From 636612dcc9c012a058e061baf6df7f3d24d353a7 Mon Sep 17 00:00:00 2001 From: Dasha_Bugayova Date: Thu, 17 Sep 2026 01:14:03 +0200 Subject: [PATCH 1/9] Create white-label-endpoint.md --- .../white-label-endpoint.md | 88 +++++++++++++++++++ 1 file changed, 88 insertions(+) create mode 100644 docs/private-dns/server-and-settings/white-label-endpoint.md diff --git a/docs/private-dns/server-and-settings/white-label-endpoint.md b/docs/private-dns/server-and-settings/white-label-endpoint.md new file mode 100644 index 000000000..014e405cb --- /dev/null +++ b/docs/private-dns/server-and-settings/white-label-endpoint.md @@ -0,0 +1,88 @@ +--- +title: White-label endpoint (Account IP) +sidebar_position: 7 +--- + +Custom domains let partners offer AdGuard DNS under their own brand. On the **Enterprise** plan, that service can also run on an IP address that isn’t shared with any other AdGuard DNS client: an *Account IP*. Domains point to it through an A record, instead of the CNAME record used for standard custom domains. + +:::note + +**CNAME** points your domain to another domain (`dns.partner.com` → `cname.adguard-dns.com`). The real IP address is resolved through that second domain, so traffic goes through the shared infrastructure it serves. + +**A record** points your domain straight to an IP address (`dns.partner.com` → `203.0.113.10`). There’s no domain in between: the address your domain resolves to is the one that handles the traffic. + +::: + +Each account can have one *Account IP*, and you can point several domains to it. This isn’t the same as the dedicated IPv4 and IPv6 addresses used to identify devices: an *Account IP* is the address your custom domains resolve to. + +### How to get an Account IP + +To request an *Account IP*, contact your account manager or support team at [support@adguard-dns.io](mailto:support@adguard-dns.io). + +Once the address is assigned, the *White-label endpoint* block appears in *Account settings* → *Advanced settings* → *Custom domains*, showing your *Account IP address*. Until then, the block isn’t shown. + +![White-label endpoint *border](https://cdn.adtidy.org/content/kb/dns/enterprise/white_label_endpoint_en.png?) + +:::caution + +If your account moves off the Enterprise plan, the address becomes inactive and domains pointing to it stop working. Custom domains stay available on the **Team** plan, but only through a CNAME record — to bring the paused domains back, add them again as standard custom domains. + +The address itself stays reserved for your account, so if you return to the Enterprise plan, you get the same one back. + +::: + +### How to point a domain to your Account IP + +Setup follows the same steps as a standard custom domain, except you create an A record instead of a CNAME. Also, for DoH domains, the certificate isn’t issued automatically — you must upload your own. + + 1. In *Custom domains*, choose the protocol: *Add DoH domain* (for DNS-over-HTTPS) or *Add DoT/DoQ domain* (for DNS-over-TLS or DNS-over-QUIC). + + ![Choosing the protocol *border](https://cdn.adtidy.org/content/kb/dns/enterprise/account_ip_protocol_en.png) + + 1. Enter the domain you want to use (e.g., `dns.partner.com`) and click *Next*. You need access to this domain’s DNS management panel. + + ![Entering the domain *border](https://cdn.adtidy.org/content/kb/dns/enterprise/account_ip_domain_en.png) + + 1. The next screen shows the values for your DNS record: your domain under *Name (Host)* and your *Account IP* under *Value (Points to / IP address)*. Leaving this screen open, go to your DNS provider’s control panel and create an A record with those values. Don’t create a CNAME record — domains on an *Account IP* point to the address directly. + + ![DNS record values *border](https://cdn.adtidy.org/content/kb/dns/enterprise/a_record_en.png) + + 1. On the AdGuard DNS screen with the record values, click *Verify*. If the record hasn’t propagated yet or points somewhere else, verification fails. Check the record and try again in a few minutes. + + 1. Upload a TLS certificate. Certificates aren’t issued automatically for domains on an *Account IP*: + + - For **DoT/DoQ**, you upload a wildcard certificate (`*.partner.com`), same as for a standard custom domain. + - For **DoH**, you upload your own certificate too. This differs from the standard flow, where AdGuard DNS can generate one for you. + + Until you add a certificate, the domain shows the *No certificate* status and your customers can’t connect to it. + + ![Uploading a certificate *border](https://cdn.adtidy.org/content/kb/dns/enterprise/account_ip_certificate_en.png) + +:::note + +Renewal is on your side. You’ll get an email reminder before the certificate expires. When this happens, your domain will stop working until you upload a new certificate. + +::: + +### Existing custom domains and Account IP + +Domains you added before getting an *Account IP* aren’t moved to it automatically. They keep working through their CNAME record, as before. + +To move a domain over to your *Account IP*, start by deleting its CNAME record at your DNS provider — a domain can’t have both a CNAME and an A record at once. Then delete the domain in AdGuard DNS and add it again, following the steps above. + +:::caution + +Your customers won’t be able to use the domain between the moment you delete it and the moment the new setup is verified. + +::: + +### Limitations + +An *Account IP* changes the address your domain resolves to. A few things it doesn’t cover: + +- Account IP isn’t fully white-label at the network level. A WHOIS, RDAP, or ASN lookup of the IP address can still identify AdGuard as the provider of the underlying IP infrastructure. +- Reverse DNS can’t be customized, so a PTR lookup won’t return your domain. +- DNS server discovery (DDR) isn’t available on an *Account IP*. +- Certificates with the IP address in the SAN field aren’t supported, so your customers connect through the domain name rather than the address itself. +- Using your own IP range (BYOIP) isn’t supported, since the address is assigned by AdGuard. +- DNSCheck domains, used to verify a device’s DNS connection, still resolve through AdGuard’s infrastructure. From fa93e333b32a28b691f8b3873f95adfe24b8d79d Mon Sep 17 00:00:00 2001 From: Dasha_Bugayova Date: Thu, 17 Sep 2026 01:25:01 +0200 Subject: [PATCH 2/9] fixed Unordered list indentation --- .../white-label-endpoint.md | 24 +++++++++---------- 1 file changed, 12 insertions(+), 12 deletions(-) diff --git a/docs/private-dns/server-and-settings/white-label-endpoint.md b/docs/private-dns/server-and-settings/white-label-endpoint.md index 014e405cb..cbc25e824 100644 --- a/docs/private-dns/server-and-settings/white-label-endpoint.md +++ b/docs/private-dns/server-and-settings/white-label-endpoint.md @@ -15,7 +15,7 @@ Custom domains let partners offer AdGuard DNS under their own brand. On the **En Each account can have one *Account IP*, and you can point several domains to it. This isn’t the same as the dedicated IPv4 and IPv6 addresses used to identify devices: an *Account IP* is the address your custom domains resolve to. -### How to get an Account IP +## How to get an Account IP To request an *Account IP*, contact your account manager or support team at [support@adguard-dns.io](mailto:support@adguard-dns.io). @@ -31,30 +31,30 @@ The address itself stays reserved for your account, so if you return to the Ente ::: -### How to point a domain to your Account IP +## How to point a domain to your Account IP Setup follows the same steps as a standard custom domain, except you create an A record instead of a CNAME. Also, for DoH domains, the certificate isn’t issued automatically — you must upload your own. - 1. In *Custom domains*, choose the protocol: *Add DoH domain* (for DNS-over-HTTPS) or *Add DoT/DoQ domain* (for DNS-over-TLS or DNS-over-QUIC). +1. In *Custom domains*, choose the protocol: *Add DoH domain* (for DNS-over-HTTPS) or *Add DoT/DoQ domain* (for DNS-over-TLS or DNS-over-QUIC). ![Choosing the protocol *border](https://cdn.adtidy.org/content/kb/dns/enterprise/account_ip_protocol_en.png) - 1. Enter the domain you want to use (e.g., `dns.partner.com`) and click *Next*. You need access to this domain’s DNS management panel. +1. Enter the domain you want to use (e.g., `dns.partner.com`) and click *Next*. You need access to this domain’s DNS management panel. ![Entering the domain *border](https://cdn.adtidy.org/content/kb/dns/enterprise/account_ip_domain_en.png) - 1. The next screen shows the values for your DNS record: your domain under *Name (Host)* and your *Account IP* under *Value (Points to / IP address)*. Leaving this screen open, go to your DNS provider’s control panel and create an A record with those values. Don’t create a CNAME record — domains on an *Account IP* point to the address directly. +1. The next screen shows the values for your DNS record: your domain under *Name (Host)* and your *Account IP* under *Value (Points to / IP address)*. Leaving this screen open, go to your DNS provider’s control panel and create an A record with those values. Don’t create a CNAME record — domains on an *Account IP* point to the address directly. ![DNS record values *border](https://cdn.adtidy.org/content/kb/dns/enterprise/a_record_en.png) - 1. On the AdGuard DNS screen with the record values, click *Verify*. If the record hasn’t propagated yet or points somewhere else, verification fails. Check the record and try again in a few minutes. +1. On the AdGuard DNS screen with the record values, click *Verify*. If the record hasn’t propagated yet or points somewhere else, verification fails. Check the record and try again in a few minutes. - 1. Upload a TLS certificate. Certificates aren’t issued automatically for domains on an *Account IP*: +1. Upload a TLS certificate. Certificates aren’t issued automatically for domains on an *Account IP*: - - For **DoT/DoQ**, you upload a wildcard certificate (`*.partner.com`), same as for a standard custom domain. - - For **DoH**, you upload your own certificate too. This differs from the standard flow, where AdGuard DNS can generate one for you. + - For **DoT/DoQ**, you upload a wildcard certificate (`*.partner.com`), same as for a standard custom domain. + - For **DoH**, you upload your own certificate too. This differs from the standard flow, where AdGuard DNS can generate one for you. - Until you add a certificate, the domain shows the *No certificate* status and your customers can’t connect to it. + Until you add a certificate, the domain shows the *No certificate* status and your customers can’t connect to it. ![Uploading a certificate *border](https://cdn.adtidy.org/content/kb/dns/enterprise/account_ip_certificate_en.png) @@ -64,7 +64,7 @@ Renewal is on your side. You’ll get an email reminder before the certificate e ::: -### Existing custom domains and Account IP +## Existing custom domains and Account IP Domains you added before getting an *Account IP* aren’t moved to it automatically. They keep working through their CNAME record, as before. @@ -76,7 +76,7 @@ Your customers won’t be able to use the domain between the moment you delete i ::: -### Limitations +## Limitations An *Account IP* changes the address your domain resolves to. A few things it doesn’t cover: From 667b7f7d7e0029b022dacba6f2b6b880584539a3 Mon Sep 17 00:00:00 2001 From: Dasha_Bugayova Date: Thu, 17 Sep 2026 12:04:51 +0200 Subject: [PATCH 3/9] fixed --- docs/private-dns/server-and-settings/white-label-endpoint.md | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/docs/private-dns/server-and-settings/white-label-endpoint.md b/docs/private-dns/server-and-settings/white-label-endpoint.md index cbc25e824..4e75721d3 100644 --- a/docs/private-dns/server-and-settings/white-label-endpoint.md +++ b/docs/private-dns/server-and-settings/white-label-endpoint.md @@ -1,5 +1,5 @@ --- -title: White-label endpoint (Account IP) +title: White-label endpoint (Account IP address) sidebar_position: 7 --- @@ -19,7 +19,7 @@ Each account can have one *Account IP*, and you can point several domains to it. To request an *Account IP*, contact your account manager or support team at [support@adguard-dns.io](mailto:support@adguard-dns.io). -Once the address is assigned, the *White-label endpoint* block appears in *Account settings* → *Advanced settings* → *Custom domains*, showing your *Account IP address*. Until then, the block isn’t shown. +Once the address is assigned, the *White-label endpoint* block appears in *Settings* → *Advanced settings* → *Custom domains*, showing your *Account IP address*. Until then, the block isn’t shown. ![White-label endpoint *border](https://cdn.adtidy.org/content/kb/dns/enterprise/white_label_endpoint_en.png?) From 95b13c65ba56a83ec8d50d0c4d7366cb97ce571b Mon Sep 17 00:00:00 2001 From: Dasha_Bugayova Date: Thu, 17 Sep 2026 12:06:45 +0200 Subject: [PATCH 4/9] added address --- .../private-dns/server-and-settings/white-label-endpoint.md | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/docs/private-dns/server-and-settings/white-label-endpoint.md b/docs/private-dns/server-and-settings/white-label-endpoint.md index 4e75721d3..ce1ac2968 100644 --- a/docs/private-dns/server-and-settings/white-label-endpoint.md +++ b/docs/private-dns/server-and-settings/white-label-endpoint.md @@ -31,7 +31,7 @@ The address itself stays reserved for your account, so if you return to the Ente ::: -## How to point a domain to your Account IP +## How to point a domain to your Account IP address Setup follows the same steps as a standard custom domain, except you create an A record instead of a CNAME. Also, for DoH domains, the certificate isn’t issued automatically — you must upload your own. @@ -64,7 +64,7 @@ Renewal is on your side. You’ll get an email reminder before the certificate e ::: -## Existing custom domains and Account IP +## Existing custom domains and Account IP address Domains you added before getting an *Account IP* aren’t moved to it automatically. They keep working through their CNAME record, as before. @@ -80,7 +80,7 @@ Your customers won’t be able to use the domain between the moment you delete i An *Account IP* changes the address your domain resolves to. A few things it doesn’t cover: -- Account IP isn’t fully white-label at the network level. A WHOIS, RDAP, or ASN lookup of the IP address can still identify AdGuard as the provider of the underlying IP infrastructure. +- Account IP address isn’t fully white-label at the network level. A WHOIS, RDAP, or ASN lookup of the IP address can still identify AdGuard as the provider of the underlying IP infrastructure. - Reverse DNS can’t be customized, so a PTR lookup won’t return your domain. - DNS server discovery (DDR) isn’t available on an *Account IP*. - Certificates with the IP address in the SAN field aren’t supported, so your customers connect through the domain name rather than the address itself. From 54eabcf51d33fa9d73d7a5c4aafd658feaa7ba7d Mon Sep 17 00:00:00 2001 From: Dasha_Bugayova Date: Thu, 24 Sep 2026 10:55:30 +0200 Subject: [PATCH 5/9] fixed the screenshot --- docs/private-dns/server-and-settings/white-label-endpoint.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/docs/private-dns/server-and-settings/white-label-endpoint.md b/docs/private-dns/server-and-settings/white-label-endpoint.md index ce1ac2968..ffae258f2 100644 --- a/docs/private-dns/server-and-settings/white-label-endpoint.md +++ b/docs/private-dns/server-and-settings/white-label-endpoint.md @@ -21,7 +21,7 @@ To request an *Account IP*, contact your account manager or support team at [sup Once the address is assigned, the *White-label endpoint* block appears in *Settings* → *Advanced settings* → *Custom domains*, showing your *Account IP address*. Until then, the block isn’t shown. -![White-label endpoint *border](https://cdn.adtidy.org/content/kb/dns/enterprise/white_label_endpoint_en.png?) +![White-label endpoint *border](https://cdn.adtidy.org/content/kb/dns/enterprise/whitelabel_endpoint_en.png) :::caution From eb91fcb17134deade645e92a9ac5914d96b1a830 Mon Sep 17 00:00:00 2001 From: Elena Ter-Mikaelyan Date: Mon, 28 Sep 2026 09:34:00 +0400 Subject: [PATCH 6/9] Update docs/private-dns/server-and-settings/white-label-endpoint.md --- docs/private-dns/server-and-settings/white-label-endpoint.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/docs/private-dns/server-and-settings/white-label-endpoint.md b/docs/private-dns/server-and-settings/white-label-endpoint.md index ffae258f2..47878eec9 100644 --- a/docs/private-dns/server-and-settings/white-label-endpoint.md +++ b/docs/private-dns/server-and-settings/white-label-endpoint.md @@ -1,5 +1,5 @@ --- -title: White-label endpoint (Account IP address) +title: White-label endpoint (Account IP) sidebar_position: 7 --- From 574874baa5af446c61e0f6a64851234b8315ef20 Mon Sep 17 00:00:00 2001 From: Elena Ter-Mikaelyan Date: Mon, 28 Sep 2026 09:34:09 +0400 Subject: [PATCH 7/9] Update docs/private-dns/server-and-settings/white-label-endpoint.md --- docs/private-dns/server-and-settings/white-label-endpoint.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/docs/private-dns/server-and-settings/white-label-endpoint.md b/docs/private-dns/server-and-settings/white-label-endpoint.md index 47878eec9..aaf5b0ece 100644 --- a/docs/private-dns/server-and-settings/white-label-endpoint.md +++ b/docs/private-dns/server-and-settings/white-label-endpoint.md @@ -3,7 +3,7 @@ title: White-label endpoint (Account IP) sidebar_position: 7 --- -Custom domains let partners offer AdGuard DNS under their own brand. On the **Enterprise** plan, that service can also run on an IP address that isn’t shared with any other AdGuard DNS client: an *Account IP*. Domains point to it through an A record, instead of the CNAME record used for standard custom domains. +Custom domains allow partners to offer AdGuard DNS under their own brand. With the Enterprise plan, this service can run on a private IP address: this feature is called *Account IP*. Domains point to the *Account IP* through an A record instead of a CNAME record, which is used for standard custom domains. :::note From f635792d38c9c2c12b7b797a45f0dd2a51a6a111 Mon Sep 17 00:00:00 2001 From: Helen Date: Mon, 28 Sep 2026 09:36:28 +0400 Subject: [PATCH 8/9] remove *border --- .../server-and-settings/white-label-endpoint.md | 10 +++++----- 1 file changed, 5 insertions(+), 5 deletions(-) diff --git a/docs/private-dns/server-and-settings/white-label-endpoint.md b/docs/private-dns/server-and-settings/white-label-endpoint.md index aaf5b0ece..3caa6d678 100644 --- a/docs/private-dns/server-and-settings/white-label-endpoint.md +++ b/docs/private-dns/server-and-settings/white-label-endpoint.md @@ -21,7 +21,7 @@ To request an *Account IP*, contact your account manager or support team at [sup Once the address is assigned, the *White-label endpoint* block appears in *Settings* → *Advanced settings* → *Custom domains*, showing your *Account IP address*. Until then, the block isn’t shown. -![White-label endpoint *border](https://cdn.adtidy.org/content/kb/dns/enterprise/whitelabel_endpoint_en.png) +![White-label endpoint](https://cdn.adtidy.org/content/kb/dns/enterprise/whitelabel_endpoint_en.png) :::caution @@ -37,15 +37,15 @@ Setup follows the same steps as a standard custom domain, except you create an A 1. In *Custom domains*, choose the protocol: *Add DoH domain* (for DNS-over-HTTPS) or *Add DoT/DoQ domain* (for DNS-over-TLS or DNS-over-QUIC). - ![Choosing the protocol *border](https://cdn.adtidy.org/content/kb/dns/enterprise/account_ip_protocol_en.png) + ![Choosing the protocol](https://cdn.adtidy.org/content/kb/dns/enterprise/account_ip_protocol_en.png) 1. Enter the domain you want to use (e.g., `dns.partner.com`) and click *Next*. You need access to this domain’s DNS management panel. - ![Entering the domain *border](https://cdn.adtidy.org/content/kb/dns/enterprise/account_ip_domain_en.png) + ![Entering the domain](https://cdn.adtidy.org/content/kb/dns/enterprise/account_ip_domain_en.png) 1. The next screen shows the values for your DNS record: your domain under *Name (Host)* and your *Account IP* under *Value (Points to / IP address)*. Leaving this screen open, go to your DNS provider’s control panel and create an A record with those values. Don’t create a CNAME record — domains on an *Account IP* point to the address directly. - ![DNS record values *border](https://cdn.adtidy.org/content/kb/dns/enterprise/a_record_en.png) + ![DNS record values](https://cdn.adtidy.org/content/kb/dns/enterprise/a_record_en.png) 1. On the AdGuard DNS screen with the record values, click *Verify*. If the record hasn’t propagated yet or points somewhere else, verification fails. Check the record and try again in a few minutes. @@ -56,7 +56,7 @@ Setup follows the same steps as a standard custom domain, except you create an A Until you add a certificate, the domain shows the *No certificate* status and your customers can’t connect to it. - ![Uploading a certificate *border](https://cdn.adtidy.org/content/kb/dns/enterprise/account_ip_certificate_en.png) + ![Uploading a certificate](https://cdn.adtidy.org/content/kb/dns/enterprise/account_ip_certificate_en.png) :::note From 58c7148e66fe89dfb9da54c43bb57f0bf5a8c12e Mon Sep 17 00:00:00 2001 From: Helen Date: Mon, 28 Sep 2026 11:01:26 +0400 Subject: [PATCH 9/9] return "address" --- docs/private-dns/server-and-settings/white-label-endpoint.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/docs/private-dns/server-and-settings/white-label-endpoint.md b/docs/private-dns/server-and-settings/white-label-endpoint.md index 3caa6d678..ae304c13f 100644 --- a/docs/private-dns/server-and-settings/white-label-endpoint.md +++ b/docs/private-dns/server-and-settings/white-label-endpoint.md @@ -1,5 +1,5 @@ --- -title: White-label endpoint (Account IP) +title: White-label endpoint (Account IP address) sidebar_position: 7 ---