Skip to main content
← Documentation

Connect a site via DNS

Put Botscope in front of your server by changing two DNS records. Nothing to install, no code to touch.

Before you start

Visitors reach our edge first; clean traffic is forwarded to your server. You'll need:

  • Access to the domain's DNS — at your registrar, your host, or Cloudflare.
  • Your server's IP address (shown in your hosting control panel).

Domain proxied by Cloudflare? If you want to keep the orange cloud, choose the Cloudflare Worker method under Sites → Connect instead — DNS mode needs the record to point straight at our edge.

1. Add the site and confirm the origin IP

In Sites → Add site pick DNS and enter the bare domain. We read the current A record and use it as the origin — where clean traffic will be sent.

You seeWhyFix
“Enter a hostname like example.com — no scheme, port or path.”The domain includes https://, a port or a path.Enter just example.com.
“No A record answers for …”The domain has no A record yet, or uses a CNAME.Type the server IP from your hosting panel.
“That address is ours”The domain already points at Botscope, so DNS can't tell us the origin.Type your real server IP.
“The origin IP is set to our own edge server…”The origin field holds our IP — traffic would loop.Replace it with your server IP.

2. Change the DNS records

Create or edit two A records. The exact edge IP is on your site's Connect page, along with where to find these settings at Cloudflare, GoDaddy, Namecheap, Route 53, DigitalOcean and OVH.

TypeNameValueTTL
A@Edge IP from the Connect page300
AwwwEdge IP from the Connect page300

Common problems

  • Old A record left in place. Two A records for @ means part of your traffic goes straight to the server and verification can fail. Edit the existing record instead of adding a second one.
  • Cloudflare orange cloud. Set the record to DNS only (grey cloud); otherwise Cloudflare's IP answers instead of ours.
  • AAAA (IPv6) records. An AAAA record on @ or www lets IPv6 visitors bypass protection — delete it.
  • www is a CNAME to another service. Replace it with the A record above, or a CNAME to your apex domain.
  • CAA records. If the domain has any, they must allow Let's Encrypt (0 issue "letsencrypt.org") or we can't issue the SSL certificate.

3. Wait for propagation

Usually minutes; at most the old record's TTL, which is sometimes several hours. To check from your computer:

shell
dig +short example.com A
dig +short www.example.com A

Both should return only the edge IP. Online tools such as dnschecker.org show what resolvers around the world see.

4. Verify

Click Verify connection. We check the A record, register the domain on the edge, issue an SSL certificate automatically, and load your homepage through the edge.

MessageMeaningFix
“DNS (…) still points to X. Expected Y.”The record hasn't changed yet, or an old record answered first.Re-check step 2, wait for propagation, verify again.
“Site connected successfully. www still points to …”The apex is protected; www is not.Update the www record.
“Edge proxy health check failed.”Your homepage didn't load through the edge.Check the origin IP is right, the server answers HTTPS for this domain and doesn't block unknown IPs. Retry in a minute — the first certificate can take a moment.
“Could not register the site on the edge proxy.”A temporary problem on our side.Retry; contact support if it persists.

Once the site shows Connected, config syncs every 5 minutes and traffic appears in the dashboard.

Rolling back

Point the A records back to your server's IP. There is nothing on the server to undo.

Still stuck?

Send us the domain and the exact message you see — we'll look at it with you.

Contact support