Cloudflare DNS
Set up Cloudflare records for an Openstead custom domain and resolve verification problems.
You can keep Cloudflare as your DNS provider while hosting the application on Openstead. Openstead's domain verification requires the hostname to resolve directly to the service's displayed IPv4 destination.
Before changing records
Deploy the service, add the hostname under Custom Domains, and keep the DNS-record instructions open. Record the current DNS settings so you can review an existing site's cutover.
Do not change mail-related MX, SPF, DKIM, or DMARC records when connecting only a website hostname.
Add a subdomain
For app.example.com, create these records in Cloudflare's DNS page:
| Type | Name | Content | Proxy |
|---|---|---|---|
| TXT | _runivo-challenge.app | Exact verification value from Openstead | Not applicable |
| CNAME | app | Service target from Openstead | DNS only |
Cloudflare shows DNS-only mode as the grey cloud. Do not put https:// or a path in the CNAME target.
Add the root domain
For example.com, use the service's root-domain A-record alternative:
| Type | Name | Content | Proxy |
|---|---|---|---|
| TXT | _runivo-challenge | Exact verification value from Openstead | Not applicable |
| A | @ | IPv4 address displayed in Openstead | DNS only |
If you also want www.example.com, add it as another custom domain in Openstead and publish its own records. One hostname's verification does not automatically verify the other.
Resolve conflicts
Remove conflicting A records, CNAMEs, or AAAA records for the hostname being moved. A stale AAAA record can send IPv6-capable visitors elsewhere even while the A record looks correct.
Do not remove unrelated records or all records for the domain. Limit changes to the exact hostname and its Openstead ownership TXT record.
Keep DNS-only mode
An orange-cloud proxied record returns Cloudflare addresses rather than the service's direct destination. Openstead's verification will report that the hostname does not point to the expected service.
Keep the record DNS-only for this integration, including after the initial verification, because Openstead rechecks routing and certificate status. Your HTTPS connection is served with the certificate managed by Openstead. Cloudflare proxy features do not apply to a DNS-only hostname.
Verify
Return to Openstead and let automatic verification continue. The page reports DNS verification and HTTPS status separately. If needed, select Verify DNS once after correcting records.
With DNS tools installed, you can inspect public answers:
nslookup -type=TXT _runivo-challenge.app.example.com
nslookup app.example.comReplace the example with your hostname. Local resolver caches can show older results temporarily. The dashboard's detailed message indicates whether ownership, routing, or the certificate is still pending.