Domain Management

Wildcard DNS — Everything You Need to Know

A wildcard DNS record matches any subdomain. Learn how to use wildcard records, their limitations, and real-world applications.

Last updated: April 2026

What is a Wildcard DNS Record?

A wildcard DNS record uses an asterisk (*) as the leftmost label to match any subdomain that doesn't have a more specific record. For example, *.example.com would match anything.example.com, random.example.com, test.example.com — any subdomain that isn't explicitly defined.

Wildcard DNS record
*.example.com. 3600 IN A 203.0.113.42
# All subdomains of example.com resolve to 203.0.113.42
# unless a more specific record exists

How Wildcard Records Work

Wildcards follow DNS specificity rules — more specific records always win:

Wildcard vs. specific records
*.example.com   A  203.0.113.42   # wildcard (catch-all)
www.example.com A  203.0.113.1    # specific (takes priority for www)
app.example.com A  203.0.113.99   # specific (takes priority for app)

# Result:
# www.example.com → 203.0.113.1  (specific record wins)
# app.example.com → 203.0.113.99 (specific record wins)
# foo.example.com → 203.0.113.42 (wildcard matches)
# xyz.example.com → 203.0.113.42 (wildcard matches)

Real-World Uses for Wildcard DNS

  • ▸Multi-tenant SaaS apps: Give each customer their own subdomain (customer1.yourapp.com) without creating individual DNS records
  • ▸Dynamic preview environments: Deploy each pull request to a unique URL like pr-123.staging.yourapp.com
  • ▸Development environments: Route any *.dev.example.com to your local dev server
  • ▸CDN edge caching: Serve assets from any subdomain through your CDN

Wildcard SSL Certificates

A wildcard SSL certificate covers all first-level subdomains of a domain. A certificate for *.example.com covers www.example.com, blog.example.com, app.example.com, etc. — but not deeper nesting like dev.api.example.com.

Getting a wildcard certificate with Certbot
# Requires DNS challenge (not HTTP challenge)
sudo certbot certonly --manual --preferred-challenges dns -d "*.example.com" -d example.com

# Certbot will ask you to add a TXT record:
# _acme-challenge.example.com TXT "some-verification-string"
💡 Tip: Cloudflare users can get wildcard certificates automatically with Cloudflare's proxying enabled. The Cloudflare Universal SSL certificate covers *.yourdomain.com for free.

Limitations of Wildcard Records

  • ▸Only matches one level deep — *.example.com won't match a.b.example.com
  • ▸Can't be CNAME on the root domain
  • ▸All wildcard-matched subdomains go to the same destination — you can't differentiate within the wildcard
  • ▸Your application must handle the subdomain routing logic (e.g., read the Host header)
⚠ Warning: Using a wildcard on a public domain means anyone could type any subdomain and get a response from your server. Make sure your application handles unknown subdomains gracefully (e.g., 404 or redirect to main site).