Your domain, your name: what connecting one actually does
What a DNS record proves, why we refuse to serve a name until it resolves, and why that refusal protects you as much as us.
Connecting a domain sounds like paperwork and is actually the most security-relevant thing you will do on the platform. It is worth ten minutes of understanding.
What you are proving
When you add the DNS record we give you, you are proving something that cannot be faked: that you control the domain. Nobody else can create that record. Not us, not a competitor, not somebody who happens to know your domain name.
That is why we insist on it, rather than accepting a typed-in domain name and taking your word for it.
What happens if a platform does not insist
Imagine a service that lets anyone claim any hostname. Somebody types a name one character off a real bank’s. The platform dutifully requests a certificate for it and starts serving a page.
That is a phishing site with a valid padlock and a real certificate, hosted by a company whose name is now attached to it. The DNS check is the single thing standing between a hosting platform and being that company.
So until your record exists, your entry does nothing at all here: no route, no certificate, nothing served. Inert by design.
Why some names are refused outright
Our own addresses, and anything under the domains we use for previews and live apps. If somebody could claim one of those, they could shadow another customer’s app — their visitors would arrive at a page that is not theirs. Not a theoretical risk; a straightforward one.
The certificate
Automatic and free, issued once the name resolves here and renewed without anyone thinking about it. You do not buy one, install one, or diarise its expiry.
Buying versus connecting
Either works. We hold a registrar account, so you can tell us the name you want and we buy it, set it up and point it at your app — you are told the cost first and you never see a registrar’s control panel.
If you already own a name, connect it instead: one DNS record and it is live. Both routes end in the same place, and the certificate is automatic.
Build the thing this is about
Ask for access and a person reads it. You start with 300 free sparks, about forty changes.
Request access Take the free founder test
Access is by invitation and a person reads every request. The founder test is free, takes a few minutes, and tells you what you are getting before you commit to anything.