CNAME on a domain root does work, and it isn't evil
pzxc.com
pzxc.com
The rest of the network, everyone has to agree, and we manage that consensus by following standards, which tend to look ambiguous when they say something you wish they didn't.
You can't return a CNAME and something else. So your MX, NS, TXT, etc. records will be in an unknown state based on the client resolver/software. You'll see 40%-60% of your inbound email fail.
It doesn't work everywhere, it's not expected to work robustly anywhere, even if your server supports it not all clients will and there's just no need to do it. No matter how many out of date RFCs you quote. This hasn't changed in the past 10 years!
% dig +noall +comments +stats pzxc.com.
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: SERVFAIL, id: 14316
;; flags: qr rd ra; QUERY: 1, ANSWER: 0, AUTHORITY: 0, ADDITIONAL: 0
;; Query time: 161 msec
;; SERVER: 75.75.75.75#53(75.75.75.75)
;; WHEN: Sat May 28 02:38:43 2011
;; MSG SIZE rcvd: 26
joyeur.com, Joyent's blog, has the same problem: % dig +noall +comments +stats joyeur.com.
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: SERVFAIL, id: 57255
;; flags: qr rd ra; QUERY: 1, ANSWER: 0, AUTHORITY: 0, ADDITIONAL: 0
;; Query time: 133 msec
;; SERVER: 75.75.75.75#53(75.75.75.75)
;; WHEN: Sat May 28 02:40:38 2011
;; MSG SIZE rcvd: 28
Both pzxc.com and joyeur.com have CNAME records.So, yeah, using CNAMEs on your domains works great, except for all those times it doesn't work at all, like with the largest residential ISP in the United States.
A base domain cname record will (I believe) alias any query type to an alternate domain (like a dname) in at least the dig resolver.
dig pzxc.com soa +short
lwebs.com.
ns1.widge.net. postmaster.lwebs.com. 1304101336 16384 2048 1048576 2560
That isn't exactly what I would expect for an soa record (cname reference to another soa). Could cause problems with secondary servers and serial numbers...Note: Edited post, as I was (for a while) unable to view the site in chrome, but it worked in safari. Could have just been a timing/propagation issue though as it is working now.
I can put all many gigs of email in a flat file called 'mbox' -- that doesn't mean it's a good idea.
The 'traditional' way to handle this without doing all kinds of nasty, is to simply use the standard A/MX combo and either proxy/redirect back to the 'www' version.
slashdot.org has been doing it for years as 'proof' though, so, congrats?
Regardless, Slashdot isn't doing it now:
;; ANSWER SECTION: slashdot.org. 1704 IN A 216.34.181.45