Your users should never touch DNS for your product.
Your customer taps one button. We detect their provider, configure DNS, and issue HTTPS — automatically.
Your customers fail at the finish line.
They love your product — right up until you hand them a CNAME and a registrar login. One wrong record, one 48-hour wait, one support ticket, and the domain that was supposed to make you look legit makes you look broken. It rarely shows up as churn. It shows up as “I’ll finish setting it up later.” Why DNS onboarding fails →
0 DNS panels your customer should ever see. That’s the number the whole product is designed around.
One click, and a domain goes live.
The real product — a customer connects their own domain and it's serving over HTTPS in seconds.
Silent product demo, on loop. See the full walkthrough.
Everything a custom-domain feature needs — handled.
The pieces you'd otherwise build and babysit: DNS, certificates, the edge, and the monitoring that keeps them healthy.
Provider auto-detection
We fingerprint the DNS host from public records and pick the right connect path — OAuth where it exists, a scoped token, or a guided step.
Automatic DNS records
A, CNAME, TXT, MX, SPF and DKIM written correctly the first time — for apex, www and per-subdomain, as one connection or many.
Automatic SSL
Certificates issue before the first request and renew ahead of expiry. A domain is never served half-issued — no browser warnings.
Edge serving — optional
Serve customer domains from our edge, or verify and hand DNS back to your own stack. Be in the request path only if you want to be.
Drift monitoring
We re-check every hour and re-issue on change — you hear about a moved record before your customer does.
Built for developers
REST API and typed SDKs, a drop-in widget, an MCP server for AI agents, and webhooks for every state change.
One API call. Or one line of embed.
Start a connection from your backend with the API, drop the widget into your app, or let an agent do it over MCP. Same detection, same verification, same edge — a customer domain live over HTTPS.
- REST API + typed SDKs
- Drop-in widget, themed to your brand
- MCP server, so AI agents connect domains too
- Webhooks for every state change
# kick off a connection from your server curl https://api.customdomain.ai/v1/connections \ -H "Authorization: Bearer $KEY" \ -d '{"domain":"everjust.co"}' # ← we detect, authorize, write & verify { "id": "con_8kQ2f7", "domain": "everjust.co", "provider": "cloudflare", "method": "oauth", "status": "live", "https": true }
One widget. Every place a domain matters.
Whether your user taps Publish in your builder, Verify domain in your email tool, or your agent calls MCP — it’s the same one-line embed, themed to your app. Pick one and watch the exact flow your end-user gets.
Live simulation — this is the real embedded widget, themed to your app.
Built for however your customers show up.
Every platform has the same last-mile problem — a customer's own domain. Pick yours for the specifics.
Five steps. One API call starts them.
Detect the provider
We fingerprint the customer's DNS host from public DNS and pick the right connect path automatically.
Write the records
Records go in over OAuth where the provider supports it, a scoped token, or a guided manual step — never a copy-paste marathon.
Verify ownership
Proof of ownership comes before go-live, and propagation is watched until records resolve.
Serve on the edge
Certificates issue before the first request, so the domain is live over HTTPS the moment it's ready.
Watch every hour
We re-check DNS drift and re-issue certs on their own — you find out before your customer does.
Every provider your customers already use.
OAuth where it exists, a scoped token or a guided step everywhere else — and moving from another tool keeps the same coverage.
Missing one? The census-driven engine adds a provider from config — no new deploy.
Weighing the alternatives?
Honest, side-by-side breakdowns — pricing, coverage, and where each one fits.
Seven questions, straight answers.
What does connecting a custom domain mean?
Serving your product from a domain your customer owns — app.theirbrand.com instead of yours. DNS records, ownership checks and a TLS certificate, handled so they only see “connected.”
What if a provider can't be automated?
We fall back to scoped tokens or a guided manual step with the exact records to paste — and watch until they resolve.
What about apex domains, www and wildcards?
All three are written and served. Apex, www, and per-subdomain — as one connection or many.
What happens when a customer's DNS changes later?
Drift monitoring re-checks every hour. If a record moves, we fix it and flag it before anything breaks.
Are you in my request path?
Only if you want us to. Use our edge, or verify and hand off DNS to your own — your app, your call.
What if a certificate fails to issue?
Certs are never served half-issued. We retry, re-verify at the edge, and renew automatically well ahead of expiry.
Can AI agents connect domains?
Yes. A full MCP server exposes search, buy, and connect with the same verification every human path gets.
Starter includes 10 domain connections a year.
Flat tiers with included volume. You always know what a domain costs before you connect it — from $0.
Give every customer a real domain.
Fully managed. One API call to start. Live in minutes.