4 ms·
> However http://example.com http://example.com cannot use CNAME because it is an apex record [snip]. And this caused many websites to occupy an IP address unne
by PinguTS 2y ago
> However http://example.com http://example.com cannot use CNAME because it is an apex record [snip]. And this caused many websites to occupy an IP address unnecessarily.
That's not true. I have an server with a single IP and a number of Domains that are served from that single IP like http(s)://example.com http(s)://example.org http(s)://example.de
All of those delivery completely different websites from that single domain. You are mixing up two tings: DNS with HTTP(s). In DNS its right but for HTTP(s) it doesn't matter.
- billyjobob 2y agoOf course you can have multiple apex A records that point to the same IP address. We are talking about CNAME records here. Are your sites using CNAME records or A records? Even if you are using CNAMEs, that's only been possible recently due to hacks/workarounds, as bonzini said.
- linsomniac 2y agoI'm imagining, but someone please correct me if I'm wrong, that this is related to the policy/standard/convention (?) that IPs have a single canonical name, so reverse and forward match. I've never really followed that strictly, though I've been aware of it and try to follow it as I can, because it makes management of DNS a little more sane. Because of no SRV records for HTTP and no CNAME for apex records, you can't follow "one true name per IP" without giving an IP to every domain.
- PinguTS 2y agoActually reverse and forward match is important for SMTP these days. It is one piece in the puzzle to detect spam. I run may own email server now for more than 20 years. Only recently I in-cooperated public RBLs to deny spam. I still don't like it to depend on external services for this, which flag spam incorrectly.
- linsomniac 2y agoI had excluded SMTP in my thinking because SMTP has the MX records, so it doesn't run into the issue with apex records not allowing CNAMEs. If I'm mailing you at pinguts@example.com, it does not require a dedicated IP for example.com, your MX record can inform my server that SMTP needs to connect to smtp.example.net, and that needs to have matching forward/reverse, but I can have a hundred domains that all specify smtp.example.net without interfering with the apex-can't-have-CNAME rule. I think this is what people elsewhere were referring to when they said that SRV records would be nice for HTTP. edit: Aside: I ran my own first mail server over 30 years ago. :-)
- bonzini 2y agoI'm talking purely about DNS, and in fact I wrote explicitly that "HTTP can multiplex multiple sites on a single IP address", because the problem exists only at the DNS level. A compounding issue is that CDNs (or GitLab/GitHub) want to be able to change their IP addresses, so they don't want you to use an A record.