DNS Provider Limitations/Behaviors for Entri Connect
Last updated: January 22, 2026
This article documents known limitations and constraints that are not under Entri's control, as they are on the DNS provider's side and affect Connect's flow.
Entri Connect is integrated with the majority of DNS providers, simplifying domain configuration. However, some DNS providers enforce restrictions through their APIs, security policies, or DNS implementations that limit what can be configured automatically. In such cases, manual DNS setup, additional user actions, or additional implementation may be required.
Understanding these limitations will help you resolve configuration issues faster.
Why These Limitations Exist
These restrictions are not Entri limitations. They originate from DNS providers themselves and are enforced through their systems and APIs.
Common reasons include:
Provider-specific implementations
Each DNS provider controls how automation is allowed.Security and account protection policies
MFA, passkeys, device security keys, and domain protection features can block automated access.API design and feature gaps
Some providers do not support advanced DNS features, wildcards, long TXT records, or record overrides.
Provider Limitations and Known Issues
Below is a list of known provider-specific constraints that may impact DNS automation.
GoDaddy
GoDaddy requires TTL values to be predefined in the Domain Connect templates. Unlike other providers, TTL values cannot be dynamically configured.
TTL values must match those defined in Entri’s templates.
If you need a custom TTL, contact Entri support to discuss template configuration.GoDaddy only allows one flow with conflicting records for 3 times. After that, if there is any conflict, it will trigger the manual flow.
GoDaddy configures parked A records that are tied to their free products. These records can only be removed once the associated product is deleted. However, when using Entri, those records will be removed automatically if they conflict with records sent through Entri's payload.
Squarespace
Squarespace does not allow automated replacement of existing DNS records. If a record already exists, Entri Connect will redirect you to manual setup.
Manual steps required:
Log in to the Squarespace DNS panel
Remove the conflicting record
Add the new DNS record provided by Entri
Example:
If www.yourdomain.com already has a CNAME record with host www, Entri cannot replace it automatically.
Cloudflare
Cloudflare allows enabling Proxy mode, but when enabled via Entri, it applies to all records created through Entri.
Amazon (Route 53)
Does not support separate hosted zones for subdomains
Passkey / security key (device MFA) login is not supported
Unexpected errors with certain login flows
MFA setup is mandatory
ArubaIT
DNS changes take up to 30 minutes to propagate
Records cannot be updated during propagation
CrazyDomains
Email verification may be required after a long period of inactivity
Premium DNS is required to update TXT and SRV records
DreamHost
Advanced protection plans require email verification on every login
Some services auto-create DNS records that cannot be removed, even if they conflict
Dynadot
Accounts may be locked while users continue login attempts
Repeated invalid credentials can trigger temporary lockouts
Gandi
Account verification is required
Some domains use legacy nameservers that do not support advanced DNS automation
GreenGeeks
Domains pointing to expired or missing hosting cannot be managed
DNS operations fail if the hosting is inactive
Hostinger
Social login credentials are not supported
Hover
TXT records longer than 255 characters are not supported
InMotion
Invalid passwords return errors only after MFA submission
Loocaweb
Wildcard DNS records are not supported
Namecheap
Device security key–based login is not supported
NameSilo
Domain Defender can block DNS record changes
One.com
MFA is handled through a companion mobile app
Mobile app MFA is not currently supported
OpenSRS
Wildcard DNS records are not allowed
OVH
Passkey login is not supported
CNAME records cannot use
@as the hostname
Papaki
Nameservers must be manually configured before DNS automation is possible
Porkbun
Hardware-based 2FA devices are not supported
Reg123
Domain Protection can prevent DNS changes
Registro
Switching between basic and advanced DNS has a cooldown period
Advanced DNS is required to configure records
Shopify
Passkey, social, and biometric logins are not supported
DNS cannot be managed for third-party domains
TXT records longer than 255 characters are not supported
Record values must be entered as FQDNs
Simply
Explicit permission from the account owner is required
Spaceship
USB security key–based login is not supported
Strato
Domain activation delay prevents DNS changes
Wildcard records are not supported
WebFamily
Password reset required after long inactivity
Migrated accounts may not be able to log in
Wild West Domains
Domain protection blocks DNS updates
Wix
Social logins are not supported
Wildcard records are not supported
WordPress.com
TXT records longer than 255 characters are not supported
Hosting.com
Domains without hosting require manual DNS setup
Some domains require admin-level login access
O2switch
Requires a cPanel password to be set
Limitations Not Yet Fully Handled
These issues are known but not fully mitigated yet:
Alibaba Cloud
Users attempt login via the Chinese version of the site, which is not supported
Porkbun
Repeatedly adding the same DNS record can trigger blocking
Namecheap
Domains using external hosting nameservers may not be discoverable
DNS cannot be managed if hosting is unavailable
GreenGeeks
Domain details API is unstable
Excessive requests may exceed timeout limits (30+ seconds)
Summary
While Entri Connect automates DNS management for a wide range of providers, provider-imposed constraints may require:
Manual DNS configuration
Account or security setting changes
Support assistance for advanced setups
If you encounter issues not listed here or need help configuring your domain, please contact Entri Support.