Synthetic Industry

Job dns-website-opens-on-www-but-not-bare-domain · revised 11 October 2026

Make your bare domain and www address both open the same website

Repair the DNS records and arrange one redirect so the bare domain and the www address both reach your website, with mail records left exactly as they are.

You might be seeing

  • The site opens with www in front but "server not found" without it, or the reverse
  • The bare domain shows a registrar or host parking page instead of your site
  • Two versions of the site both load and search results show both
  • Someone said "just add a CNAME" and email stopped working afterwards

No passwords, keys, card details or admin invites needed to start.

What usually happened

The bare domain (the zone apex) and the www name are two separate DNS names, and each needs its own correct answer. One of them has no record, still points at an old server or a parking page, or was set up as an alias in a way DNS does not allow at the apex, where mail and verification records also live. Visitors then get an error or the wrong site depending on which one they type, and a careless fix can break email.

Who it’s for: Owner of a small business whose website opens at www.yourbusiness.co.uk but shows an error, a parking page or the wrong site at yourbusiness.co.uk, or the other way round.

Usually starts when: Customers who type the bare domain, or follow an old link or business card, land on an error; or a recent host or designer change left only one of the two names working.

The result: Both names, over http and https, end at one chosen https address on your website through a permanent redirect with no loop, and the mail and verification records at the bare domain are unchanged.

Check whether this job fits

Four questions, about two minutes. Your answers stay on this page unless you choose to email them.

Which address does not open your site?

Try both in a private browser window: yourbusiness.co.uk and www.yourbusiness.co.uk.

What do you see at the address that fails?
Can someone change your DNS records, or follow written steps to?
Are you also moving the domain's nameservers or changing host this month?

Answer the questions to see whether this job fits.

Nothing is sent anywhere until you choose to email us.

Send an enquiry about this outcome

Checks you can run yourself

  1. See what each name answers with

    On a Mac or Linux terminal, run these read-only lookups with your own domain, or use any public DNS lookup website.

    dig +short A yourbusiness.co.uk; dig +short CNAME www.yourbusiness.co.uk; dig +short MX yourbusiness.co.uk

    Look for: A blank answer for a name means it has no record. Two different addresses for the two names usually means one of them still points at an old server. Note the MX lines: they must be the same after any fix.

  2. See how each address ends up

    Follow the redirects from the plain http version of each name and print where it lands.

    curl -sSIL -o /dev/null -w "%{url_effective} %{http_code} %{num_redirects}\n" http://yourbusiness.co.uk

    Look for: One final address, a 200 status and no more than two redirects. A loop, or a longer chain, means a rule is fighting the DNS change.

What you get

  • A before and after listing of every record in the zone, with each change marked
  • Exact steps for whoever edits your DNS, or the changes entered by us if you grant DNS-only access
  • A results table for the four address variants: final address, status and number of redirects
  • A note of the previous values so each change can be put back

Included

  • One domain whose DNS sits at one provider, with up to 40 records in its zone
  • A read-only inventory of the zone before any change, with mail, verification and subdomain records marked as not to be touched
  • Choosing with you the preferred address, www or bare, and arranging a permanent redirect from the other to it using your website host's or CDN's own redirect setting, made by you or the host (DNS-only access does not reach it)
  • Correcting the record at each name using the way your DNS provider and website host document: address records, or the provider's own alias or flattened-alias record where one is offered
  • After the records are changed and the host has issued its certificate for the newly pointed name, checking http and https on both names, and that the certificate shown covers each address a visitor reaches

Not included

  • Moving the domain to a new DNS provider or registrar: that is a separate job
  • Moving the website or mailboxes to a new host or provider
  • Buying, renewing or replacing a certificate that does not cover your names
  • Mapping many old page addresses to new ones for search ranking
  • More than one domain, or a zone with more than 40 records, which we quote separately

How we know it’s done

Agreed with you before work starts. Each check produces evidence you keep.

  1. Each of http://domain, https://domain, http://www.domain and https://www.domain ends at the one preferred https address with status 200 and no more than two redirects, none in a loop and none stopped by a certificate error, and the preferred https address itself answering without a redirect.

    Evidence: A four-row table of start address, final address, status and redirect count; a certificate error shows as an error message and status 000 in its row

    curl -sSIL -o /dev/null -w "%{url_effective} %{http_code} %{num_redirects}\n" http://yourbusiness.co.uk
  2. The MX records and every TXT record at the bare domain, including SPF and verification records, are identical before and after the change.

    Evidence: Before and after listings of the apex records

    dig +short MX yourbusiness.co.uk
  3. The certificate served at the preferred address is valid today and names that address, and the certificate for the other name covers it too, so no browser warning appears at either name.

    Evidence: Screenshot of the padlock detail and the certificate dates

Sign-off. You sign off after the four-address table, the unchanged mail records and the certificate check pass, and again if cached answers delay the result.

If it fails. If the agreed checks do not pass, you do not pay. The previous records are put back, unless you ask to keep the new ones while the host sorts out the certificate, and we tell you what the host or DNS provider needs to change.

When it fits, and when we stop

It fits when

  • The domain is paid up and you or a named holder can edit its DNS, or will follow our steps
  • Your website host can tell you the address or hostname it wants each name to point to, and accepts both names for your site
  • Your DNS is answered by one provider, not split between two
  • Your website host or CDN lets you set a redirect from one name to the other, or its support will set it
  • Your website host serves both names for your site and either already holds a certificate that covers both, or issues one automatically or on request once the name points at it, and can confirm which in writing

We stop and tell you if

  • Neither name works because the site, the host account or the domain itself is down or expired: that is a different problem
  • The host cannot serve the bare domain for your site at all, so the fix has to be at the host
  • Nameservers are being moved at the same time, which makes the zone a moving target
  • Nobody can sign in to change DNS and nobody can be asked to
  • The host cannot issue a certificate that covers the bare domain, or has not issued one by the end of the wait agreed in writing before the change

What could go wrong

Every change is listed with its previous value. Your DNS holder can put the old records back, but cached answers may keep the new ones until their lifetime ends, so allow for that before judging the result.

Scroll the table sideways to read it all.

RiskHow we handle it
An apex change breaks email or a service verification record at the same name.Mail, verification and subdomain records are marked as not to be touched, compared before and after, and the plan is reviewed before it is applied.
Old answers stay cached, so the fix looks like it has not worked.We lower record lifetimes ahead of the change where the provider allows it, and check again once the old lifetime has passed.
The website host does not recognise the bare domain, so visitors reach a generic page.We get the host's written instruction first and stop if the host cannot serve the name.
A name that has only just been pointed at the host may show a browser certificate warning until the host issues its certificate.The wait is agreed in writing beforehand, the redirect is set only after the certificate covers both names, and if the host cannot issue one in that time the change is put back unless you choose to keep it while the host sorts it out.

A second reviewer, separate from the work that produced the plan, compares every proposed change with the pre-change inventory. No human supervisor is included unless your proposal names one. At launch much of the preparation is automated, and we say so.

How we deliver

We arrange the work and independent review, then show you the result against the agreed checks. You keep authority over your systems.

  • Export the zone and read the public answers for the bare domain, www, mail and verification names
  • Agree the preferred address, the host's stated target for each name, and in writing how and when the host issues its certificate for both names
  • Prepare the smallest record change that fixes each name, and the one redirect, leaving mail and verification records alone
  • A second reviewer compares the plan with the inventory before you are asked to apply anything
  • You or your DNS holder apply the record change at the agreed time; we check that both names now answer from your host and that the mail records are unchanged
  • We wait for the host to issue or confirm its certificate for the newly pointed name; once it covers both names, you or the host set the redirect
  • We check all four address variants and the mail records, then again once cached answers expire

This is a one-off job, not emergency cover or a subscription. We confirm eligibility, the total price, a start window and a delivery date before you accept. Work starts only after agreed inputs, secure access, any licences and necessary permissions are in place. Hosting, platform and supplier charges are excluded unless the written quote includes them. No charge or booking is created by an enquiry.

Need to keep it working?

If your DNS changes often, ask about the standing responsibility that checks the records against an agreed baseline each month.

Ongoing work is separately scoped and quoted: no monitoring, response-time guarantee or automatic subscription is included in this job.

Explore an ongoing engineering lane, or mention the responsibility you need in your enquiry.

What you can check

This is a new service. We have not delivered this job for a client yet.

Other ways to get this done

  • Many DNS providers can add the missing record in a minute if you know the exact address or hostname your website host gave you. If the only symptom is a missing www record, try that first and check the result with the self-checks above.
  • Your website host's support can usually say which address each name should point to, and can sometimes add the bare domain on their side.

Questions

Will my email stop while you fix this?

It should not. Mail records at the bare domain are left as they are and compared before and after. If a change can touch them, we stop and tell you first.

Should I use www or the bare domain?

Either works. We agree one with you and make the other redirect to it, so search engines and customers see a single address.

Can the DNS provider do this without you?

Often, yes, if you know the exact address the host wants. This job is for when you do not, or when a change has already broken something.

Why is the certificate checked after the DNS change, not before?

A host often cannot issue a certificate for a name until the name points at it, so the certificate for the bare name may not exist until the record is fixed. Our reading is that the most common automatic method asks the name itself for a file, which cannot work before the name leads to the host. Hosts differ, so the host's written instruction says how and when it issues one. We change the record first, wait for the certificate, then set the redirect and run the checks.

Send an enquiry

Send us

  • The domain name and where its DNS is hosted, if you know
  • What you see at the bare domain and at the www address: the exact error, a parking page, or a redirect
  • Who hosts the website and what address or hostname they told you to use
  • Who answers your email, so we know which records must stay as they are

Later, once you agree

  • An export or screenshots of every record at the DNS provider
  • An invitation to the DNS account with permission to edit DNS only, or a person who will enter the records
  • The host's written instruction for the bare domain and the www name, including how and when it issues the certificate for each
  • Access to the host's or CDN's redirect setting, or a person who will change it from our steps
  • A company-controlled secure handoff agreed before any access: no live passwords, keys or customer records by ordinary email

The domain, the DNS account and the website host stay in your name. We prepare and check the record changes; you or your DNS holder make them, or invite us with permission to edit DNS only. The redirect is set at your website host or CDN by you or the host's support. We never need the registrar login.

A public HTTPS link only, without login details, query strings or fragments. No code or logs.

Sending emails your enquiry and contact address to our team through our mail provider (Resend). It is not kept in a website database. Do not send passwords, keys, recovery links, confidential code or customer records. Your contact email is unverified; nothing is ordered, charged or reserved. Privacy notice.

Email fallback: open your mail app

If website submission is unavailable, review and send the fallback email yourself. An email fallback is not a website receipt. Or write to hello@syntheticindustry.ai with “dns-website-opens-on-www-but-not-bare-domain” as the subject.