Point Namecheap Domain to Vercel: Apex, CNAME, and SSL Setup

by Fahim

You bought a domain on Namecheap and want your Vercel app to resolve smoothly across both your root and www hostnames without throwing SSL warnings. Here is how to configure Namecheap BasicDNS, map your apex A record, wire up CNAME routing for subdomains, and get Let’s Encrypt TLS certificates verified without getting stuck on stale records.

Terminal window showing DNS dig verification commands for Namecheap domain connected to Vercel
Terminal window showing DNS dig verification commands for Namecheap domain connected to Vercel

Apex vs Subdomain: Choosing Your Primary Production URL

Before touching your DNS records in Namecheap, decide which format will be your canonical production URL. You generally have two choices:

  • Apex canonical (domain.com): Clean and compact, but standard DNS providers like Namecheap BasicDNS do not support CNAME flattening at the zone apex.
  • Subdomain canonical (www.domain.com): Easier to scale across CDNs using pure CNAME routing, while redirecting root traffic to www.

Vercel handles both natively and manages the automatic 308 permanent redirect between them. I usually pick www.domain.com as the canonical target with a redirect from the apex for better edge routing flexibility, but you’ll configure records for both so users land in the right spot either way.

If you’ve routed domains on other platforms, the logic is identical. Our guide on pointing Namecheap domains to Netlify follows the exact same root-to-subdomain workflow.

Add Your Custom Domains Inside Vercel Dashboard

First, register both hostnames in your Vercel project so their edge network knows to route traffic to your build.

  1. Head to your Vercel Dashboard and click into your project.
  2. Go to Settings > Domains.
  3. Enter your apex domain (e.g., mysite.com) and click Add.
  4. Vercel will ask if you want to automatically add the www variant with a redirect. Choose the recommended option: “Add mysite.com and redirect www.mysite.com to it” (or flip it to www canonical if that is your preference).

Once added, Vercel will flag an Invalid Configuration badge with the DNS targets you need. Keep that tab open while you jump to Namecheap.

Configure Namecheap BasicDNS Records (A & CNAME)

By default, Namecheap uses BasicDNS, which gives you direct access to your DNS zone file. Log in to Namecheap to adjust the records.

  1. Open your Domain List and click Manage next to your domain.
  2. Under the Nameservers section, make sure Namecheap BasicDNS (or WebDNS) is selected. If custom nameservers are set, switch back to BasicDNS and save.
  3. Click the Advanced DNS tab.
  4. Delete any existing parking records—especially URL Redirect Record rows pointing to http://www.namecheap.com or parking A Records pointing to 198.54.115.x. Leaving them will break validation.

Now add the two records Vercel needs:

Enter these exact DNS entries in the Namecheap table:

Type: A Record
Host: @
Value: 76.76.21.21
TTL: Automatic (or 1 min for fast testing) Type: CNAME Record
Host: www
Value: cname.vercel-dns.com.
TTL: Automatic

The @ host represents your root apex (mysite.com), and 76.76.21.21 is Vercel’s Anycast IP. Adding a trailing dot to cname.vercel-dns.com. prevents Namecheap from accidentally appending your domain name to the end of the target.

This is standard procedure across static hosts. See our breakdown on pointing Namecheap to GitHub Pages if you want to see how GitHub handles apex routing compared to Vercel.

Verify DNS Propagation via Terminal

Do not rely on refreshing your browser to test DNS—local browser and OS caches will lie to you. Query public DNS resolvers directly using dig or nslookup against Cloudflare (1.1.1.1) or Google (8.8.8.8).

Run these commands to confirm your records are live:

# Check the apex A record
dig @8.8.8.8 mysite.com A +short # Check the www CNAME record
dig @8.8.8.8 www.mysite.com CNAME +short

You want to see 76.76.21.21 for the apex query and cname.vercel-dns.com. for www. If you’re on Windows without dig, use Resolve-DnsName mysite.com in PowerShell.

Next, send a quick curl request to ensure Vercel’s edge nodes are handling requests for the domain:

curl -I https://mysite.com

Look for server: Vercel and an x-vercel-id response header. If you see those, traffic is successfully hitting Vercel’s infrastructure.

Automated SSL Generation and Let’s Encrypt Verification

Once DNS resolves properly, Vercel automatically requests an SSL/TLS certificate via Let’s Encrypt using an automated ACME HTTP-01 challenge.

In your Vercel dashboard, the status badge will move through three stages:

  • Invalid Configuration: DNS records haven’t propagated yet or don’t match Vercel’s targets.
  • Generating Certificate: DNS matched; Vercel is running the ACME challenge.
  • Valid Configuration: Everything is live, SSL is active, and HTTP redirects to HTTPS automatically.

This process usually takes under two minutes once DNS propagates. Vercel auto-renews these certificates every 60 days in the background.

Fix the Classic Gotchas (Parking Pages, Stale CAA, and MX Clashes)

If your domain stays stuck on “Invalid Configuration” or “Generating Certificate” for more than 15 minutes, you’re almost certainly hitting one of these Namecheap quirks.

1. Hidden URL Redirect Records

Namecheap often preserves an active URL Redirect Record in the Advanced DNS tab after registration. If there is a row with Type: URL Redirect Record pointing to http://www.namecheap.com, delete it. It silently intercepts traffic and prevents Vercel from validating the apex @ A record.

2. Restrictive CAA Records

If your domain has preexisting CAA (Certificate Authority Authorization) records from another host, Let’s Encrypt will be blocked from generating your certificate. Add an explicit record allowing Let’s Encrypt to issue certs:

Type: CAA Record
Host: @
Value: 0 issue "letsencrypt.org"
TTL: Automatic

3. Custom Email and MX Record Preservation

Pointing your apex A record to 76.76.21.21 won’t disrupt your email delivery as long as your MX records point to separate mail servers (like Google Workspace or Fastmail). Just make sure your MX records never point to @ directly. If you manage custom email on this domain, review our guide on configuring SPF, DKIM, and DMARC in Namecheap DNS to keep deliverability intact.

Custom Subdomains and Multi-Environment Routing

If you want to spin up a staging environment, doc site, or separate API on a subdomain like app.mysite.com, you don’t need another A record.

In Namecheap’s Advanced DNS tab, add a CNAME record targeting Vercel:

Type: CNAME Record
Host: app
Value: cname.vercel-dns.com.
TTL: Automatic

Then jump back to Vercel, add app.mysite.com under Domains, and map it directly to your target branch (like staging or preview). If you ever need to route a subdomain to a separate VPS instead, check our walkthrough on pointing a Namecheap subdomain to a separate server.

Frequently Asked Questions

How long does it take for Namecheap DNS to update on Vercel?

With Namecheap BasicDNS, updates usually propagate within 5 to 15 minutes if your TTL is set to Automatic or 1 min. Full global propagation can take longer, but your local resolvers and Vercel will typically pick it up in minutes.

Can I use Namecheap ALIAS or ANAME records instead of an A record?

No. Namecheap BasicDNS does not support apex ALIAS or ANAME records. You have to use the static Anycast A record (76.76.21.21) for root (@) and a CNAME for subdomains like www.

Do I need to change Nameservers to Vercel’s nameservers?

No. Keep Namecheap BasicDNS active and simply add the A and CNAME records in the Advanced DNS tab. Switching to Vercel’s nameservers (ns1.vercel-dns.com) is optional and only necessary if you want Vercel to manage your entire DNS zone.

Why is my SSL certificate failing to verify on Vercel?

This almost always comes down to an undeleted Namecheap URL Redirect parking record or restrictive CAA records blocking Let’s Encrypt. Remove conflicting records and give Vercel 10 minutes to rerun the ACME HTTP-01 challenge.

Next Steps

With your apex and www records wired up and SSL active, you can move on to setting custom branch domains or security headers. If you’re running WordPress or a backend service alongside your Vercel frontend, read our guide on creating a subdomain with Namecheap DNS to connect the rest of your stack.

all_in_one_marketing_tool