Connect a site via DNS
Put Botscope in front of your server by changing two DNS records. Nothing to install, no code to touch.
Before you start
Visitors reach our edge first; clean traffic is forwarded to your server. You'll need:
- Access to the domain's DNS — at your registrar, your host, or Cloudflare.
- Your server's IP address (shown in your hosting control panel).
Domain proxied by Cloudflare? If you want to keep the orange cloud, choose the Cloudflare Worker method under Sites → Connect instead — DNS mode needs the record to point straight at our edge.
1. Add the site and confirm the origin IP
In Sites → Add site pick DNS and enter the bare domain. We read the current A record and use it as the origin — where clean traffic will be sent.
| You see | Why | Fix |
|---|---|---|
| “Enter a hostname like example.com — no scheme, port or path.” | The domain includes https://, a port or a path. | Enter just example.com. |
| “No A record answers for …” | The domain has no A record yet, or uses a CNAME. | Type the server IP from your hosting panel. |
| “That address is ours” | The domain already points at Botscope, so DNS can't tell us the origin. | Type your real server IP. |
| “The origin IP is set to our own edge server…” | The origin field holds our IP — traffic would loop. | Replace it with your server IP. |
2. Change the DNS records
Create or edit two A records. The exact edge IP is on your site's Connect page, along with where to find these settings at Cloudflare, GoDaddy, Namecheap, Route 53, DigitalOcean and OVH.
| Type | Name | Value | TTL |
|---|---|---|---|
| A | @ | Edge IP from the Connect page | 300 |
| A | www | Edge IP from the Connect page | 300 |
Common problems
- Old A record left in place. Two A records for @ means part of your traffic goes straight to the server and verification can fail. Edit the existing record instead of adding a second one.
- Cloudflare orange cloud. Set the record to DNS only (grey cloud); otherwise Cloudflare's IP answers instead of ours.
- AAAA (IPv6) records. An AAAA record on @ or www lets IPv6 visitors bypass protection — delete it.
- www is a CNAME to another service. Replace it with the A record above, or a CNAME to your apex domain.
- CAA records. If the domain has any, they must allow Let's Encrypt (0 issue "letsencrypt.org") or we can't issue the SSL certificate.
3. Wait for propagation
Usually minutes; at most the old record's TTL, which is sometimes several hours. To check from your computer:
dig +short example.com A
dig +short www.example.com ABoth should return only the edge IP. Online tools such as dnschecker.org show what resolvers around the world see.
4. Verify
Click Verify connection. We check the A record, register the domain on the edge, issue an SSL certificate automatically, and load your homepage through the edge.
| Message | Meaning | Fix |
|---|---|---|
| “DNS (…) still points to X. Expected Y.” | The record hasn't changed yet, or an old record answered first. | Re-check step 2, wait for propagation, verify again. |
| “Site connected successfully. www still points to …” | The apex is protected; www is not. | Update the www record. |
| “Edge proxy health check failed.” | Your homepage didn't load through the edge. | Check the origin IP is right, the server answers HTTPS for this domain and doesn't block unknown IPs. Retry in a minute — the first certificate can take a moment. |
| “Could not register the site on the edge proxy.” | A temporary problem on our side. | Retry; contact support if it persists. |
Once the site shows Connected, config syncs every 5 minutes and traffic appears in the dashboard.
Rolling back
Point the A records back to your server's IP. There is nothing on the server to undo.
Still stuck?
Send us the domain and the exact message you see — we'll look at it with you.