Compare

Cloudflare for SaaS custom hostnames: the price, and the DNS record it still needs

These are not competitors, and pretending otherwise would waste your time. Cloudflare for SaaS terminates traffic on your customers' hostnames — certificates, routing, WAF. DoDomain does the half that happens first: getting the DNS records created in the customer's own registrar and proving they are live. This page prices the Cloudflare side at your volume, covers apex and validation, and is about the seam between the two.

Facts about Cloudflare for SaaS checked on against developers.cloudflare.com (Cloudflare for SaaS plans, quotas and billing, getting started, validation and certificate pages) — check their site for current figures. DoDomain's numbers come from its live plan definitions. Published , updated .

Who does which half

DoDomainCloudflare for SaaS
Gets the customer's DNS records createdYes — Cloudflare OAuth one-click, Domain Connect where the provider has enabled it, guided per-provider steps everywhere elseNo — the customer still has to create the record in their own DNS provider
Proves the records are liveYes — queried at the domain's authoritative nameservers, not a UI checkboxHandles the domain validation its own certificates require: hostname ownership, plus certificate validation by http, txt or email
Terminates TLS on the customer's hostnameNo, by design — traffic never touches DoDomainYes — that is the product
Watches for DNS drift after go-liveYes — on every plan, including Free, with signed events naming the failing recordsPartly — a hostname whose record no longer points at the fallback origin is marked Moved and deleted after seven days; the documented webhooks cover the certificate lifecycle only
Apex (zone-root) hostnamesA/AAAA/TXT/MX at the apex on every plan and every connect tierApex proxying / BYOIP: a paid Enterprise add-on; a CNAME at the apex through the customer's CNAME flattening is not gated (per developers.cloudflare.com/cloudflare-for-platforms/cloudflare-for-saas/plans/, retrieved 2026-10-06)
What you pay forVerified connections per month — a connection counts once, on its first verification; 50 of them on FreeCustom hostnames served: first 100 included, then $0.10 per hostname per month to 50,000, Enterprise above; pending hostnames bill until deleted (per developers.cloudflare.com/cloudflare-for-platforms/cloudflare-for-saas/plans/, retrieved 2026-10-06)

What Cloudflare for SaaS custom hostnames cost at scale

Cloudflare bills this product per custom hostname served. The published packaging (per developers.cloudflare.com/cloudflare-for-platforms/cloudflare-for-saas/plans/, retrieved 2026-10-06) includes the first 100 hostnames on the Free, Pro and Business zone plans, charges $0.10 per additional hostname per month up to 50,000, and moves volumes beyond that to Enterprise. Worked through, that is:

Custom hostnamesBillable beyond the included 100Hostname fee per month
1000$0
500400$40
1,000900$90
5,0004,900$490
10,0009,900$990
50,00049,900$4,990

That is the custom-hostname line only, computed from the published rate. A customer who adds a hostname and never completes setup still counts: per Cloudflare's quotas and billing page, each custom hostname counts toward usage until you delete it, pending ones included. The quota is described as a soft limit, with a separate enforcement threshold on non-Enterprise plans.

Cloudflare says the product is bundled with non-Enterprise plans, and its getting-started guide begins by adding your zone on a Free plan. The zone plan's own price was not retrieved for this page, so the table excludes it; check Cloudflare for what else your account is billed for.

DoDomain is priced on a different unit, which is why the two bills do not overlap. The table below prices three scenarios on each side's own meter: new domains per month for DoDomain, domains live at once for Cloudflare.

ScenarioNew domains a monthDomains liveDoDomainCloudflare for SaaS
Launching20100Free — $0 forever$0
Growing3002,000Pro — $29 per month$190
Established2,00020,000Scale — $99 per month$1,990

List prices, monthly billing. DoDomain counts a domain once, in the month it first verifies; re-checks and drift monitoring are free on every plan, so live domains add nothing. One-click setup starts on Pro — a cheaper plan above is the guided-records flow. Cloudflare's column is the custom-hostname fee only. It excludes the zone plan, Enterprise-only features (custom certificates, wildcard custom hostnames, mTLS), apex proxying or BYOIP, and anything above 50,000 hostnames, which is Enterprise pricing.

DoDomain does not compete with that hostname rate; the point of the table is that the two lines are different, and a product serving 20,000 domains and adding 2,000 a month pays both. See pricing.

How Cloudflare validates a hostname, and what it leaves undone

Cloudflare for SaaS runs two separate validations, both documented in its own pages. The first proves your customer owns the hostname. That can happen before the routing record exists, using a TXT record or an HTTP token, or in real time once the customer adds the record that points the hostname at your target. Cloudflare notes the real-time path may cause some downtime and that its retries follow a backoff schedule: 75 retries over seven days, after which a hostname that never validates is deleted.

The second is certificate validation. Per Cloudflare the method is http, txt or email, and wildcard certificates require TXT. Each hostname gets two certificates, ECDSA and RSA, with 90-day validity and renewal 30 days before expiry.

Both validations answer one question: may Cloudflare issue and serve this hostname. Neither creates the record in your customer's DNS account, and neither reports next month whether the customer deleted it. The status values give you some of that: a hostname that no longer points at the fallback origin is marked Moved, and a hostname that stays Moved for more than seven days is Deleted. The documented webhooks we found cover certificate events, so a customer breaking their own record reaches you by polling the status or by noticing the traffic stop.

Limits worth knowing before you build

Cloudflare documents a few constraints that shape the integration. Custom hostnames over 64 characters need cloudflare_branding turned on, a hostname equal to your SaaS zone name is not allowed, and hostnames that use another CDN are not compatible. A customer whose domain is already on Cloudflare cannot control Argo, Early Hints, client-side security, Spectrum or wildcard DNS for the managed hostname, and pre-validation is not supported in that case.

The general Cloudflare API limit is 1,200 requests per five minutes per user or account token, and a breach blocks calls for five minutes. We found no custom-hostname-specific limit beyond that. If you onboard in bursts, a queue in front of the hostname-create call is cheaper than learning about the limit in production.

Apex domains: where the two products disagree about tiers

Customers type the bare domain. Cloudflare's normal setup is CNAME-only, and it says that if a customer needs to use an A record you need apex proxying. The plans page row is "Apex proxying/BYOIP", listed as a paid add-on for Enterprise (per developers.cloudflare.com/cloudflare-for-platforms/cloudflare-for-saas/plans/, retrieved 2026-10-06). A customer whose DNS provider flattens a CNAME at the apex can still point it at your target, and Cloudflare's own docs describe that as offered through CNAME flattening. So serving acme.com itself is a tier decision only on the IP-based path.

On the DNS side it is not a tier decision at all. Apex records — A, AAAA, TXT and MX at @ — are guided and verified on every DoDomain plan, including Free, and on every connect path. On Pro and Scale the Cloudflare one-click path writes them through the user's own OAuth grant.

Being precise about the apex, because it matters and because it also limits us: a CNAME can never exist at a zone apex — that is RFC 1034 §3.6.2 and RFC 2181 §10.1, not a product decision — and DoDomain does not write the non-standard ALIAS/ANAME records some providers offer instead. What it does is know which providers have that feature, tell your customer the right thing for theirs, and verify the result. The apex guide is the honest, provider-by-provider version.

And then nobody watches the record again

A proxy's job starts when a request arrives. If your customer edits their zone six months from now and the record stops pointing at you, no request arrives — so the first signal is usually the customer, unless you poll Cloudflare's hostname status.

DoDomain keeps reading authoritative DNS after go-live: every 10 minutes for a connection's first day, then hourly for a week, then every 6 hours, with suspected drift confirmed on three consecutive checks before you are told. connection.failed names the exact failing records; connection.verified fires again with a recovery signal when they come back. Both are HMAC-SHA256-signed and both are on every plan, Free included.

What the DoDomain side looks like in code

On this page DoDomain gets the record into the customer's DNS and proves it, and Cloudflare serves the traffic. So the record in the session points at Cloudflare's edge through your CNAME target. Cloudflare lets you use a friendlier name such as customers.saasprovider.com as the target, which is a proxied record in your own zone that resolves to your fallback origin. The sample uses that shape, with your own name in place of the placeholder.

Add the custom hostname in Cloudflare first, then mint the session with the same target. The customer never sees Cloudflare's name for your origin, only the one record.

// 1. Your server: mint a connect session for the customer's domain.
import { DoDomain, verifyWebhook } from "@dodomain/node";
import { env } from "./env"; // your validated server env

const dodomain = new DoDomain({ secretKey: env.DODOMAIN_SECRET_KEY });
const session = await dodomain.sessions.create({
  domain: "customer.com",
  records: [
    { type: "CNAME", host: "app", value: "customers.yourapp.com" },
  ],
  returnUrl: "https://yourapp.com/settings/domains",
});

// 2. Your page: open the connect sheet with session.token.
import { showDoDomain } from "@dodomain/connect";

showDoDomain({ token, onVerified: ({ domain }) => markDomainLive(domain) });

// 3. Your webhook route: DoDomain calls it once the record is live at the
//    domain's authoritative nameservers, and again if it ever breaks.
if (!verifyWebhook(env.DODOMAIN_WEBHOOK_SECRET, rawBody, signatureHeader)) {
  return new Response("bad signature", { status: 400 });
}

From Pro up, the session picks the path on its own: a Cloudflare-hosted domain gets the OAuth one-click, a provider that has enabled DoDomain's Domain Connect templates gets a signed apply, and every other provider gets step-by-step records for that provider's dashboard. On the free plan every provider gets the step-by-step records. The full walkthrough is in the quickstart.

Wiring them together

The integration is small because the handoff is narrow. Add the custom hostname in Cloudflare for SaaS as you already do; take the record values Cloudflare tells you the customer must create; pass exactly those records to POST /api/v1/sessions and hand your user the returned connectUrl — a hosted page, or the @dodomain/connect widget embedded in your own onboarding.

Your customer then gets a real path instead of a record to copy: if their domain is on Cloudflare, a scoped OAuth approval on Cloudflare's own page writes it; if their provider has enabled our Domain Connect templates, a signed one-click apply writes it; otherwise they get their provider's dashboard link, its host-field quirks, and a live status per record.

When the signed connection.verified webhook reaches your server, the records are confirmed live at the domain's authoritative nameservers — that is your cue to activate the tenant. One-click setup starts on Pro; on Free the same session produces guided records.

How to choose

  • You need HTTPS on customer domains and have no edge: Cloudflare for SaaS is the cheapest published way in, and DoDomain does not replace it.
  • Your customers' domains are already in your own Cloudflare account: the DNS step is yours to make and there is nothing to guide.
  • Self-serve customers arrive on many registrars and stall at the record: add DoDomain. Keep Cloudflare for SaaS exactly as it is.
  • You only onboard a handful of enterprise customers a year: a support engineer on a call is cheaper than any vendor.

The two run side by side with no shared state. If you later move off Cloudflare for SaaS, change the record value in your session payload and DoDomain guides the same customers through the new one.

Where Cloudflare for SaaS still wins

On price, first. It publishes a low per-hostname rate, includes the first 100 hostnames, and the cost of getting started is a Free zone plus the hostname fee. DoDomain does not serve traffic, so there is nothing to weigh against it on that axis.

It runs on Cloudflare's own network, with WAF for SaaS under the current zone plan on the self-serve tiers and custom firewall rulesets on Enterprise. Per-hostname analytics, Argo, caching and Early Hints for SaaS exist as documentation sections, and a per-hostname custom origin is available on every plan.

Its documentation is deep. It covers certificate validation, the retry backoff, custom origins, custom certificates, certificate authority choice and a published API rate limit. Enterprise adds custom certificates, CSR support, wildcard custom hostnames and mTLS. It documents certificate-lifecycle events and per-hostname analytics.

When you don't need DoDomain here

Honest flip side. If your customers' domains are already inside your own Cloudflare account, the DNS step is yours to make and there is nothing to guide. If you only onboard a handful of enterprise customers a year, a support engineer on a call solves this more cheaply than any vendor. And if the record your customers must create is genuinely one CNAME on a provider they all share, a good copy-paste screen may be enough.

DoDomain earns its place when self-serve customers arrive on 20 different registrars and the DNS step is where they stall — and it never asks you to move traffic to find out, because it is never in the request path.

Frequently asked questions

Is DoDomain an alternative to Cloudflare for SaaS?

No — they solve different halves of the same problem. Cloudflare for SaaS terminates traffic on your customer's hostname: it issues and renews the certificate and routes the request to your origin. DoDomain is the step before that: it gets your customer to create the DNS records Cloudflare needs, applies them one-click where it can, verifies them against the domain's authoritative nameservers, and tells your server when they are live. DoDomain never proxies traffic and never issues certificates, so it cannot replace Cloudflare for SaaS.

What does Cloudflare for SaaS cost?

Per Cloudflare's plans page (retrieved 2026-10-06, shown as last updated Aug 14, 2026), the first 100 custom hostnames are included on the Free, Pro and Business zone plans and each additional hostname is $0.10 per month, up to 50,000. That is $90 a month for 1,000 custom hostnames and $990 a month for 10,000, for the hostname line only. Enterprise is custom pricing. We did not retrieve the zone plans' own prices.

Is Cloudflare for SaaS free?

Partly. Cloudflare says Cloudflare for SaaS is bundled with non-Enterprise plans, and its getting-started guide begins by adding your zone on a Free plan. The first 100 custom hostnames are included, so a small fleet pays no hostname fee. Beyond that it is $0.10 each per month. Pending hostnames count toward usage until you delete them.

Do pending custom hostnames cost money on Cloudflare?

Yes, according to Cloudflare's quotas and billing page: each custom hostname counts toward usage until you delete it, including hostnames that are pending validation or activation. A customer who adds a domain and never creates the record can therefore keep billing. Cloudflare's validation backoff retries over seven days (75 retries) and then deletes a hostname that never validates.

Does Cloudflare for SaaS write DNS records in my customer's account?

No. Per its getting-started guide, your customer needs to set up a CNAME record at their authoritative DNS that points to your CNAME target. If the domain is on Cloudflare too the experience differs, but for everyone else the customer creates the record themselves. That handoff is what DoDomain automates, with a Cloudflare OAuth path, a signed Domain Connect apply, or guided steps.

Does Cloudflare for SaaS support apex domains?

Two different things. A customer can point their apex at your target with a CNAME if their provider flattens it, and Cloudflare notes that this is offered through CNAME flattening. Apex proxying, where the customer uses an A record, uses a Cloudflare-assigned static IP prefix or BYOIP, and the plans page lists it as a paid Enterprise add-on. DoDomain guides and verifies A, AAAA, TXT and MX at the apex on every plan.

How does Cloudflare for SaaS validate a customer's domain?

There are two validations. Hostname validation verifies the customer owns the hostname, using a TXT record or an HTTP token before the record exists, or automatically once the customer adds the routing record. Certificate validation (DCV) uses http, txt or email, and wildcards require TXT. All of these are about Cloudflare issuing a certificate; none of them tells your app the customer's DNS is still correct next month.

Does Cloudflare for SaaS send webhooks?

The documented notification events are certificate lifecycle events: validation, issuance, deployment, deletion and renewal succeeded or failed, plus an upcoming-expiration notice. We found no documented webhook for a hostname moving away from your fallback origin, and no signature scheme on that page. DoDomain's webhooks are HMAC-signed and report whether the customer's DNS holds the records you asked for.

Can I use DoDomain with Cloudflare for SaaS?

Yes, and nothing about your Cloudflare configuration changes. Add the custom hostname in Cloudflare for SaaS, take the record values it tells you the customer must create, and pass exactly those records to POST /api/v1/sessions. Send your user the returned connectUrl. When the signed connection.verified webhook arrives, the records exist at the domain's authoritative nameservers and you can activate the tenant.

Do I still need a custom-hostname provider if I use DoDomain?

Yes, if your product is reached over HTTPS on your customer's domain. Something has to hold a certificate for that hostname and route the request — Cloudflare for SaaS, another proxy, or your own platform's custom-domain support. DoDomain's job ends at proof that the DNS is correct.

Does DoDomain charge extra for webhooks?

No. HMAC-SHA256-signed webhooks are on every DoDomain plan, including Free at $0 forever — connection.verified when a domain goes live, and connection.failed when a connected domain's records later drift, with the failing records named in the event.

Start on the free plan

No card, no sales call — create an app, mint a session, and watch the first domain verify.

Other comparisons