What is a Wildcard DNS Record?
A wildcard DNS record uses an asterisk (*) as the leftmost label to match any subdomain that doesn't have a more specific record. For example, *.example.com would match anything.example.com, random.example.com, test.example.com — any subdomain that isn't explicitly defined.
Wildcard DNS record
*.example.com. 3600 IN A 203.0.113.42 # All subdomains of example.com resolve to 203.0.113.42 # unless a more specific record exists
How Wildcard Records Work
Wildcards follow DNS specificity rules — more specific records always win:
Wildcard vs. specific records
*.example.com A 203.0.113.42 # wildcard (catch-all) www.example.com A 203.0.113.1 # specific (takes priority for www) app.example.com A 203.0.113.99 # specific (takes priority for app) # Result: # www.example.com → 203.0.113.1 (specific record wins) # app.example.com → 203.0.113.99 (specific record wins) # foo.example.com → 203.0.113.42 (wildcard matches) # xyz.example.com → 203.0.113.42 (wildcard matches)
Real-World Uses for Wildcard DNS
- ▸Multi-tenant SaaS apps: Give each customer their own subdomain (
customer1.yourapp.com) without creating individual DNS records - ▸Dynamic preview environments: Deploy each pull request to a unique URL like
pr-123.staging.yourapp.com - ▸Development environments: Route any
*.dev.example.comto your local dev server - ▸CDN edge caching: Serve assets from any subdomain through your CDN
Wildcard SSL Certificates
A wildcard SSL certificate covers all first-level subdomains of a domain. A certificate for *.example.com covers www.example.com, blog.example.com, app.example.com, etc. — but not deeper nesting like dev.api.example.com.
Getting a wildcard certificate with Certbot
# Requires DNS challenge (not HTTP challenge) sudo certbot certonly --manual --preferred-challenges dns -d "*.example.com" -d example.com # Certbot will ask you to add a TXT record: # _acme-challenge.example.com TXT "some-verification-string"
💡 Tip: Cloudflare users can get wildcard certificates automatically with Cloudflare's proxying enabled. The Cloudflare Universal SSL certificate covers
*.yourdomain.com for free.Limitations of Wildcard Records
- ▸Only matches one level deep —
*.example.comwon't matcha.b.example.com - ▸Can't be CNAME on the root domain
- ▸All wildcard-matched subdomains go to the same destination — you can't differentiate within the wildcard
- ▸Your application must handle the subdomain routing logic (e.g., read the
Hostheader)
⚠ Warning: Using a wildcard on a public domain means anyone could type any subdomain and get a response from your server. Make sure your application handles unknown subdomains gracefully (e.g., 404 or redirect to main site).