Domain & email terms, in plain English.
If you've ever been told "just add an MX record" and silently panicked, this is for you. Every term we use in checkout, in your account, or in our help center — defined by the people who actually configure them for a living.
-
A record DNS
The DNS record that maps a domain or hostname to a single IPv4 address.
-
AAAA record DNS
The DNS record that maps a domain or hostname to an IPv6 address.
-
AGP (Auto-Renew Grace Period) Policy
The 45-day window after a domain expires during which the original owner can still renew at the regular price.
-
CAA record Security
A DNS record that restricts which Certificate Authorities can issue SSL certificates for your domain.
-
CNAME record DNS
A DNS alias that says "this hostname points to that other hostname".
-
CSR (Certificate Signing Request) Security
A file you generate on your server containing your public key + identity info, which a Certificate Authority signs to produce an SSL certificate.
-
DKIM (DomainKeys Identified Mail) Email
A cryptographic signature on every outgoing email that proves the message hasn't been tampered with in transit.
-
DMARC (Domain-based Message Authentication, Reporting and Conformance) Email
A policy layer on top of SPF and DKIM that tells receivers what to do with messages that fail authentication.
-
DNS (Domain Name System) DNS
The phone book of the internet — translates human-readable domain names into IP addresses computers route to.
-
DV SSL (Domain Validated) Security
The most common type of SSL certificate. Issued in minutes after proving you control the domain. Suitable for 90% of sites.
-
EPP code (Auth code / Transfer code) Domains
A short alphanumeric secret used to authorize transferring a domain from one registrar to another.
-
ERRP (Expired Registration Recovery Policy) Policy
ICANN policy requiring registrars to send pre- and post-expiration renewal notifications to registrants.
-
EV SSL (Extended Validation) Security
The most rigorous SSL validation tier. Mostly relevant for banks and financial institutions; lost its visual browser distinction in 2019.
-
gTLD (generic Top-Level Domain) Domains
A TLD not tied to a country. Examples: .com, .org, .net, .io, .ai, .app, .shop.
-
HSTS (HTTP Strict Transport Security) Security
An HTTP header that tells browsers to ONLY connect to this site over HTTPS, never plain HTTP, for the next N seconds.
-
ICANN (Internet Corporation for Assigned Names and Numbers) Policy
The non-profit that coordinates the global domain name system and accredits registrars.
-
IDN (Internationalized Domain Name) Domains
A domain name containing non-ASCII characters — like Cyrillic, Arabic, Chinese, or accented Latin.
-
MX record DNS
A DNS record that says "here's where to deliver email addressed to anything @yourdomain.com".
-
Nameserver DNS
A server that holds DNS records for one or more domains and answers DNS queries about them.
-
NS record DNS
The DNS record that tells the internet which nameservers are authoritative for a domain.
-
OV SSL (Organization Validated) Security
An SSL certificate that includes verified organization information — the CA checks your company exists in business registries.
-
DNS propagation DNS
The time it takes for a DNS change to be visible to everyone on the internet — usually minutes to a few hours.
-
Punycode Domains
The encoding scheme that lets DNS handle Unicode characters by translating them to ASCII.
-
RDAP (Registration Data Access Protocol) Policy
The modern HTTPS-based replacement for the legacy WHOIS protocol. JSON instead of plain text, with proper authentication.
-
Redemption Period (RGP) Policy
A 30-day post-expiration window during which the original owner can recover an expired domain — for a hefty fee.
-
Registrant Domains
The legal owner of a registered domain — the person or company on file with the registry.
-
Registrar Domains
A company accredited by ICANN to sell domain registrations to end users on behalf of registries.
-
Registry Domains
The organization that operates a specific TLD and maintains its master database of registered domains.
-
SNI (Server Name Indication) Security
A TLS extension that lets a single server host multiple SSL certificates — one per domain — on the same IP address.
-
SPF (Sender Policy Framework) Email
A DNS TXT record listing which mail servers are authorized to send email on behalf of your domain.
-
SRV record DNS
A DNS record that locates specific services on a domain — like which server to talk to for SIP, XMPP, or Microsoft 365 autodiscover.
-
TTL (Time To Live) DNS
How long DNS resolvers cache a record before re-asking the authoritative nameservers.
-
TXT record DNS
A DNS record that holds arbitrary text. Used by SPF, DKIM, DMARC, and domain-verification services.
-
UDRP (Uniform Domain-Name Dispute-Resolution Policy) Policy
The ICANN policy that lets trademark holders take a domain from a cybersquatter through arbitration instead of court.
-
URS (Uniform Rapid Suspension) Policy
A fast, cheap alternative to UDRP for clear-cut cybersquatting cases — suspends the domain rather than transferring it.
-
WHOIS Policy
A public directory of who owns each registered domain. Often abbreviated as the protocol used to look it up.