Alias record in DNS that points one name at another, for example www at <app>.azurewebsites.net; it can't be placed at the apex of a zone.
Also called canonical name record.
Read more: Microsoft Learn
In the Ultra Transcenders books
AZ-104AZ-700SC-300AZ-802MD-102
Each book explains CNAME in context, with comparison tables and the common traps.
Terms in this definition
- Alias record
In Azure DNS, a record set that targets an Azure resource itself (say, a CDN endpoint or public IP) rather than a fixed address, so it stays correct whenever that resource gets a new IP. Bare apex domains can use one to reach such a resource.
- DNS
The system that turns names into addresses. In Azure, private endpoints depend on private DNS zones, which are queried through 168.63.129.16.
- App protection policy
A set of Intune rules on managed apps that safeguards organisational data, for example by demanding a PIN or preventing copy-paste and save-as into personal apps. It works whether or not the device is enrolled.
Related terms
- afdverify
Verification CNAME in Front Door (classic), mapping afdverify.<host> to afdverify.<name>.azurefd.net, which proves ownership of a custom domain while live traffic stays where it is.
- Apex domain
The bare domain without any subdomain (example.com), also known as the zone apex or root domain. Since a CNAME is not allowed there, routing it to a service like Front Door relies on CNAME flattening or Azure DNS alias records.
- App Service custom domain
Host name bound to an App Service app once the service has confirmed an asuid TXT record and an A or CNAME record. Serving it over HTTPS also requires binding a TLS certificate.
- Custom domain
A DNS name of your own attached to a service. In an Entra tenant it is verified through a TXT or MX record, and every on-premises UPN suffix used to sign in must be one (.local can't be); for App Service it is bound with CNAME or TXT validation.
- DNAME
A DNS record that points an entire branch of the namespace at a different domain, whereas a CNAME only gives a single name an alias.
- Endpoint (Front Door)
Host name in Front Door Standard/Premium, shaped like
<name>-<hash>.z01.azurefd.net, to which routes are attached and custom domains point by CNAME. - privatelink zone
Private DNS zone holding a private endpoint's A record, named after the privatelink CNAME target of the service, for instance privatelink.database.windows.net for Azure SQL Database. Naming it after the public suffix is wrong.