All Products
Search
Document Center

Server Load Balancer:Configure a CNAME record for an ALB instance

Last Updated:Aug 03, 2026

Add a CNAME record with your DNS provider to map a custom domain name to the DNS name of your ALB instance. Following the domain name service upgrade, new ALB instances cannot be accessed directly by their DNS names.

image
Important

Do not use the ALB DNS name (for example, alb-xxxx.alb.aliyuncsslb.com) as a direct business access address.

  • Accessing the ALB DNS name directly triggers security mechanisms that return a 403 error, a rejection page, or an aliyun.com redirect page.

  • Certain local or specific network environments may permit direct access due to testing policies. This does not indicate that the configuration is production-ready.

Configure and verify the CNAME record

  1. Go to the ALB console, find the target instance, and copy its DNS name from the Domain Name column.

  2. Add a DNS record with your DNS hosting provider. This example uses Alibaba Cloud DNS.

    You can add domain names not registered with Alibaba Cloud to the Alibaba Cloud DNS console to manage them with Alibaba Cloud DNS.
    1. Go to the Public Zone page in the Alibaba Cloud DNS console. Click the target domain name to open the Settings page, then click Add Record.

    2. Configure the CNAME record with the following settings, then click OK.

      • Record Type: Select CNAME.

      • Hostname: Enter the prefix of your custom domain name. For example, if your custom domain name is www.example.com, enter www.

      • Query Source: Keep the default value, Default. This setting applies the record to all DNS requests.

      • TTL: The Time-to-Live (TTL) specifies how long DNS resolvers cache the record. A lower TTL value helps changes take effect more quickly.

      • Record Value: Paste the DNS name of the ALB instance that you copied earlier.

      To resolve a DNS record conflict when adding the record, delete the conflicting record or use a different hostname.
  3. Verify that the custom domain name points to the ALB instance.

    1. Open a command-line terminal on your local computer and run ping <custom_domain_name> or dig <custom_domain_name>.

    2. If the output includes the DNS name of the ALB instance (for example, alb-xxxx.<region-id>.alb.aliyuncsslb.com), the CNAME record is active.

      Note: New CNAME records take effect almost immediately. However, changes to existing records can take longer to propagate, as DNS servers follow the cached record until its TTL expires.

FAQ

Should I use a CNAME record, or point an A record directly to the ALB IP (EIP/VIP)?

Using a CNAME record is strongly recommended. Point your custom domain name to the DNS name of the ALB instance. ALB has an independent address in each enabled availability zone (for a public instance, the elastic IP address (EIP) bound in each zone; for a private instance, the private VIP in each zone). When you access ALB through a CNAME record, each DNS resolution returns the currently healthy set of addresses. If an availability zone fails, ALB removes that zone's addresses from the resolution results through automatic DNS withdrawal, providing zone-level automatic disaster recovery.

Point your domain name to a specific ALB address with an A record only in special scenarios that require a fixed IP address:

  • Public access: Resolve to the EIP bound in the target availability zone.

  • Internal access: Resolve to the private VIP of the target availability zone.

You can view and copy the EIP and VIP addresses of each availability zone in the availability zone area on the instance details page.

Note the following limitations when using an A record for direct resolution:

  • The address corresponds to a single availability zone, so you cannot benefit from cross-zone traffic distribution.

  • If that availability zone fails, ALB's automatic DNS withdrawal does not apply to your fixed A record, which interrupts traffic. You must implement your own address health checking and failover.

  • If the EIP/VIP address changes (for example, due to unbinding, release, reclamation for an overdue payment, or an availability zone adjustment), you must manually update your DNS record. Otherwise, access fails.

How do I access a public ALB instance from an internal network?

When you access a public ALB instance from an internal network, the internal DNS cannot automatically resolve the ALB DNS name. You must manually add resolution records to your internal DNS to point the ALB DNS name to its private IP address:

  1. Configure PrivateZone: PrivateZone does not automatically recognize ALB instances. In PrivateZone, manually add an A record using the same domain name as your public-facing custom domain, pointing to the ALB private IP address. For instructions, see Quick start for Private Zone.

  2. Configure on-premises DNS: If the environment that needs to access ALB over the internal network uses a self-managed DNS server, configure the same A record on that server, also pointing to the ALB private IP address.

After you complete this configuration, internal traffic can reach the ALB directly over the private network.

What should I do if dig returns a different number of IP addresses than expected?

If dig <custom_domain_name> returns fewer IP addresses than expected, the discrepancy may be caused by caching or scheduling policies on third-party DNS servers. To rule out this cause, retest using Alibaba Cloud Public DNS (223.5.5.5) or Google Public DNS (8.8.8.8):

dig <custom_domain_name> @223.5.5.5

References

To learn how to forward requests from different domain names to different backend servers using the same ALB instance, see these documents: