# Help understanding DNS-01 domain delegation

**URL:** <https://community.letsencrypt.org/t/help-understanding-dns-01-domain-delegation/149196>\
**Category:** Help\
**Created:** [April 7, 2021, 1:09am UTC](https://community.letsencrypt.org/t/help-understanding-dns-01-domain-delegation/149196 "2021-04-07T01:09:50Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![ninjasloth](https://avatars.discourse-cdn.com/v4/letter/n/7ba0ec/32.png) [@ninjasloth](https://community.letsencrypt.org/u/ninjasloth)\
**Post date:** [April 7, 2021, 1:09am UTC](https://community.letsencrypt.org/t/help-understanding-dns-01-domain-delegation/149196/1 "2021-04-07T01:09:50Z")

</div>

Hey,

I'm just looking for a bit of clarity on how the dns delegation works with acme/dns-01.  
I've had a look at some other threads and couldn't really find a clear answer.  
Currently I have cert-manager running inside a k8s cluster using letsencrypt.  
I have it using dns-01 via route53 to an isolated subdomain so credentials are restricted.  
E.g [certs.example.com](http://certs.example.com)

I want users to be able to self service certificates easily for our domain.

In the main [example.com](http://example.com) zone I have the \_acme-challenge cname.  
\_acme-challenge.example.com CNAME \_acme-challenge.certs.example.com

Where I am getting a bit lost is this allows me to only generate the exact domain name "[example.com](http://example.com)" or a wildcard "\*.example.com"  
For any other domain name i require additional aliases?  
E.g  
\_acme-challenge.myapp.example.com CNAME \_acme-challenge.certs.example.com  
\_acme-challenge.webapp2.example.com CNAME \_acme-challenge.certs.example.com

So if I want to allow my users to generate certs easily for any app they make in k8s, they would either have to use a wildcard or we would have to make a CNAME every time they need a new domain name for an application?  
Is there a way to simply delegate all requests for a domain to a subdomain without needing a CNAME for every single required fqdn?

Or am I possibly looking at the wrong implementation or letsencrypt for my use case?

---

<div class="post-metadata">

**Author:** ![rg305](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rg305/32/91314_2.png) [@rg305](https://community.letsencrypt.org/u/rg305)\
**Post date:** [April 7, 2021, 2:13am UTC](https://community.letsencrypt.org/t/help-understanding-dns-01-domain-delegation/149196/2 "2021-04-07T02:13:25Z")

</div>

> [@ninjasloth](#):
>
> Is there a way to simply delegate all requests for a domain to a subdomain without needing a CNAME for every single required fqdn?

Name reduction only happens when you can group similar names within a single wildcard.  
Then you can CNAME the **\_acme-challenge** entry required for that wildcard (and all others) to any other FQDN.  
Otherwise, you will likely need one-for-one CNAME entries for each name requiring a cert.  
[some can be grouped in DNS with the "\*" - but that usually fails for root folder domain entries]

Example:

- [www1.us.company.com](http://www1.us.company.com)
- [www2.us.company.com](http://www2.us.company.com)
- [www99.us.company.com](http://www99.us.company.com)

Can all be easily CNAMED with:  
\ ***.us.company.com** \> some.other.domain.name

But it is not so easy with:

- [www1.company.com](http://www1.company.com)
- [www2.company.com](http://www2.company.com)
- [www99.company.com](http://www99.company.com)

As trying to create \ ***.company.com** would overlap/conflict with many required DNS entries in that zone.

And to answer your question:  
No. There is no simple way to delegate **all** requests.

---

<div class="post-metadata">

**Author:** ![ninjasloth](https://avatars.discourse-cdn.com/v4/letter/n/7ba0ec/32.png) [@ninjasloth](https://community.letsencrypt.org/u/ninjasloth)\
**Post date:** [April 7, 2021, 2:44am UTC](https://community.letsencrypt.org/t/help-understanding-dns-01-domain-delegation/149196/3 "2021-04-07T02:44:55Z")

</div>

That's awesome, thank you @rg305 for that response.  
That clears things up for me!

---

<div class="post-metadata">

**Author:** ![system](https://global.discourse-cdn.com/letsencrypt/original/3X/c/a/ca6c06ea1ea201324bba7048c6841ce60236468d.png) [@system](https://community.letsencrypt.org/u/system)\
**Post date:** [May 7, 2021, 2:45am UTC](https://community.letsencrypt.org/t/help-understanding-dns-01-domain-delegation/149196/4 "2021-05-07T02:45:36Z")

</div>

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.
