Domains

Domains: Where to Start

Everything you can do with a domain name at KapsuleHost, and which guide to read for each job.

A domain is the name people type to reach you. Kapsule is a domain registrar as well as a host, so you can register a new name, bring an existing one across, run its DNS, and point it at a website or a mailbox without leaving the panel. This page is the map.

The Two Things People Confuse

Almost every domain support question comes down to mixing up these two, so it is worth being precise before anything else.

Registration is who holds the name. It has an expiry date, a registrar, contact details, and a lock. If registration lapses, the name stops being yours and nothing else matters.

DNS is where the name points. It is a set of records, and it can be run by a completely different company from the one you registered with. Changing your DNS records does not change who owns the domain, and transferring a domain between registrars does not by itself change where it points.

A domain registered at Kapsule can use someone else's DNS. A domain registered elsewhere can use Kapsule's DNS. Both are normal. When you are troubleshooting, work out which of the two you are actually looking at.

Getting a Domain Onto Your Account

There are three routes, and they are not interchangeable.

Register a new one. Go to Domains in the sidebar and search for the name you want. Registration is immediate once payment clears, and a domain registered through Kapsule is set up with our nameservers, an A record for the bare domain and for www pointing at your hosting, a working MX record so mail can arrive, and a starter SPF record. See Adding and Connecting Your Domain.

Transfer one in. Move an existing registration to Kapsule so you manage it in one place. You need the domain unlocked at the current registrar and its EPP auth code. See EPP Auth Codes for how to get one, and Transferring a Domain In for the full sequence.

Point one here without transferring it. Leave the registration where it is and just change the nameservers to ours. This is the fastest way to get a site live and it is fully supported. See Nameservers.

If you are in a hurry to launch, point the nameservers first and transfer the registration later. Transfers can take several days at the registry; a nameserver change is usually visible within an hour.

Running Your DNS

Open Domains, click the domain, then the DNS tab. That is the record editor for everything the domain resolves to.

The records you will touch most often:

RecordWhat it doesGuide
ASends web traffic to an IPv4 addressDNS Basics
CNAMEPoints one name at another nameCNAME Records
MXSays which server accepts your emailMX Records
TXTCarries SPF, DKIM, DMARC and ownership proofsSPF, DKIM and DMARC

Two things about DNS that catch people out. First, a change is live on our nameservers in seconds, but resolvers elsewhere hold their cached copy until its TTL expires, which is what "propagation" actually means. Second, we deliberately do not overwrite your own mail records: if you already run MX, SPF, DKIM or DMARC for the domain, adding services here will not silently replace them.

For proving ownership to Google, Microsoft or anyone else who asks for a TXT record, see Domain Verification Records.

Security and Lifecycle

Domains have a lifecycle that runs independently of your hosting, and the failure modes are unforgiving because they are enforced by the registry, not by us.

  • Renewals and expiry. Know your expiry date and keep auto-renew on. See Renewals and Expiry.
  • Registrar lock. On by default. It blocks unauthorised transfers away. Turn it off only when you are deliberately transferring out.
  • WHOIS privacy. Replaces your personal contact details in the public record where the registry allows it. See WHOIS Privacy.
  • Contact details. Registries require accurate contacts, and some verify the email address. See Contact Details.
  • DNSSEC. Cryptographically signs your DNS answers. Real protection, and genuinely risky to switch off in the wrong order. See DNSSEC.

Never remove DNSSEC signing at the DNS side while the DS record still exists at your registrar. Resolvers will refuse every answer for the domain and the whole thing goes dark. Remove the DS record at the registrar first, confirm it has cleared from the parent zone, and only then unsign.

New Zealand Domains

.nz names have their own registry rules that differ from the generic TLDs: different transfer mechanics, different expiry behaviour, and eligibility conditions on some second levels. If you hold a .co.nz, .net.nz, .org.nz or a second-level .nz, read New Zealand Domain Rules before you plan anything time-sensitive.

Leaving

Transferring away is a supported operation, not a fight. Unlock the domain, get the auth code from the panel, and start the transfer at the gaining registrar. See Transferring a Domain Out.

Every Domains Guide

Getting started

DNS

Lifecycle and admin

Security

When something is wrong

Still need help?

Email us at support@kapsulehost.com or open a chat in KPanel.

Open KPanel