{
  "@context": "https://schema.org",
  "@graph": [
    {
      "@type": "Blog",
      "@id": "https://approximated.app/blog/#blog",
      "url": "https://approximated.app/blog/",
      "name": "Approximated Blog",
      "inLanguage": "en",
      "blogPost": [
        {
          "@id": "https://approximated.app/blog/custom-domain-security/#article"
        },
        {
          "@id": "https://approximated.app/blog/custom-domain-onboarding-checklist/#article"
        },
        {
          "@id": "https://approximated.app/blog/apex-domains-for-saas/#article"
        },
        {
          "@id": "https://approximated.app/blog/best-custom-domain-apis-for-saas/#article"
        },
        {
          "@id": "https://approximated.app/blog/custom-domains-for-saas-guide/#article"
        }
      ]
    },
    {
      "@type": "BlogPosting",
      "@id": "https://approximated.app/blog/custom-domain-security/#article",
      "url": "https://approximated.app/blog/custom-domain-security/",
      "headline": "Custom domain security for multi-tenant SaaS",
      "description": "Secure SaaS custom domains with safe tenant claims, WAF and DDoS protection, Edge Verify, monitoring, and verified hostname reassignment.",
      "abstract": "secure custom domains at three boundaries: who may bind a hostname, which tenant a request may reach, and what happens when the binding is removed. Managed TLS protects the connection, but it doesn't decide whether the right customer owns a name or whether your application selected the right tenant.",
      "datePublished": "2026-09-23",
      "dateModified": "2026-09-28",
      "inLanguage": "en",
      "articleSection": "Security",
      "author": {
        "@type": "Organization",
        "@id": "https://approximated.app/#organization",
        "name": "Approximated",
        "url": "https://approximated.app/"
      },
      "publisher": {
        "@type": "Organization",
        "@id": "https://approximated.app/#organization",
        "name": "Approximated",
        "url": "https://approximated.app/"
      },
      "mainEntityOfPage": {
        "@type": "WebPage",
        "@id": "https://approximated.app/blog/custom-domain-security/"
      },
      "isPartOf": {
        "@id": "https://approximated.app/blog/#blog"
      },
      "isAccessibleForFree": true,
      "wordCount": 1262,
      "keywords": [
        "Custom domain security",
        "Multi-tenant SaaS",
        "WAF and DDoS protection",
        "Edge Verify"
      ],
      "about": [
        {
          "@type": "DefinedTerm",
          "name": "Custom domain security"
        },
        {
          "@type": "DefinedTerm",
          "name": "Multi-tenant SaaS"
        },
        {
          "@type": "DefinedTerm",
          "name": "WAF and DDoS protection"
        },
        {
          "@type": "DefinedTerm",
          "name": "Edge Verify"
        }
      ],
      "citation": [
        "https://approximated.app/docs/#virtual-hosts-api",
        "https://approximated.app/blog/custom-domain-onboarding-checklist/",
        "https://approximated.app/guides/",
        "https://cheatsheetseries.owasp.org/cheatsheets/Subdomain_Takeover_Prevention_Cheat_Sheet.html",
        "https://approximated.app/#waf",
        "https://approximated.app/docs/#edge-verify",
        "https://approximated.app/docs/#webhooks",
        "https://approximated.app/#faq",
        "https://approximated.app/self-hosted/",
        "https://approximated.app/pricing/",
        "https://approximated.app/product/",
        "https://approximated.app/docs/",
        "https://approximated.app/blog/best-custom-domain-apis-for-saas/"
      ],
      "hasPart": [
        {
          "@id": "https://approximated.app/blog/custom-domain-security/#faq"
        }
      ],
      "encoding": {
        "@type": "MediaObject",
        "encodingFormat": "text/markdown",
        "contentUrl": "https://approximated.app/blog/custom-domain-security/index.md"
      }
    },
    {
      "@type": "FAQPage",
      "@id": "https://approximated.app/blog/custom-domain-security/#faq",
      "url": "https://approximated.app/blog/custom-domain-security/#faq",
      "name": "Custom domain security for multi-tenant SaaS: frequently asked questions",
      "inLanguage": "en",
      "isPartOf": {
        "@id": "https://approximated.app/blog/custom-domain-security/#article"
      },
      "mainEntity": [
        {
          "@type": "Question",
          "@id": "https://approximated.app/blog/custom-domain-security/#faq-https-ownership",
          "url": "https://approximated.app/blog/custom-domain-security/#faq-https-ownership",
          "name": "Does automatic HTTPS prevent custom domain takeover in a multi-tenant SaaS?",
          "acceptedAnswer": {
            "@type": "Answer",
            "@id": "https://approximated.app/blog/custom-domain-security/#faq-https-ownership-answer",
            "text": "HTTPS encrypts a connection to a hostname; it doesn't decide which tenant is allowed to use that hostname. Your application must authorize domain changes, enforce one active tenant claim per normalized hostname, and reject unknown hosts. We handle certificates and edge protection, while tenant identity, hostname ownership, and application authorization remain your controls."
          }
        },
        {
          "@type": "Question",
          "@id": "https://approximated.app/blog/custom-domain-security/#faq-dangling-dns",
          "url": "https://approximated.app/blog/custom-domain-security/#faq-dangling-dns",
          "name": "How do I prevent a disconnected custom domain from being claimed by another tenant?",
          "acceptedAnswer": {
            "@type": "Answer",
            "@id": "https://approximated.app/blog/custom-domain-security/#faq-dangling-dns-answer",
            "text": "Stop serving the old tenant but retain a non-routing hostname reservation while DNS can still point at your shared edge. Require fresh proof bound to the exact hostname and requesting account before reassignment. A stale A or CNAME record isn't sufficient proof for a different tenant. Tell the former customer to remove obsolete DNS and make transfer an explicit audited action."
          }
        },
        {
          "@type": "Question",
          "@id": "https://approximated.app/blog/custom-domain-security/#faq-control-layers",
          "url": "https://approximated.app/blog/custom-domain-security/#faq-control-layers",
          "name": "What security controls should a SaaS custom domain feature include?",
          "acceptedAnswer": {
            "@type": "Answer",
            "@id": "https://approximated.app/blog/custom-domain-security/#faq-control-layers-answer",
            "text": "Use authorized hostname claims, exact tenant mappings, trusted proxy headers, unknown-host rejection, and safe transfer and removal. Add edge request inspection, traffic-abuse controls, form protection, and ongoing domain monitoring. Our dedicated cloud clusters combine WAF and DDoS protection, Edge Verify, and operational signals for many customer domains; your app continues to enforce login, sessions, and tenant access."
          }
        },
        {
          "@type": "Question",
          "@id": "https://approximated.app/blog/custom-domain-security/#faq-multi-tenant-waf",
          "url": "https://approximated.app/blog/custom-domain-security/#faq-multi-tenant-waf",
          "name": "How does Approximated protect traffic across many tenant domains?",
          "acceptedAnswer": {
            "@type": "Answer",
            "@id": "https://approximated.app/blog/custom-domain-security/#faq-multi-tenant-waf-answer",
            "text": "Our WAF and DDoS protection operates in the dedicated cluster serving your SaaS domains. It combines request inspection, client fingerprints, and traffic analysis, using shared threat intelligence alongside evidence from your own traffic. It can challenge suspicious clients and restrict qualifying attacks before they reach your origin. Monitor the outcome for legitimate customer flows as you introduce protection rules."
          }
        },
        {
          "@type": "Question",
          "@id": "https://approximated.app/blog/custom-domain-security/#faq-edge-verify-forms",
          "url": "https://approximated.app/blog/custom-domain-security/#faq-edge-verify-forms",
          "name": "How does Edge Verify protect forms on customer-owned domains?",
          "acceptedAnswer": {
            "@type": "Answer",
            "@id": "https://approximated.app/blog/custom-domain-security/#faq-edge-verify-forms-answer",
            "text": "Edge Verify serves its browser script from the customer's own domain and checks form submissions at the edge. Verification tokens are short-lived, single-use, and bound to the domain and visitor. Monitor mode records outcomes without blocking; enforce mode rejects missing or invalid verification. It complements our WAF and DDoS protection while your application still owns identity, authorization, and domain claims."
          }
        }
      ]
    },
    {
      "@type": "BlogPosting",
      "@id": "https://approximated.app/blog/custom-domain-onboarding-checklist/#article",
      "url": "https://approximated.app/blog/custom-domain-onboarding-checklist/",
      "headline": "A custom domain onboarding checklist customers can follow",
      "description": "Design a custom-domain setup flow around five checks: tenant claim, edge configuration, DNS, certificate, and a real application request.",
      "abstract": "make custom-domain onboarding a sequence of five evidence checks: the right tenant claimed the hostname, the edge configuration exists, DNS points where expected, HTTPS is ready, and a real request reaches the right application. These are application UI states, not names of a particular provider's API statuses. Keeping them separate gives customers a useful next action instead of a generic “pending” badge. We built our DNS onboarding, monitoring, and webhooks to help you ship that clarity inside your own product.",
      "datePublished": "2026-09-04",
      "dateModified": "2026-09-28",
      "inLanguage": "en",
      "articleSection": "Product design",
      "author": {
        "@type": "Organization",
        "@id": "https://approximated.app/#organization",
        "name": "Approximated",
        "url": "https://approximated.app/"
      },
      "publisher": {
        "@type": "Organization",
        "@id": "https://approximated.app/#organization",
        "name": "Approximated",
        "url": "https://approximated.app/"
      },
      "mainEntityOfPage": {
        "@type": "WebPage",
        "@id": "https://approximated.app/blog/custom-domain-onboarding-checklist/"
      },
      "isPartOf": {
        "@id": "https://approximated.app/blog/#blog"
      },
      "isAccessibleForFree": true,
      "wordCount": 1145,
      "keywords": [
        "Custom domain onboarding",
        "DNS verification",
        "TLS readiness",
        "Domain monitoring"
      ],
      "about": [
        {
          "@type": "DefinedTerm",
          "name": "Custom domain onboarding"
        },
        {
          "@type": "DefinedTerm",
          "name": "DNS verification"
        },
        {
          "@type": "DefinedTerm",
          "name": "TLS readiness"
        },
        {
          "@type": "DefinedTerm",
          "name": "Domain monitoring"
        }
      ],
      "citation": [
        "https://approximated.app/docs/#virtual-hosts-api",
        "https://approximated.app/blog/apex-domains-for-saas/",
        "https://approximated.app/dns-widget/",
        "https://approximated.app/docs/#dns-widget-headless",
        "https://approximated.app/docs/#webhook-events-virtual-host-monitor-updated",
        "https://approximated.app/docs/#webhook-events-virtual-host-created",
        "https://approximated.app/#waf",
        "https://approximated.app/docs/#edge-verify",
        "https://approximated.app/blog/custom-domain-security/",
        "https://approximated.app/blog/custom-domains-for-saas-guide/",
        "https://approximated.app/docs/",
        "https://approximated.app/#faq",
        "https://approximated.app/pricing/",
        "https://approximated.app/self-hosted/"
      ],
      "hasPart": [
        {
          "@id": "https://approximated.app/blog/custom-domain-onboarding-checklist/#faq"
        }
      ],
      "encoding": {
        "@type": "MediaObject",
        "encodingFormat": "text/markdown",
        "contentUrl": "https://approximated.app/blog/custom-domain-onboarding-checklist/index.md"
      }
    },
    {
      "@type": "FAQPage",
      "@id": "https://approximated.app/blog/custom-domain-onboarding-checklist/#faq",
      "url": "https://approximated.app/blog/custom-domain-onboarding-checklist/#faq",
      "name": "A custom domain onboarding checklist customers can follow: frequently asked questions",
      "inLanguage": "en",
      "isPartOf": {
        "@id": "https://approximated.app/blog/custom-domain-onboarding-checklist/#article"
      },
      "mainEntity": [
        {
          "@type": "Question",
          "@id": "https://approximated.app/blog/custom-domain-onboarding-checklist/#faq-connected-state",
          "url": "https://approximated.app/blog/custom-domain-onboarding-checklist/#faq-connected-state",
          "name": "When should my SaaS show that a custom domain is connected?",
          "acceptedAnswer": {
            "@type": "Answer",
            "@id": "https://approximated.app/blog/custom-domain-onboarding-checklist/#faq-connected-state-answer",
            "text": "Show connected only after the authorized tenant claim is recorded, the edge is configured, DNS points correctly, a valid certificate is active, and a real HTTPS request reaches the intended tenant. Keep saved, DNS, and certificate progress separate. Our monitoring and webhooks provide edge observations, while your application verifies the final customer experience."
          }
        },
        {
          "@type": "Question",
          "@id": "https://approximated.app/blog/custom-domain-onboarding-checklist/#faq-dns-time",
          "url": "https://approximated.app/blog/custom-domain-onboarding-checklist/#faq-dns-time",
          "name": "How long does a customer DNS change take to become visible?",
          "acceptedAnswer": {
            "@type": "Answer",
            "@id": "https://approximated.app/blog/custom-domain-onboarding-checklist/#faq-dns-time-answer",
            "text": "There is no single reliable time for every DNS change. The provider must publish the record, and recursive resolvers can retain the previous answer until its cache expires. Check the authoritative answer and public resolvers, show the record actually observed, and offer a check-again action. Treat certificate readiness as a separate step after DNS rather than promising an immediate connection."
          }
        },
        {
          "@type": "Question",
          "@id": "https://approximated.app/blog/custom-domain-onboarding-checklist/#faq-in-product-dns",
          "url": "https://approximated.app/blog/custom-domain-onboarding-checklist/#faq-in-product-dns",
          "name": "Can customers follow DNS setup inside my SaaS product?",
          "acceptedAnswer": {
            "@type": "Answer",
            "@id": "https://approximated.app/blog/custom-domain-onboarding-checklist/#faq-in-product-dns-answer",
            "text": "Yes. Our DNS widget presents provider-specific instructions and verifies requested records inside your product. Headless mode lets your own UI use those instructions and checks. The customer still makes the required change at their DNS provider; your application controls who may claim the hostname and confirms the final HTTPS route to the tenant."
          }
        },
        {
          "@type": "Question",
          "@id": "https://approximated.app/blog/custom-domain-onboarding-checklist/#faq-polling-webhooks",
          "url": "https://approximated.app/blog/custom-domain-onboarding-checklist/#faq-polling-webhooks",
          "name": "Should I use polling or webhooks for custom domain status?",
          "acceptedAnswer": {
            "@type": "Answer",
            "@id": "https://approximated.app/blog/custom-domain-onboarding-checklist/#faq-polling-webhooks-answer",
            "text": "Webhooks let your application react to domain observations, while API reads let it reconcile the current state. We provide creation and monitor-update events with distinct meanings: creation doesn't mean HTTPS is ready. Authenticate deliveries, process repeats idempotently, and reconcile current API status so retries or delayed events don't move the onboarding UI backward."
          }
        },
        {
          "@type": "Question",
          "@id": "https://approximated.app/blog/custom-domain-onboarding-checklist/#faq-dns-before-ssl",
          "url": "https://approximated.app/blog/custom-domain-onboarding-checklist/#faq-dns-before-ssl",
          "name": "Why can DNS be verified while a custom domain SSL certificate is still pending?",
          "acceptedAnswer": {
            "@type": "Answer",
            "@id": "https://approximated.app/blog/custom-domain-onboarding-checklist/#faq-dns-before-ssl-answer",
            "text": "DNS and certificate issuance are different checks. The record may point correctly while domain validation, certificate issuance, or the actual HTTPS route is still pending. Show that DNS is correct and that the domain is being secured, then confirm a valid certificate and tenant response. A proxy in front of the edge can also change the validation path, so test the public route."
          }
        }
      ]
    },
    {
      "@type": "BlogPosting",
      "@id": "https://approximated.app/blog/apex-domains-for-saas/#article",
      "url": "https://approximated.app/blog/apex-domains-for-saas/",
      "headline": "Apex domains for SaaS: DNS choices and SSL",
      "description": "Support customer root domains with A records, ALIAS or CNAME flattening, or redirects. Learn the DNS and HTTPS checks each choice needs.",
      "abstract": "a customer can point www.example.com at your SaaS with a normal CNAME, but the root example.com needs another path. Offer an A record to an address your proxy controls, a DNS provider's ALIAS or CNAME-flattening feature, or a redirect from the root to www. The right instruction depends on the customer's DNS provider and on how your edge provisions HTTPS.",
      "datePublished": "2026-08-13",
      "dateModified": "2026-09-28",
      "inLanguage": "en",
      "articleSection": "DNS",
      "author": {
        "@type": "Organization",
        "@id": "https://approximated.app/#organization",
        "name": "Approximated",
        "url": "https://approximated.app/"
      },
      "publisher": {
        "@type": "Organization",
        "@id": "https://approximated.app/#organization",
        "name": "Approximated",
        "url": "https://approximated.app/"
      },
      "mainEntityOfPage": {
        "@type": "WebPage",
        "@id": "https://approximated.app/blog/apex-domains-for-saas/"
      },
      "isPartOf": {
        "@id": "https://approximated.app/blog/#blog"
      },
      "isAccessibleForFree": true,
      "wordCount": 1029,
      "keywords": [
        "Apex domains",
        "DNS records",
        "CNAME flattening",
        "HTTPS redirects"
      ],
      "about": [
        {
          "@type": "DefinedTerm",
          "name": "Apex domains"
        },
        {
          "@type": "DefinedTerm",
          "name": "DNS records"
        },
        {
          "@type": "DefinedTerm",
          "name": "CNAME flattening"
        },
        {
          "@type": "DefinedTerm",
          "name": "HTTPS redirects"
        }
      ],
      "citation": [
        "https://www.rfc-editor.org/rfc/rfc1034",
        "https://developers.cloudflare.com/dns/cname-flattening/set-up-cname-flattening/",
        "https://docs.aws.amazon.com/Route53/latest/DeveloperGuide/resource-record-sets-choosing-alias-non-alias.html",
        "https://approximated.app/docs/#what-is-a-proxy-cluster",
        "https://approximated.app/approximated-cloudflare-comparison/",
        "https://letsencrypt.org/docs/challenge-types/",
        "https://approximated.app/docs/#virtual-host-statuses",
        "https://approximated.app/docs/#webhooks",
        "https://approximated.app/dns-widget/",
        "https://approximated.app/blog/custom-domain-onboarding-checklist/",
        "https://approximated.app/#waf",
        "https://approximated.app/docs/#edge-verify",
        "https://approximated.app/#faq",
        "https://approximated.app/pricing/",
        "https://approximated.app/self-hosted/"
      ],
      "hasPart": [
        {
          "@id": "https://approximated.app/blog/apex-domains-for-saas/#faq"
        }
      ],
      "encoding": {
        "@type": "MediaObject",
        "encodingFormat": "text/markdown",
        "contentUrl": "https://approximated.app/blog/apex-domains-for-saas/index.md"
      }
    },
    {
      "@type": "FAQPage",
      "@id": "https://approximated.app/blog/apex-domains-for-saas/#faq",
      "url": "https://approximated.app/blog/apex-domains-for-saas/#faq",
      "name": "Apex domains for SaaS: DNS choices and SSL: frequently asked questions",
      "inLanguage": "en",
      "isPartOf": {
        "@id": "https://approximated.app/blog/apex-domains-for-saas/#article"
      },
      "mainEntity": [
        {
          "@type": "Question",
          "@id": "https://approximated.app/blog/apex-domains-for-saas/#faq-cname-restriction",
          "url": "https://approximated.app/blog/apex-domains-for-saas/#faq-cname-restriction",
          "name": "Why can't a standard CNAME record be used at the domain apex?",
          "acceptedAnswer": {
            "@type": "Answer",
            "@id": "https://approximated.app/blog/apex-domains-for-saas/#faq-cname-restriction-answer",
            "text": "A standard CNAME can't coexist with other records at the same DNS name. A zone apex already needs records such as SOA and NS, so a plain apex CNAME conflicts with the DNS model. Provider features called ALIAS, ANAME, or CNAME flattening work around that constraint through provider-specific behavior. Their availability and target restrictions vary."
          }
        },
        {
          "@type": "Question",
          "@id": "https://approximated.app/blog/apex-domains-for-saas/#faq-record-type",
          "url": "https://approximated.app/blog/apex-domains-for-saas/#faq-record-type",
          "name": "Which DNS record should a SaaS customer use for a root domain?",
          "acceptedAnswer": {
            "@type": "Answer",
            "@id": "https://approximated.app/blog/apex-domains-for-saas/#faq-record-type-answer",
            "text": "Use an A record when your edge provides a stable IPv4 address, or a DNS-provider alias or flattening feature when that provider supports your target. We give each proxy cluster a dedicated IPv4 address that serves its configured customer domains, making an apex A record a straightforward option without requiring customers to change DNS providers."
          }
        },
        {
          "@type": "Question",
          "@id": "https://approximated.app/blog/apex-domains-for-saas/#faq-redirect-certificate",
          "url": "https://approximated.app/blog/apex-domains-for-saas/#faq-redirect-certificate",
          "name": "Does redirecting an apex domain to www require an SSL certificate?",
          "acceptedAnswer": {
            "@type": "Answer",
            "@id": "https://approximated.app/blog/apex-domains-for-saas/#faq-redirect-certificate-answer",
            "text": "Yes, for an HTTPS redirect. A browser establishes TLS with the apex hostname before it can read the HTTP redirect to www or another hostname. The apex therefore needs a valid certificate even if it only redirects. Verify the certificate and the redirect separately, using the exact public hostname the customer will visit."
          }
        },
        {
          "@type": "Question",
          "@id": "https://approximated.app/blog/apex-domains-for-saas/#faq-shared-address",
          "url": "https://approximated.app/blog/apex-domains-for-saas/#faq-shared-address",
          "name": "Does every customer apex domain need its own IP address?",
          "acceptedAnswer": {
            "@type": "Answer",
            "@id": "https://approximated.app/blog/apex-domains-for-saas/#faq-shared-address-answer",
            "text": "No. A proxy can serve many configured hostnames on one address and select the appropriate certificate and route for each request. We provide a dedicated IPv4 address per proxy cluster, rather than one IP per customer hostname. Your application must still map each hostname to the correct tenant and enforce that tenant's authorization."
          }
        },
        {
          "@type": "Question",
          "@id": "https://approximated.app/blog/apex-domains-for-saas/#faq-ongoing-checks",
          "url": "https://approximated.app/blog/apex-domains-for-saas/#faq-ongoing-checks",
          "name": "What should I monitor after a customer apex domain connects?",
          "acceptedAnswer": {
            "@type": "Answer",
            "@id": "https://approximated.app/blog/apex-domains-for-saas/#faq-ongoing-checks-answer",
            "text": "Monitor DNS answers, certificate validity, and the real HTTPS response for the intended tenant. A customer can later change DNS or place another proxy in front of the route, so setup success isn't permanent proof. Our DNS, SSL, and proxy-hit monitoring and webhooks keep edge changes visible; application request checks confirm that the origin still serves the right content."
          }
        }
      ]
    },
    {
      "@type": "BlogPosting",
      "@id": "https://approximated.app/blog/best-custom-domain-apis-for-saas/#article",
      "url": "https://approximated.app/blog/best-custom-domain-apis-for-saas/",
      "headline": "How to choose the best custom domain API for your SaaS",
      "description": "Compare Approximated, Cloudflare for SaaS, and Entri Power on TLS, apex DNS, WAF, DDoS protection, monitoring, support, self-hosting, and pricing.",
      "abstract": "choose a custom-domain API by how well it runs the feature in production: DNS and TLS, safe tenant routing, protection against abusive traffic, useful monitoring, and help when something goes wrong. We built Approximated for SaaS teams that want those capabilities together, with a dedicated cluster, straightforward apex support, public pricing with automatic volume discounts, and a self-hosting path as your app grows.",
      "datePublished": "2026-07-24",
      "dateModified": "2026-09-28",
      "inLanguage": "en",
      "articleSection": "Comparison",
      "author": {
        "@type": "Organization",
        "@id": "https://approximated.app/#organization",
        "name": "Approximated",
        "url": "https://approximated.app/"
      },
      "publisher": {
        "@type": "Organization",
        "@id": "https://approximated.app/#organization",
        "name": "Approximated",
        "url": "https://approximated.app/"
      },
      "mainEntityOfPage": {
        "@type": "WebPage",
        "@id": "https://approximated.app/blog/best-custom-domain-apis-for-saas/"
      },
      "isPartOf": {
        "@id": "https://approximated.app/blog/#blog"
      },
      "isAccessibleForFree": true,
      "wordCount": 1873,
      "keywords": [
        "Custom domain APIs",
        "SaaS infrastructure",
        "API pricing",
        "Self-hosted proxy infrastructure"
      ],
      "about": [
        {
          "@type": "DefinedTerm",
          "name": "Custom domain APIs"
        },
        {
          "@type": "DefinedTerm",
          "name": "SaaS infrastructure"
        },
        {
          "@type": "DefinedTerm",
          "name": "API pricing"
        },
        {
          "@type": "DefinedTerm",
          "name": "Self-hosted proxy infrastructure"
        }
      ],
      "citation": [
        "https://approximated.app/blog/custom-domains-for-saas-guide/",
        "https://developers.entri.com/power/overview",
        "https://approximated.app/#waf",
        "https://approximated.app/docs/#edge-verify",
        "https://approximated.app/docs/#virtual-host-statuses",
        "https://approximated.app/docs/#webhooks",
        "https://approximated.app/self-hosted/",
        "https://approximated.app/#faq",
        "https://approximated.app/pricing/",
        "https://developers.cloudflare.com/cloudflare-for-platforms/cloudflare-for-saas/plans/",
        "https://developers.cloudflare.com/cloudflare-for-platforms/cloudflare-for-saas/start/advanced-settings/apex-proxying/",
        "https://www.reddit.com/r/CloudFlare/comments/1ey3jiu/price_of_entreprise_plan/",
        "https://www.entri.com/plans",
        "https://customdomain.ai/compare/entri",
        "https://approximated.app/#pricing",
        "https://developers.cloudflare.com/cloudflare-for-platforms/cloudflare-for-saas/start/getting-started/",
        "https://developers.entri.com/power/configuration"
      ],
      "hasPart": [
        {
          "@id": "https://approximated.app/blog/best-custom-domain-apis-for-saas/#faq"
        }
      ],
      "encoding": {
        "@type": "MediaObject",
        "encodingFormat": "text/markdown",
        "contentUrl": "https://approximated.app/blog/best-custom-domain-apis-for-saas/index.md"
      }
    },
    {
      "@type": "FAQPage",
      "@id": "https://approximated.app/blog/best-custom-domain-apis-for-saas/#faq",
      "url": "https://approximated.app/blog/best-custom-domain-apis-for-saas/#faq",
      "name": "How to choose the best custom domain API for your SaaS: frequently asked questions",
      "inLanguage": "en",
      "isPartOf": {
        "@id": "https://approximated.app/blog/best-custom-domain-apis-for-saas/#article"
      },
      "mainEntity": [
        {
          "@type": "Question",
          "@id": "https://approximated.app/blog/best-custom-domain-apis-for-saas/#faq-criteria",
          "url": "https://approximated.app/blog/best-custom-domain-apis-for-saas/#faq-criteria",
          "name": "What should I compare in custom domain APIs for SaaS?",
          "acceptedAnswer": {
            "@type": "Answer",
            "@id": "https://approximated.app/blog/best-custom-domain-apis-for-saas/#faq-criteria-answer",
            "text": "Compare Approximated, Cloudflare for SaaS, and Entri Power across the complete domain lifecycle: apex and subdomain DNS, automated HTTPS, origin routing, onboarding, removal, and ongoing monitoring. Include WAF and DDoS protection, form verification, webhooks, engineering support, deployment options, and the full domain-and-bandwidth bill. We built Approximated to bring these production capabilities together in dedicated proxy infrastructure for SaaS teams."
          }
        },
        {
          "@type": "Question",
          "@id": "https://approximated.app/blog/best-custom-domain-apis-for-saas/#faq-approximated-fit",
          "url": "https://approximated.app/blog/best-custom-domain-apis-for-saas/#faq-approximated-fit",
          "name": "When is Approximated a good custom domain API choice?",
          "acceptedAnswer": {
            "@type": "Answer",
            "@id": "https://approximated.app/blog/best-custom-domain-apis-for-saas/#faq-approximated-fit-answer",
            "text": "We're a strong fit when customer domains are a production feature your SaaS depends on. Our cloud combines dedicated clusters, automatic HTTPS, straightforward apex A records, WAF and DDoS protection, Edge Verify, domain monitoring, webhooks, and DNS onboarding. Real engineers can help with integration and incidents, and our published cloud and self-hosted plans let you evaluate costs and deployment scope up front."
          }
        },
        {
          "@type": "Question",
          "@id": "https://approximated.app/blog/best-custom-domain-apis-for-saas/#faq-apex-providers",
          "url": "https://approximated.app/blog/best-custom-domain-apis-for-saas/#faq-apex-providers",
          "name": "Which custom domain providers support apex domains?",
          "acceptedAnswer": {
            "@type": "Answer",
            "@id": "https://approximated.app/blog/best-custom-domain-apis-for-saas/#faq-apex-providers-answer",
            "text": "Our cloud supports apex A records through a dedicated anycast IPv4 address for each customer cluster; its configured tenant hostnames share that address. Entri Power documents a root-domain hosting workflow. Cloudflare's IP-based Apex Proxying requires an Enterprise plan plus a paid add-on; other apex routes can depend on the customer's DNS provider. Test the actual DNS instructions and plan requirements alongside the provider's production tools."
          }
        },
        {
          "@type": "Question",
          "@id": "https://approximated.app/blog/best-custom-domain-apis-for-saas/#faq-cloud-cost",
          "url": "https://approximated.app/blog/best-custom-domain-apis-for-saas/#faq-cloud-cost",
          "name": "How much does Approximated Cloud cost for customer domains?",
          "acceptedAnswer": {
            "@type": "Answer",
            "@id": "https://approximated.app/blog/best-custom-domain-apis-for-saas/#faq-cloud-cost-answer",
            "text": "Our published cloud rate is $0.20 per domain per month with a $20 monthly minimum. It includes 400 GB of bandwidth, with additional bandwidth at $0.05 per GB. Domain volume discounts apply automatically: five percentage points for each full 1,000 domains, up to 50%. At 10,000 domains, the domain charge is $0.10 per domain per month, before any bandwidth overage. Self-hosted plans have their own published prices and scope, and custom SLA terms are agreed separately. Use expected domains and traffic to calculate the complete bill."
          }
        },
        {
          "@type": "Question",
          "@id": "https://approximated.app/blog/best-custom-domain-apis-for-saas/#faq-self-hosting",
          "url": "https://approximated.app/blog/best-custom-domain-apis-for-saas/#faq-self-hosting",
          "name": "Can I self-host custom domains as my SaaS grows?",
          "acceptedAnswer": {
            "@type": "Answer",
            "@id": "https://approximated.app/blog/best-custom-domain-apis-for-saas/#faq-self-hosting-answer",
            "text": "Yes. You can start with Approximated Cloud, then move toward hybrid or full self-hosting as traffic and infrastructure requirements grow. Hybrid keeps our cloud API and dashboard while traffic and certificates run on your servers. Full self-hosting provides a separate installation with a local API and dashboard, with a different feature scope. Cloudflare for SaaS and Entri Power document managed proxy services without an equivalent published self-hosted platform. Our engineers can help plan deployment and any customer DNS migration."
          }
        }
      ]
    },
    {
      "@type": "BlogPosting",
      "@id": "https://approximated.app/blog/custom-domains-for-saas-guide/#article",
      "url": "https://approximated.app/blog/custom-domains-for-saas-guide/",
      "headline": "Custom domains for SaaS: a production guide",
      "description": "A production guide to SaaS custom domains: DNS, TLS, tenant routing, WAF and DDoS protection, monitoring, webhooks, and self-hosting.",
      "abstract": "a SaaS custom-domain feature is a lifecycle, not a DNS field. You need to decide which customer may claim a hostname, give them the right DNS record, prepare HTTPS, route the request to the correct tenant, and keep checking the connection after launch. A domain is ready only when the application answers on that hostname over valid HTTPS. We built Approximated to make this production path easier to ship and operate, from your first customer domain to a large SaaS fleet.",
      "datePublished": "2026-06-30",
      "dateModified": "2026-09-28",
      "inLanguage": "en",
      "articleSection": "Guide",
      "author": {
        "@type": "Organization",
        "@id": "https://approximated.app/#organization",
        "name": "Approximated",
        "url": "https://approximated.app/"
      },
      "publisher": {
        "@type": "Organization",
        "@id": "https://approximated.app/#organization",
        "name": "Approximated",
        "url": "https://approximated.app/"
      },
      "mainEntityOfPage": {
        "@type": "WebPage",
        "@id": "https://approximated.app/blog/custom-domains-for-saas-guide/"
      },
      "isPartOf": {
        "@id": "https://approximated.app/blog/#blog"
      },
      "isAccessibleForFree": true,
      "wordCount": 1457,
      "keywords": [
        "Custom domains for SaaS",
        "TLS certificates",
        "Tenant routing",
        "DNS onboarding"
      ],
      "about": [
        {
          "@type": "DefinedTerm",
          "name": "Custom domains for SaaS"
        },
        {
          "@type": "DefinedTerm",
          "name": "TLS certificates"
        },
        {
          "@type": "DefinedTerm",
          "name": "Tenant routing"
        },
        {
          "@type": "DefinedTerm",
          "name": "DNS onboarding"
        }
      ],
      "citation": [
        "https://approximated.app/docs/#virtual-host-statuses",
        "https://www.rfc-editor.org/rfc/rfc1034",
        "https://approximated.app/dns-widget/",
        "https://letsencrypt.org/docs/challenge-types/",
        "https://letsencrypt.org/docs/rate-limits/",
        "https://approximated.app/guides/",
        "https://approximated.app/self-hosted/",
        "https://approximated.app/#waf",
        "https://approximated.app/docs/#edge-verify",
        "https://approximated.app/docs/#webhooks",
        "https://approximated.app/#faq",
        "https://approximated.app/pricing/",
        "https://developers.cloudflare.com/cloudflare-for-platforms/cloudflare-for-saas/start/getting-started/",
        "https://approximated.app/blog/best-custom-domain-apis-for-saas/",
        "https://approximated.app/blog/custom-domain-onboarding-checklist/",
        "https://approximated.app/blog/custom-domain-security/"
      ],
      "hasPart": [
        {
          "@id": "https://approximated.app/blog/custom-domains-for-saas-guide/#faq"
        }
      ],
      "encoding": {
        "@type": "MediaObject",
        "encodingFormat": "text/markdown",
        "contentUrl": "https://approximated.app/blog/custom-domains-for-saas-guide/index.md"
      }
    },
    {
      "@type": "FAQPage",
      "@id": "https://approximated.app/blog/custom-domains-for-saas-guide/#faq",
      "url": "https://approximated.app/blog/custom-domains-for-saas-guide/#faq",
      "name": "Custom domains for SaaS: a production guide: frequently asked questions",
      "inLanguage": "en",
      "isPartOf": {
        "@id": "https://approximated.app/blog/custom-domains-for-saas-guide/#article"
      },
      "mainEntity": [
        {
          "@type": "Question",
          "@id": "https://approximated.app/blog/custom-domains-for-saas-guide/#faq-definition",
          "url": "https://approximated.app/blog/custom-domains-for-saas-guide/#faq-definition",
          "name": "What is a custom domain for a SaaS application?",
          "acceptedAnswer": {
            "@type": "Answer",
            "@id": "https://approximated.app/blog/custom-domains-for-saas-guide/#faq-definition-answer",
            "text": "A custom domain lets a customer use a hostname they own, such as app.customer.example, to access their workspace in your SaaS. DNS sends traffic to your edge, HTTPS secures the connection, and your application maps the hostname to the correct tenant. We handle the custom-domain proxy infrastructure while your app keeps control of tenant identity and authorization."
          }
        },
        {
          "@type": "Question",
          "@id": "https://approximated.app/blog/custom-domains-for-saas-guide/#faq-setup",
          "url": "https://approximated.app/blog/custom-domains-for-saas-guide/#faq-setup",
          "name": "How do I add custom domains to a multi-tenant SaaS?",
          "acceptedAnswer": {
            "@type": "Answer",
            "@id": "https://approximated.app/blog/custom-domains-for-saas-guide/#faq-setup-answer",
            "text": "Record the hostname against one authorized tenant, create its edge mapping, and show the customer the exact DNS record to publish. Check DNS and certificate readiness separately, then make a real HTTPS request that confirms the expected tenant answers. Our API, DNS onboarding, monitoring, and webhooks cover the edge workflow; your application owns the tenant association."
          }
        },
        {
          "@type": "Question",
          "@id": "https://approximated.app/blog/custom-domains-for-saas-guide/#faq-root-subdomain",
          "url": "https://approximated.app/blog/custom-domains-for-saas-guide/#faq-root-subdomain",
          "name": "Can SaaS customers connect both root domains and subdomains?",
          "acceptedAnswer": {
            "@type": "Answer",
            "@id": "https://approximated.app/blog/custom-domains-for-saas-guide/#faq-root-subdomain-answer",
            "text": "Yes, if your edge supports both hostname types. Subdomains usually use a CNAME. Root or apex domains need an A record, a supported DNS-provider alias or flattening feature, or a redirect to a subdomain. Our cloud provides a dedicated anycast IPv4 address per customer proxy cluster, shared by the tenant hostnames configured in that cluster. Your customers can connect apex domains with an A record at their existing DNS provider."
          }
        },
        {
          "@type": "Question",
          "@id": "https://approximated.app/blog/custom-domains-for-saas-guide/#faq-readiness",
          "url": "https://approximated.app/blog/custom-domains-for-saas-guide/#faq-readiness",
          "name": "Does managed SSL mean a custom domain is ready to use?",
          "acceptedAnswer": {
            "@type": "Answer",
            "@id": "https://approximated.app/blog/custom-domains-for-saas-guide/#faq-readiness-answer",
            "text": "A certificate is only one readiness check. The hostname must also resolve to the intended edge, reach a working origin, and render the correct tenant over HTTPS. We expose DNS, SSL, and proxy-hit observations separately. Use those signals for the onboarding UI and complete the check with an actual application request before marking the domain connected."
          }
        },
        {
          "@type": "Question",
          "@id": "https://approximated.app/blog/custom-domains-for-saas-guide/#faq-self-hosting",
          "url": "https://approximated.app/blog/custom-domains-for-saas-guide/#faq-self-hosting",
          "name": "Can I start with managed custom domains and later self-host?",
          "acceptedAnswer": {
            "@type": "Answer",
            "@id": "https://approximated.app/blog/custom-domains-for-saas-guide/#faq-self-hosting-answer",
            "text": "We offer cloud, hybrid, and full self-hosted deployment paths. Hybrid keeps our cloud API and dashboard while traffic and certificates run on your infrastructure. Full self-hosting provides a separate installation with a local API and dashboard, and its feature scope differs. Plan the deployment, address changes, and any customer DNS migration with our engineers before moving traffic."
          }
        }
      ]
    }
  ]
}
