Skip to Content
OAuth-first · automatic HTTPS

Your users should never touch DNS for your product.

Your customer taps one button. We detect their provider, configure DNS, and issue HTTPS — automatically.

63 DNS providers, auto-configured
The real widget — embed it in one line.
The problem

Your customers fail at the finish line.

They love your product — right up until you hand them a CNAME and a registrar login. One wrong record, one 48-hour wait, one support ticket, and the domain that was supposed to make you look legit makes you look broken. It rarely shows up as churn. It shows up as “I’ll finish setting it up later.” Why DNS onboarding fails →

0 DNS panels your customer should ever see. That’s the number the whole product is designed around.

01
Your product ships the feature
“Connect your domain” — your side works perfectly.
02
Your customer opens their registrar
A, CNAME, TXT, TTL — a control panel they have never seen.
03
The setup dies here
Wrong record, a two-day wait, or they simply give up.
See it in action

One click, and a domain goes live.

The real product — a customer connects their own domain and it's serving over HTTPS in seconds.

Silent product demo, on loop. See the full walkthrough.

Features

Everything a custom-domain feature needs — handled.

The pieces you'd otherwise build and babysit: DNS, certificates, the edge, and the monitoring that keeps them healthy.

Provider auto-detection

We fingerprint the DNS host from public records and pick the right connect path — OAuth where it exists, a scoped token, or a guided step.

Automatic DNS records

A, CNAME, TXT, MX, SPF and DKIM written correctly the first time — for apex, www and per-subdomain, as one connection or many.

Automatic SSL

Certificates issue before the first request and renew ahead of expiry. A domain is never served half-issued — no browser warnings.

Edge serving — optional

Serve customer domains from our edge, or verify and hand DNS back to your own stack. Be in the request path only if you want to be.

Drift monitoring

We re-check every hour and re-issue on change — you hear about a moved record before your customer does.

Built for developers

REST API and typed SDKs, a drop-in widget, an MCP server for AI agents, and webhooks for every state change.

For developers

One API call. Or one line of embed.

Start a connection from your backend with the API, drop the widget into your app, or let an agent do it over MCP. Same detection, same verification, same edge — a customer domain live over HTTPS.

  • REST API + typed SDKs
  • Drop-in widget, themed to your brand
  • MCP server, so AI agents connect domains too
  • Webhooks for every state change
POST /v1/connections 200 OK
# kick off a connection from your server
curl https://api.customdomain.ai/v1/connections \
  -H "Authorization: Bearer $KEY" \
  -d '{"domain":"everjust.co"}'

# ← we detect, authorize, write & verify
{
  "id": "con_8kQ2f7",
  "domain": "everjust.co",
  "provider": "cloudflare",
  "method": "oauth",
  "status": "live",
  "https": true
}
Built for your platform

One widget. Every place a domain matters.

Whether your user taps Publish in your builder, Verify domain in your email tool, or your agent calls MCP — it’s the same one-line embed, themed to your app. Pick one and watch the exact flow your end-user gets.

Your creators publish to their own domain — instantly.

They tap Publish, approve once, and their site is live over HTTPS on their own domain. No DNS panel, no 48-hour wait, no support ticket — and they never leave your builder.

  • They tapPublish
  • We writeA + CNAME → your edge
  • They getA live site on their domain, HTTPS and all

Live simulation — this is the real embedded widget, themed to your app.

everjust.co is live
Live · HTTPS secured

Serving on the edge — nothing left to configure.

Powered by Custom Domain
How it works

Five steps. One API call starts them.

01

Detect the provider

We fingerprint the customer's DNS host from public DNS and pick the right connect path automatically.

02

Write the records

Records go in over OAuth where the provider supports it, a scoped token, or a guided manual step — never a copy-paste marathon.

03

Verify ownership

Proof of ownership comes before go-live, and propagation is watched until records resolve.

04

Serve on the edge

Certificates issue before the first request, so the domain is live over HTTPS the moment it's ready.

05

Watch every hour

We re-check DNS drift and re-issue certs on their own — you find out before your customer does.

TypeHostValueStatus
Aeverjust.coedge.customdomain.ai live
CNAMEwwwedge.customdomain.ai live
TXT_acme9aF2bQ7x…Kd0verifying
Written, verified, and served — no customer action required.
Ship custom domains this week — not next quarter.
Start free with 10 connections a year. No credit card to try it.
63+ providers auto-configured

Every provider your customers already use.

OAuth where it exists, a scoped token or a guided step everywhere else — and moving from another tool keeps the same coverage.

Cloudflare
GoDaddy
Namecheap
Google Cloud DNS
Amazon Route 53
Azure DNS
DigitalOcean
Vercel
Netlify
IONOS
Squarespace
Linode
Porkbun
Hetzner
Gandi
DNSimple
Name.com
deSEC
Vultr
OVH
DNS Made Easy
NameSilo
Dynadot
DreamHost
Alibaba Cloud DNS
Bunny DNS
eNom
Hover
NameBright
TransIP
Hostinger
Spaceship
Openprovider
ClouDNS
LuaDNS
PowerDNS
easyDNS
GleSYS
Njalla

Missing one? The census-driven engine adds a provider from config — no new deploy.

Compare

Weighing the alternatives?

Honest, side-by-side breakdowns — pricing, coverage, and where each one fits.

Objections, answered

Seven questions, straight answers.

What does connecting a custom domain mean?

Serving your product from a domain your customer ownsapp.theirbrand.com instead of yours. DNS records, ownership checks and a TLS certificate, handled so they only see “connected.”

What if a provider can't be automated?

We fall back to scoped tokens or a guided manual step with the exact records to paste — and watch until they resolve.

What about apex domains, www and wildcards?

All three are written and served. Apex, www, and per-subdomain — as one connection or many.

What happens when a customer's DNS changes later?

Drift monitoring re-checks every hour. If a record moves, we fix it and flag it before anything breaks.

Are you in my request path?

Only if you want us to. Use our edge, or verify and hand off DNS to your own — your app, your call.

What if a certificate fails to issue?

Certs are never served half-issued. We retry, re-verify at the edge, and renew automatically well ahead of expiry.

Can AI agents connect domains?

Yes. A full MCP server exposes search, buy, and connect with the same verification every human path gets.

Browse the full glossary  ·  Read the setup guides

Starter includes 10 domain connections a year.

Flat tiers with included volume. You always know what a domain costs before you connect it — from $0.

Free whitepaper

The State of Custom Domain Infrastructure

Seventy-six pages on why domain onboarding breaks, and what a system that survives it looks like: the apex CNAME rule that makes a root domain illegal to point, CAA records that block certificate issuance without ever surfacing an error, and propagation your customer cannot see and you cannot prove. Built on a census of 63 DNS providers. No email required.

76 pages · 12 figures · 42 cited sources · What is inside →

Give every customer a real domain.

Fully managed. One API call to start. Live in minutes.

Newsletter

DNS and domain-setup notes for SaaS builders. About twice a month.

About two emails a month. Unsubscribe with one click.