Latest Posts

View All Posts →
Stay in the Loop

No spam. No data selling. Just useful updates.

Client Portal

Manage your services, tools, and account.

Client Login

 

Domains & DNS

Registered in your name. Renewals tracked. Records handled.

A sage key resting on an open navy platform tilted toward the viewer, with a slate signpost behind, representing a domain held in your name and records pointed where you choose.

Your domain is your asset

The registration says your name, not ours. We operate the records; we do not hold them . That distinction matters most on the day you want to leave, which is exactly when a domain sitting in someone else's account becomes a problem.

Registration In your name, with you as the legal owner
Renewals Watched, so nothing lapses quietly
DNS records Managed for you, changes staged rather than live-edited
Transfers We handle the move in, and the move out if it ever comes
Subdomains Set up as needed for mail, staging or apps
Included from All plans

The cost of forgetting.

An expired domain takes the website and the email with it, and recovery can cost more than years of renewals. It is a small thing to watch and an expensive thing to miss.

We do not know who has our domain.

That happens more than you would think, usually when the site builder registered it themselves. We can find out and, if you own it, get it back into your name.

Can we keep our current registrar?

Yes. We will manage the records where they are. Moving is a convenience, not a requirement.

Do we get the domains included, or is it extra?

Executive covers up to four domains with renewals, Business covers two, and Basic covers one. The Assurance plan allows you to add domains upon request at our trade rate rather than retail. If you already hold names elsewhere, we can leave them where they are and still manage the records.

What is DMARC, and do we need it?

DMARC is a DNS record that tells other mail servers what to do with email claiming to be from you that fails authentication. Without it, anyone can send mail in your name and it will land in inboxes normally. We start it in reporting mode so we can see every system legitimately sending as you, then tighten it to quarantine or reject once nothing legitimate is left out. Turning enforcement on blind is how businesses end up blocking their own invoices.

Why put a domain behind Cloudflare?

It puts a filtered edge between the public internet and your server. Junk traffic and denial-of-service floods are absorbed before they reach you, certificates are issued and renewed automatically, pages are cached closer to your visitors, and your real server address stops being public. For most sites it is also the least expensive speed improvement available, which search engines measure directly.

How long does moving a domain take?

The transfer itself takes a few days at the registrar, nothing needs to go down while this happens. We lower the TTL on your records first, so the actual cutover takes minutes, keeps mail flowing throughout, and only change nameservers once the destination is confirmed as working. You should not notice it as a customer-facing event.

What the domains actually cost you.

We register at trade rates rather than retail, so a domain acquired through us costs less than a domain bought elsewhere . Domains and renewals are included on Basic, Business, and Executive plans.

Plan Domains included Renewals
Executive Up to 4 Included
Business 2 Included
Basic 1 Included
Assurance Added on At our trade rate

Four domains matters more than it sounds. Most businesses end up holding more names than they set out to: the common misspelling, the old trading name, the .net someone bought defensively. If this sounds like you visit multi-location  . Full detail on service plans.

DNS is the part nobody sees until it breaks

Your DNS determines where your website lives, where your mail is delivered, and which servers are allowed to send your emails. It is a handful of small text records, and every one of them is a single point of failure.

Nameservers The primary address book for your domain name. Points internet traffic to the correct records using actively monitored servers rather than legacy setups.
A and CNAME records  Directs where your website resolves. Changes are staged and TTLs are lowered in advance so site cutovers take minutes, not days. .
MX records Controls mail delivery. If misconfigured, incoming emails silently drop with no error. See secure email.
DNSSEC Signs your DNS answers to prevent tampering, forgery, or redirected traffic. Enabled upon request if supported by your registrar.
CAA records Identifies which certificate authorities are authorized to issue an HTTPS certificate for your domain, so nobody else can get one. Set upon request.
Registrar lock  Prevents unauthorized domain transfers by blocking move requests until explicitly unlocked by you.

Every DNS update is planned, documented, and tested. No guesswork, and no high-risk Friday deploys.

Security at the domain level

Your domain sits in front of everything else you own, so it gets a dedicated layer of protection. Where appropriate, domains run behind Cloudflare to place a filtered edge between the public internet and your server. .

  • Denial-of-service absorption filters a flood of junk traffic from taking your site down.
  • Certificates issued and renewed automatically  prevents a full-page browser warning
  • Origin Cloaking hides your actual server IP address so it cannot be directly targeted or scanned by attackers.
  • Caching at the edge the least expensive speed improvement available for users and search engine rankings.
  • WHOIS privacy masks domain registration data so personal contact info and home addresses remain private.

This works alongside backups and security and where you have your own machine, dedicated hosting.

Whether the world trusts your email

Three DNS records dictate whether your mail lands in the inbox or the junk folder. Most businesses have none of them configured correctly, only finding out when a client asks where their invoice went - and usually blaming the wrong provider.

Record What it says What goes wrong without it
SPF Which servers are allowed to send mail as your domain. Anyone can pretend to be you. Recipients lose trust.
DKIM Signs each message so it can be proved as unaltered in transit. Mail arrives unsigned and gets marked as suspicious.
DMARC Tells receivers what to do with mail that fails the first two, and sends you reports Forged mail in your name is delivered to your clients.

When mail comes under management, we enforce SPF first, set up DKIM where your provider issues keys, and launch DMARC in reporting mode - tightening policies only after every legitimate sender is accounted for . It's not glamorous work, but it's the difference between your emails landing in the inbox or quietly dropping into oblivion.

See more details on secure email; the whole picture is on managed services.

Not sure who actually owns your domain?

We can look into that for you, and give you the details.

Check what I actually own See the plans

Server Managed hosting Domain DNS records Security Privacy Backups Restore Uptime monitoring Email Deliverability Inbox Chat support Voice agent Reviews Review replies Your team Articles Publishing Social posting Schedule Images Newsletters Search visibility AI answers Reporting Digital footprint Response time Automation Workflow Knowledge base Checks Locations Billing