Skip to Content
OAuth-first · automatic HTTPS

Your users should never touch DNS for your product.

Your customer taps one button. We detect their provider, configure DNS, and issue HTTPS — automatically.

63 DNS providers, auto-configured
The real widget — embed it in one line.
The problem

Your customers fail at the finish line.

They love your product — right up until you hand them a CNAME and a registrar login. One wrong record, one 48-hour wait, one support ticket, and the domain that was supposed to make you look legit makes you look broken. It rarely shows up as churn. It shows up as “I’ll finish setting it up later.” Why DNS onboarding fails →

0 DNS panels your customer should ever see. That’s the number the whole product is designed around.

01
Your product ships the feature
“Connect your domain” — your side works perfectly.
02
Your customer opens their registrar
A, CNAME, TXT, TTL — a control panel they have never seen.
03
The setup dies here
Wrong record, a two-day wait, or they simply give up.
See it in action

One click, and a domain goes live.

The real product — a customer connects their own domain and it's serving over HTTPS in seconds.

Silent product demo, on loop. See the full walkthrough.

Features

Everything a custom-domain feature needs — handled.

The pieces you'd otherwise build and babysit: DNS, certificates, the edge, and the monitoring that keeps them healthy.

Provider auto-detection

We fingerprint the DNS host from public records and pick the right connect path — OAuth where it exists, a scoped token, or a guided step.

Automatic DNS records

A, CNAME, TXT, MX, SPF and DKIM written correctly the first time — for apex, www and per-subdomain, as one connection or many.

Automatic SSL

Certificates issue before the first request and renew ahead of expiry. A domain is never served half-issued — no browser warnings.

Edge serving — optional

Serve customer domains from our edge, or verify and hand DNS back to your own stack. Be in the request path only if you want to be.

Drift monitoring

We re-check every hour and re-issue on change — you hear about a moved record before your customer does.

Built for developers

REST API and typed SDKs, a drop-in widget, an MCP server for AI agents, and webhooks for every state change.

For developers

One API call. Or one line of embed.

Start a connection from your backend with the API, drop the widget into your app, or let an agent do it over MCP. Same detection, same verification, same edge — a customer domain live over HTTPS.

  • REST API + typed SDKs
  • Drop-in widget, themed to your brand
  • MCP server, so AI agents connect domains too
  • Webhooks for every state change
POST /v1/connections 200 OK
# kick off a connection from your server
curl https://api.customdomain.ai/v1/connections \
  -H "Authorization: Bearer $KEY" \
  -d '{"domain":"everjust.co"}'

# ← we detect, authorize, write & verify
{
  "id": "con_8kQ2f7",
  "domain": "everjust.co",
  "provider": "cloudflare",
  "method": "oauth",
  "status": "live",
  "https": true
}
Built for your platform

One widget. Every place a domain matters.

Whether your user taps Publish in your builder, Verify domain in your email tool, or your agent calls MCP — it’s the same one-line embed, themed to your app. Pick one and watch the exact flow your end-user gets.

    Live simulation — this is the real embedded widget, themed to your app.

    Powered by Custom Domain
    How it works

    Five steps. One API call starts them.

    01

    Detect the provider

    We fingerprint the customer's DNS host from public DNS and pick the right connect path automatically.

    02

    Write the records

    Records go in over OAuth where the provider supports it, a scoped token, or a guided manual step — never a copy-paste marathon.

    03

    Verify ownership

    Proof of ownership comes before go-live, and propagation is watched until records resolve.

    04

    Serve on the edge

    Certificates issue before the first request, so the domain is live over HTTPS the moment it's ready.

    05

    Watch every hour

    We re-check DNS drift and re-issue certs on their own — you find out before your customer does.

    TypeHostValueStatus
    Aeverjust.coedge.customdomain.ai live
    CNAMEwwwedge.customdomain.ai live
    TXT_acme9aF2bQ7x…Kd0verifying
    Written, verified, and served — no customer action required.
    Ship custom domains this week — not next quarter.
    Start free with 10 connections a year. No credit card to try it.
    63+ providers auto-configured

    Every provider your customers already use.

    OAuth where it exists, a scoped token or a guided step everywhere else — and moving from another tool keeps the same coverage.

    Cloudflare
    GoDaddy
    Namecheap
    Google Cloud DNS
    Amazon Route 53
    Azure DNS
    DigitalOcean
    Vercel
    Netlify
    IONOS
    Squarespace
    Linode
    Porkbun
    Hetzner
    Gandi
    DNSimple
    Name.com
    deSEC
    Vultr
    OVH
    DNS Made Easy
    NameSilo
    Dynadot
    DreamHost
    Alibaba Cloud DNS
    Bunny DNS
    eNom
    Hover
    NameBright
    TransIP
    Hostinger
    Spaceship
    Openprovider
    ClouDNS
    LuaDNS
    PowerDNS
    easyDNS
    GleSYS
    Njalla

    Missing one? The census-driven engine adds a provider from config — no new deploy.

    Compare

    Weighing the alternatives?

    Honest, side-by-side breakdowns — pricing, coverage, and where each one fits.

    Objections, answered

    Seven questions, straight answers.

    What does connecting a custom domain mean?

    Serving your product from a domain your customer ownsapp.theirbrand.com instead of yours. DNS records, ownership checks and a TLS certificate, handled so they only see “connected.”

    What if a provider can't be automated?

    We fall back to scoped tokens or a guided manual step with the exact records to paste — and watch until they resolve.

    What about apex domains, www and wildcards?

    All three are written and served. Apex, www, and per-subdomain — as one connection or many.

    What happens when a customer's DNS changes later?

    Drift monitoring re-checks every hour. If a record moves, we fix it and flag it before anything breaks.

    Are you in my request path?

    Only if you want us to. Use our edge, or verify and hand off DNS to your own — your app, your call.

    What if a certificate fails to issue?

    Certs are never served half-issued. We retry, re-verify at the edge, and renew automatically well ahead of expiry.

    Can AI agents connect domains?

    Yes. A full MCP server exposes search, buy, and connect with the same verification every human path gets.

    Browse the full glossary  ·  Read the setup guides

    Starter includes 10 domain connections a year.

    Flat tiers with included volume. You always know what a domain costs before you connect it — from $0.

    Give every customer a real domain.

    Fully managed. One API call to start. Live in minutes.