Skip to content
Growth
6 min read

Choosing domains for indie apps: .io.vn at Mắt Bão vs .com

Why my seven iOS apps use .io.vn domains from Mắt Bão, the three DNS records that point them at Vercel, and what to check before a domain ships in a build.

Cover: choosing .io.vn or .com domains for indie apps hosted on Vercel
On this page
  1. Starting on vercel.app, and why that stops being enough
  2. Why .io.vn and not .com
  3. The DNS records: A, CNAME, and nothing else
  4. Search Console: the TXT record
  5. One constant for the site, one for the app
  6. Takeaways

Every app I ship needs a website before App Review will look at it: a privacy policy, terms, a support page, and ideally a landing page that explains the app. For a long time those sites lived on whatever hostname Vercel handed me. Today all seven of my apps have their own domain, and every one of them ends in .io.vn: lockboxy.io.vn, minivid.io.vn, ringsy.io.vn and the rest. The showcase that lists them sits on my personal domain, apps.vanthuongdao.id.vn.

This post is about how I got there: why .io.vn and not .com, the exact DNS records I add at Mắt Bão to point a domain at Vercel, the Search Console record, and the two mistakes that taught me to treat a domain as part of the app, not just part of the website.

Starting on vercel.app, and why that stops being enough

Each landing is a small Next.js project on Vercel. A new project gets a *.vercel.app alias for free, and that is what the first App Store submissions pointed at. It works, but the names are not yours. When I set up the site for what was then called Toolbox (now Lockboxy), toolbox.vercel.app was already taken in Vercel's global namespace, so the production alias became toolbox-vanthuongdao.vercel.app. Linkeeper was luckier: linkeeper-landing.vercel.app was free. Later I moved several sites to shorter aliases like minivid-app.vercel.app and talkzy-app.vercel.app, which is a nicer URL but still somebody else's namespace.

There is also a less obvious problem. Vercel's deployment protection on one project was set to all_except_custom_domains. That setting protects every .vercel.app hostname, including the production alias, behind a Vercel login. If App Review had opened the privacy link, it would have landed on a login wall instead of a policy. I switched it to protect previews only. If you serve your App Store URLs from a .vercel.app host, check this setting. A custom domain avoids the problem completely, because a custom domain is never behind that wall.

Why .io.vn and not .com

I would have liked .com names. They are the default everyone types. But short, pronounceable app names are mostly gone. When I checked on 2026-09-22, minivid.com had been registered since 2003 and minivid.app since February 2026, both by other people. minivid.io.vn was not delegated at all, so it was free to register. Lockboxy had already gone the same way in July.

Comparison of .io.vn and .com for the same app name
Same name, two endings: what was actually free

What I weighed:

.io.vn.com
Short app namesstill availablemostly registered years ago
What it signalsa maker based in Vietnamneutral, global
Checking availabilityDNS delegation (no RDAP)RDAP over HTTPS
Registrara Vietnamese registrar such as Mắt Bãoany

For a solo developer in Ho Chi Minh City, the Vietnamese signal is fine, honestly even a plus. The apps are localized into ten languages, but the domain is just where the legal pages and the landing live. A user who taps "Privacy Policy" in Settings does not care about the ending. They care that the page loads.

One practical trap when checking availability. On my machine, port 43 is blocked, so whois times out, and a timeout looks exactly like "taken" if you are not careful. Use RDAP over HTTPS for generic endings. .io.vn has no RDAP service, so for that one I just check whether the name is delegated:

bash
# No NS records back → nobody has delegated the name yet
dig +short NS minivid.io.vn

The DNS records: A, CNAME, and nothing else

I buy the domains at Mắt Bão and keep the DNS there. Vercel offers to take over the nameservers, but I prefer adding records at the registrar. That way any other records in the zone (email, for example) stay where they are, and Vercel only gets the two names it needs.

After adding the domain (apex and www) to the Vercel project, these are the records I add in Mắt Bão's DNS panel:

dns
; lockboxy.io.vn zone at the registrar
@     A      76.76.21.21
www   CNAME  cname.vercel-dns.com.

The A record points the apex at Vercel's IP. The CNAME hands www to Vercel, which then redirects it to whichever of the two you marked as primary. Once Vercel sees the records, it issues the HTTPS certificate on its own. For Lockboxy I did not consider it done until the site loaded over HTTPS on the new name. My commit message from 2026-07-12 says "verified live over HTTPS", and I still check the same way.

DNS records at Mắt Bão pointing a domain at Vercel and Search Console
The whole setup: two records for Vercel, one for Search Console

On 2026-10-01 I moved Minivid, Ringsy, Talkzy, Baton and Stampzy at once, all with the same two records at Mắt Bão, and the showcase moved to its id.vn subdomain the same day.

Search Console: the TXT record

A new domain is a new site as far as Google is concerned. A Domain property in Search Console covers the apex, www, and both http and https in one go. It is verified with one more record in the same zone:

dns
@     TXT    "google-site-verification=…"

Copy the value from Search Console exactly (I will not paste mine here), wait for it to propagate, then press Verify. The record has to stay in the zone. Delete it and the property eventually loses its verification.

The Lockboxy landing also supports the other method, a meta tag for a URL-prefix property. It reads the token from an environment variable instead of the code, so adding or rotating one is a Vercel setting, not a commit:

ts
verification: {
  ...(process.env.GOOGLE_SITE_VERIFICATION && {
    google: process.env.GOOGLE_SITE_VERIFICATION,
  }),
},

The same block carries Bing's msvalidate.01 tag. Bing matters beyond Bing itself, because ChatGPT search runs on its index.

Search Console earned its place quickly. On 2026-09-22 it reported that Google had ignored the canonical of Lockboxy's /vi homepage and chosen the bare domain, a URL that only redirects. The fix was declaring an x-default hreflang. I would not have known without the console.

One constant for the site, one for the app

Every landing has a single SITE_URL in src/lib/site.ts. Canonical URLs, hreflang alternates, the sitemap, OpenGraph tags, JSON-LD and the llms.txt files all derive from it. Moving a site to its domain is a one-line diff plus a redeploy:

ts
export const SITE_URL = "https://minivid.io.vn";

The app is the harder half. Each app builds its privacy, terms and support links from its own SITE_URL (<SITE_URL>/<lang>/<page>), and that value ships inside a binary that users keep for months. So when the landings moved on 2026-10-01, the apps did not. Their links still point at the old vercel.app host, and that host keeps serving the same site. Never remove the old alias while a build in the wild still uses it.

What changes when a site moves to a new domain
The landing moves with one deploy; links inside a shipped build do not

The opposite mistake is worse. Stampzy's first build put stampzy.app into the app, a domain I had never registered. The privacy, terms and support links in build 1 led nowhere. Build 2 pointed them back at the Vercel alias that actually existed, and the .io.vn domain came later.

Only put a domain into an app build after it resolves and serves the page over HTTPS. A link in a shipped binary is very hard to take back.

My portfolio went through the same move earlier. It started at vanthuongdao.vercel.app, and in April its fallback URL became www.vanthuongdao.id.vn. Its site.ts resolves an explicit env override first, then Vercel's production URL, and only then the hardcoded fallback.

Takeaways

  • If the .com for your app name is gone, .io.vn is a reasonable home for a Vietnamese indie developer. It is short, it is yours, and users only see it on legal pages and the landing.
  • Keep DNS at the registrar and add records: A @ 76.76.21.21, CNAME www cname.vercel-dns.com, plus a TXT for Search Console. Your other records stay put.
  • Check availability with RDAP, or with dig NS for .io.vn. A whois timeout is not an answer.
  • One SITE_URL on the site, one in the app. Move the site freely, but keep every old host serving until no build uses it, and never ship a domain you have not bought.

All seven landings are linked from apps.vanthuongdao.id.vn.

  • #Domains
  • #DNS
  • #Vercel
  • #Search Console
  • #SEO
ShareXLinkedInFacebook
Dao Van Thuong

Mobile and fullstack engineer in Ho Chi Minh City. I build and ship my own indie iOS apps — Lockboxy, Linkeeper, Minivid, Ringsy, Talkzy, Baton and Stampzy.