Domains, DNS & SSL
Domains and subdomains
Your primary domain was set when the account was created and cannot be changed. On the Domains page you can add:
- addon domains (
another-site.com) — served from their own folder in your home,another-site.com/by default; - subdomains of any of your domains
(
shop.example.com) — also served from their own folder.
For each domain you choose:
- Document root — a folder inside your home; it is
created if missing. Paths cannot leave your home, contain
.., or be insidemail/,tmp/or.ssh/. - www alias — whether
www.<domain>serves the same site. On by default for top-level domains, off for subdomains. - PHP version — per domain; see PHP.
You cannot add a domain that already exists on the server or that belongs to another account (including subdomains of it), nor a subdomain of the server's own hostname. The account limit is normally 10 domains.
Removing a domain removes its web configuration and certificate but keeps the files in your home. A domain with mailboxes or forwarders cannot be removed until those are deleted.
DNS records
The DNS page lists, per domain, the records to create at your registrar or DNS provider, each with a live check against public resolvers:
| Record | Name | Value | Purpose |
|---|---|---|---|
| A | @ and www |
server IPv4 | website |
| AAAA | @ and www |
server IPv6 | website (only if shown; do not add an AAAA record pointing elsewhere) |
| MX | @ |
the server hostname, priority 10 | incoming mail |
| TXT | @ |
v=spf1 a:<server hostname> ~all |
SPF — tells receivers the server may send for your domain |
| TXT | mp1._domainkey |
the DKIM public key shown on the page | DKIM — signs outgoing mail |
| TXT | _dmarc |
v=DMARC1; p=none; rua=mailto:postmaster@<domain> |
DMARC — a safe starting policy |
| CNAME | autoconfig, autodiscover |
the server hostname | lets mail apps find the mail settings automatically (an A record to the server's address works too) |
| SRV | _imaps._tcp, _pop3s._tcp,
_submission._tcp, _autodiscover._tcp |
0 1 993 <server hostname> etc., as shown |
same, for apps that look up service records |
If your domain already has an SPF record, the page shows how to merge the server into it rather than adding a second one (two SPF records are invalid).
DNS changes take from minutes to a day to propagate; the checks turn green on their own.
When your host manages DNS
If your hosting provider publishes DNS from the panel, the DNS page
is a zone editor instead of a checklist: point your
domain at the nameservers shown at the top (at your registrar), and
everything else is done for you. The records the server needs
(addresses, www, mail, DKIM, autoconfig) are marked
automatic and follow your settings: assign a different address
or turn www off and the zone changes with it. Add your own
records below the table (verification TXT records, a subdomain hosted
elsewhere, an external mail service): name @ means the
domain itself, shop means
shop.<your domain>. MX values look like
10 mail.example.com, SRV like
0 5 5060 sip.example.com, CAA like
0 issue letsencrypt.org; TXT is the text without
quotes.
To change an automatic record, unlock it first; it then stays as you set it until you lock it again. Records marked external were created outside the panel; editing or deleting one takes it over. A subdomain's records live in the zone of its parent domain. If the provider could not be reached, the page says so and shows the last known records; publish now retries.
Pause page
If your site exceeds the resource limits of your plan, the server
pauses it for a few minutes and shows visitors a plain "temporarily
paused" page. Pause page on the Domains page lets you
replace that page per domain with your own HTML: a short note, your
phone number, a link to your social media, anything that helps a
visitor. It is a static file served without PHP, so it cannot slow the
recovery down; inline CSS and JavaScript are fine, but images and fonts
must be embedded as data: URLs or hosted elsewhere, because
the site's own URLs answer 503 while it is paused. Preview
opens it in a new tab, Back to the standard page removes it.
The page is not used when the hosting provider suspends an account.
SSL certificates
Certificates come from Let's Encrypt and are fully automatic:
- When you add a domain (or fix its DNS), the server checks that the
domain — and
www.if enabled — resolves to this server. Every A and AAAA record must point here; a leftover AAAA record at your old host blocks issuance. - Names that point here are requested immediately;
wwwis added later automatically if it starts pointing here. - The server retries every hour while a domain is pending, and renews certificates before they expire.
The SSL column shows the state:
| State | Meaning |
|---|---|
pending_dns |
the domain does not point at this server yet (the DNS page shows what the resolvers return) |
issuing |
a request is in progress |
active (expires …) |
HTTPS is live; HTTP redirects to HTTPS |
failed (reason) |
Let's Encrypt refused; fix the reason and click Retry |
Until a certificate exists the site is served over plain HTTP only.