CNAME records across every zone in a Cloudflare account. Point it at a target hostname and it lists every matching record; give it a replacement and it updates them all in place. Useful when a backend, CDN endpoint or load balancer is renamed and dozens of zones still point at the old name.
- Authenticates against the Cloudflare API with the given API token.
- Lists every zone the token has access to.
- Fetches the
CNAMErecords of all zones concurrently, one goroutine per zone. - Selects the records whose target matches
-target-url— either as an exact match (-full-url) or as a suffix of the record's target (the default). - Prints the matching records grouped by zone. If no
-new-urlis given, it stops here, so the tool is a read-only search by default. - If
-new-urlis given, it rewrites each matching record and prints its before/after state. In suffix mode only the matched suffix is replaced, so the record's own prefix is preserved:app.old.example.combecomesapp.new.example.com.
Build or download the cfcname binary, then run it with the required flags.
List every record across all zones that points at something ending in old.example.com:
./cfcname -token 'CF_API_TOKEN' -target-url old.example.comRewrite them to new.example.com, keeping each record's own prefix:
./cfcname -token 'CF_API_TOKEN' -target-url old.example.com -new-url new.example.comMatch and replace one exact target instead of a suffix:
./cfcname -token 'CF_API_TOKEN' -full-url -target-url lb1.old.example.com -new-url lb2.new.example.com| Flag | Short | Default | Description |
|---|---|---|---|
-token |
-t |
(required) | Cloudflare API token |
-target-url |
-u |
(required) | Target hostname to look for in CNAME records |
-new-url |
-n |
(empty) | New target to write. Leave empty to only list the matching records |
-full-url |
-f |
false |
Match -target-url as the record's full target instead of a suffix |
Note: the API token needs
Zone:ReadandDNS:Editpermissions on every zone you want it to touch. Run the tool without-new-urlfirst and check the listed records — with-new-urlit updates everything it matched, across every zone, with no further confirmation.
To build the binary:
go build -o bin/cfcname .The resulting binary will be in the bin folder.
cfcname is licensed under GPL-3.0-only. See LICENSE file for details.