Skip navigation

wildcard dns

1483 Views 8 Replies Latest reply: Jul 19, 2013 10:20 AM by David Kelly1 RSS
OcchioNL Calculating status...
Currently Being Moderated
Nov 23, 2012 1:39 AM

From my blog.


I’m having this problem where I can’t get the CNAME *.domain.tld working on Mac OSX server 10.8


I'll illustrate my problem (presuming web service is up and running):


Let’s set up a new “Primary Zone” with an “A Record”.

  2. DNS
  3. +
  4. Add Primary Zone
  5. Name: domain.tld
  6. Done
  7. +
  8. Add Machine Record
  9. Zone: domain.tld
  10. Host Name: domain.tld
  11. IP Addresses:
  12. Done
  13. Visit http://domain.tld/ in Safari

That’s great, now we can find the domain by visiting the browser, but how about www.domain.tld?

No can do.... But this is logical


Let’s add a CNAME (or “alias Record”)

  2. DNS
  3. +
  4. Add Alias Record
  5. Zone: domain.tld
  6. Host Name: www
  7. Destination: domain.tld
  8. Done
  9. Visit http://www.domain.tld/ in Safari

Now we can find domain.tld as well as www.domain.tld in the browser.

This is just great, it almost looks like a full Enterprise Webserver!!


Now I want to add *.domain.tld so I can find as well, of maybe just dev.domain.tld or test.domain.tld or even www2.domain.tld

  2. DNS
  3. +
  4. Add Alias Record
  5. Zone: domain.tld
  6. Host Name: *



The by most people much beloved GUI does not accept the * so I’ll just type “asteriks” in stead and change it in the terminal later.


  1. Host Name: asteriks
  2. Destination: domain.tld
  3. Done
  5. # sudo nano /private/var/named/db.domain.tld
  6. change "asteriks.domain.tld" to "*.domain.tld"
  8. DNS
  9. OFF
  10. ON


The “GUI” now reflects the zonefile.

I can now resolve anything.domain.tld, but not for long…


The problem

The problem is that periodically or after a service/machine restart, the *.domain.tld CNAME will be undone because Apple does not like it when I change things I’m not "supposed" to change.


The issue I have with this problem is that *.domain.tld is widely accepted in Bind/DNS systems except for Mac OSX server Mountain Lion.




Apple OSX Server is NOT enterprise ready because it fails on a number of accounts (Bind, Samba) to offer the functionalities a 'real world' enterprise *NIX server offers.


Apple "Server Support"

I have spoken to Apple Server Support in Ireland who only know how to handle the GUI, so very friendly, but not very helpful!



Please feel free to discus this issue in this thread of on my blog.


Message was edited by: OcchioNL

Mac Mini Server 10.8, OS X Server, 10.8
  • infinite vortex Level 7 Level 7 (21,400 points)
    Currently Being Moderated
    Dec 4, 2012 5:11 PM (in response to OcchioNL)

    It might simply be an issue in the GUI that doesn't allow wildcard entries. What you may wish to do is edit the zone record file manually and directly in /var/named and then lock the file so it can't be messed with. Irrespective of whether it's the right or wrong thing to do, it should fix your problem as this should work in BIND.

  • UptimeJeff Level 4 Level 4 (3,390 points)
    Currently Being Moderated
    Dec 4, 2012 6:57 PM (in response to infinite vortex)

    Very clear post.. thanks for that :-)


    try an $INCLUDE so that your wildcard lives in another file.


    not sure if will remove your $INCLUDE.. but worth a try.

  • David Kelly1 Level 1 Level 1 (25 points)
    Currently Being Moderated
    Jul 19, 2013 7:16 AM (in response to OcchioNL)

    Am curious if the GUI re-interprets the zone file or keeps an XML copy stashed somewhere which is used to regenerate the zone file any time it is edited by the GUI? I have grep'ed /Library looking for such and not found it.


    I seriously desire to enter wildcard domain definiitons for obnoxious pop-under ad domains.

  • MrHoffman Level 6 Level 6 (11,710 points)
    Currently Being Moderated
    Jul 19, 2013 9:33 AM (in response to David Kelly1)

    I don't know that there's any official documentation on the interaction, nor assurance that things won't change in some new version.  I've never seen that documentation, in any case.  Various versions of and Server have kept both the service configuration file(s) around and a plist file around; it's dreadfully fun when the two squabble around a DNS change.  There've been a few and rare occasions where I've had to exit the app and delete the plist to get the change accepted by the tool.


    As for your question, just set your DNS server as the authoritative DNS server for the domain you're aiming at, with no records.  Add an empty zone, in other words, that matches the domain or subdomain you're after.  No need for wildcards.

  • David Kelly1 Level 1 Level 1 (25 points)
    Currently Being Moderated
    Jul 19, 2013 10:20 AM (in response to MrHoffman)

    Thanks! An empty domain works when my server is the only DNS server but when clients have a fallback DNS listed they go that way when my mini's DNS fails to provide an answer.


    But ideas prompted by MrHoffman's and a bit more playing I have now found a workable solution!


    • Create a primary domiain, say "dummy.primary"
    • Create a nameserver entry for dummy.primary, use "localhost"


    Without the nameserver entry clients will try all DNS servers they know. But with, they will stop, which is the desired behavior for killing malicious domains.


More Like This

  • Retrieving data ...

Bookmarked By (0)


  • This solved my question - 10 points
  • This helped me - 5 points
This site contains user submitted content, comments and opinions and is for informational purposes only. Apple disclaims any and all liability for the acts, omissions and conduct of any third parties in connection with or related to your use of the site. All postings and use of the content on this site are subject to the Apple Support Communities Terms of Use.