DNS resolution in partial (CNAME) configuration
In a partial (CNAME) configuration, CIS handles DNS records a bit differently from full zones to internally resolve the origin server where proxied HTTP requests are sent to.
Records within the same zone
When you create a new DNS record in a partial zone, CIS automatically checks whether any of your CNAME records point to existing A, AAAA, or CNAME records within the same zone.
For example, CIS shows a warning if you have the following records in your partial zone:
sub1.partialzone.com CNAME sub2.partialzone.com
sub2.partialzone.com A 192.0.2.1
Because CIS contains both the CNAME and its target, the DNS resolution sends incoming HTTP requests to sub1.partialzone.com to the origin 192.0.2.1.
This can cause issues if you already have DNS records for sub2.partialzone.com at your authoritative DNS provider. These records might point to 192.0.2.4, another IP address, or another domain. However, because CIS
contains the initial record and the target, it never queries your authoritative DNS provider for the record for sub2.partialzone.com.
If you don't have the target of the CNAME record within your partial zone this DNS resolution happens differently.
Records pointing to a partial zone within the same account
You can also create a CNAME record in a zone (partial or full setup) that points to a record in another partial zone within your account. In this case, CIS always resolves the CNAME target based on the value at your authoritative DNS provider of the partial target zone.