPF is merged, not duplicated #

A domain may publish exactly one v=spf1 record. Adding a second does not extend the first — it puts the domain into permerror, which fails SPF as completely as publishing nothing.

A guided setup therefore never writes an SPF record of its own. It merges what the provider needs into the record already there and shows you the merged value in the preview. If the zone already carries more than one SPF record, the setup stops and tells you, rather than adding to the problem.

SPF also has a limit of ten DNS lookups during evaluation; the eleventh is a permerror. The preview counts the lookups the merged record will need and warns you before applying when the result would cross that line.

Who can do what #

OwnerAdminManagerDeveloperViewer
View zones and records✓✓✓✓✓
Create, edit and delete records, apply guided setups✓✓✓——
Connect or remove the Cloudflare integration✓✓———

See Members for how roles work.