DNS Provider Limitations/Behaviors for Entri Connect

Last updated: January 22, 2026

This article documents known limitations and constraints that are not under Entri's control, as they are on the DNS provider's side and affect Connect's flow.

Entri Connect is integrated with the majority of DNS providers, simplifying domain configuration. However, some DNS providers enforce restrictions through their APIs, security policies, or DNS implementations that limit what can be configured automatically. In such cases, manual DNS setup, additional user actions, or additional implementation may be required.

Understanding these limitations will help you resolve configuration issues faster.


Why These Limitations Exist

These restrictions are not Entri limitations. They originate from DNS providers themselves and are enforced through their systems and APIs.

Common reasons include:

  • Provider-specific implementations
    Each DNS provider controls how automation is allowed.

  • Security and account protection policies
    MFA, passkeys, device security keys, and domain protection features can block automated access.

  • API design and feature gaps
    Some providers do not support advanced DNS features, wildcards, long TXT records, or record overrides.


Provider Limitations and Known Issues

Below is a list of known provider-specific constraints that may impact DNS automation.


GoDaddy

  • GoDaddy requires TTL values to be predefined in the Domain Connect templates. Unlike other providers, TTL values cannot be dynamically configured.
    TTL values must match those defined in Entri’s templates.
    If you need a custom TTL, contact Entri support to discuss template configuration.

  • GoDaddy only allows one flow with conflicting records for 3 times. After that, if there is any conflict, it will trigger the manual flow.

  • GoDaddy configures parked A records that are tied to their free products. These records can only be removed once the associated product is deleted. However, when using Entri, those records will be removed automatically if they conflict with records sent through Entri's payload.


Squarespace

  • Squarespace does not allow automated replacement of existing DNS records. If a record already exists, Entri Connect will redirect you to manual setup.

  • Manual steps required:

    1. Log in to the Squarespace DNS panel

    2. Remove the conflicting record

    3. Add the new DNS record provided by Entri

Example:
If www.yourdomain.com already has a CNAME record with host www, Entri cannot replace it automatically.


Cloudflare

  • Cloudflare allows enabling Proxy mode, but when enabled via Entri, it applies to all records created through Entri.


Amazon (Route 53)

  • Does not support separate hosted zones for subdomains

  • Passkey / security key (device MFA) login is not supported

  • Unexpected errors with certain login flows

  • MFA setup is mandatory


ArubaIT

  • DNS changes take up to 30 minutes to propagate

  • Records cannot be updated during propagation


CrazyDomains

  • Email verification may be required after a long period of inactivity

  • Premium DNS is required to update TXT and SRV records


DreamHost

  • Advanced protection plans require email verification on every login

  • Some services auto-create DNS records that cannot be removed, even if they conflict


Dynadot

  • Accounts may be locked while users continue login attempts

  • Repeated invalid credentials can trigger temporary lockouts


Gandi

  • Account verification is required

  • Some domains use legacy nameservers that do not support advanced DNS automation


GreenGeeks

  • Domains pointing to expired or missing hosting cannot be managed

  • DNS operations fail if the hosting is inactive


Hostinger

  • Social login credentials are not supported


Hover

  • TXT records longer than 255 characters are not supported


InMotion

  • Invalid passwords return errors only after MFA submission


Loocaweb

  • Wildcard DNS records are not supported


Namecheap

  • Device security key–based login is not supported


NameSilo

  • Domain Defender can block DNS record changes


One.com

  • MFA is handled through a companion mobile app

  • Mobile app MFA is not currently supported


OpenSRS

  • Wildcard DNS records are not allowed


OVH

  • Passkey login is not supported

  • CNAME records cannot use @ as the hostname


Papaki

  • Nameservers must be manually configured before DNS automation is possible


Porkbun

  • Hardware-based 2FA devices are not supported


Reg123

  • Domain Protection can prevent DNS changes


Registro

  • Switching between basic and advanced DNS has a cooldown period

  • Advanced DNS is required to configure records


Shopify

  • Passkey, social, and biometric logins are not supported

  • DNS cannot be managed for third-party domains

  • TXT records longer than 255 characters are not supported

  • Record values must be entered as FQDNs


Simply

  • Explicit permission from the account owner is required


Spaceship

  • USB security key–based login is not supported


Strato

  • Domain activation delay prevents DNS changes

  • Wildcard records are not supported


WebFamily

  • Password reset required after long inactivity

  • Migrated accounts may not be able to log in


Wild West Domains

  • Domain protection blocks DNS updates


Wix

  • Social logins are not supported

  • Wildcard records are not supported


WordPress.com

  • TXT records longer than 255 characters are not supported


Hosting.com

  • Domains without hosting require manual DNS setup

  • Some domains require admin-level login access


O2switch

  • Requires a cPanel password to be set


Limitations Not Yet Fully Handled

These issues are known but not fully mitigated yet:

Alibaba Cloud

  • Users attempt login via the Chinese version of the site, which is not supported


Porkbun

  • Repeatedly adding the same DNS record can trigger blocking


Namecheap

  • Domains using external hosting nameservers may not be discoverable

  • DNS cannot be managed if hosting is unavailable


GreenGeeks

  • Domain details API is unstable

  • Excessive requests may exceed timeout limits (30+ seconds)


Summary

While Entri Connect automates DNS management for a wide range of providers, provider-imposed constraints may require:

  • Manual DNS configuration

  • Account or security setting changes

  • Support assistance for advanced setups

If you encounter issues not listed here or need help configuring your domain, please contact Entri Support.