Addresses vs Names · Intermediate · 20 minutes
How to connect to a VPS with SSH — Connect to the Address, Not the Name
Halfway through a migration the hostname points at the old server, and every ssh session you open lands on the machine you are trying to leave.
The short answer
Use the IP address for administration, especially while a name is in motion. A hostname resolves to wherever DNS currently says, so during a migration or a delegation change the same ssh command can reach two different machines on two different days — and you will not be told which one you got.
Collect the three details from the provisioning email — address, username, port — connect once by IP, then generate a key pair, install the public key, and turn password authentication off.
Twenty minutes at intermediate level. The name-related parts, host keys and reverse DNS, are the ones worth reading twice.
By the Hosting & Domains team · Reviewed 24 August 2026
Intermediate
Experience assumed
5
Stages in the guide
Free
Support cost
Proven
Checked on our platform
This page separates two things that are easy to conflate: the machine, which has an address, and the name, which is a record pointing at an address and can be changed by anybody with the right login.
Administration belongs to the machine. Serving the public belongs to the name. Keeping those apart is what stops a migration turning into an afternoon of confusion.
Nothing here changes a record unless you choose to add the reverse DNS entry at the end, which is optional but matters if the machine will ever send mail.
The three details, and why the first one is an address
The server's IP address, the username — root on a fresh build — and the port, 22 unless it has been changed. All three arrive in the provisioning email and nothing else is needed for a first connection.
Use the address rather than a hostname. During a migration, a delegation change, or any period when a name is being repointed, the hostname is a moving target and the address is not. Administer the machine; publish the name.
Host keys, and the warning worth stopping for
The first connection asks you to accept a host fingerprint, and your client stores it against whatever you typed — address or hostname. Connect by address and by name and you will be asked twice, for the same machine, because the client is keying on the string rather than on the server.
A changed fingerprint on a target you have used before is a warning to stop at. It means either the server was rebuilt, or the name now resolves somewhere else. Both are worth knowing about before you type a password into whatever answered.
Keys, then no more passwords
ssh-keygen -t ed25519 produces a private key that stays on your machine and a public one that travels. Put a passphrase on the private key; it is the single secret that matters in this whole exercise. ssh-copy-id appends the public key to the server's authorised keys.
Open a second terminal and confirm the key works before closing the session you already have. Then set PasswordAuthentication no in sshd_config and reload the service, at which point brute-force attempts become noise in a log rather than a race that might one day go against you.
Give the machine a name, and a reverse one
Once the machine is doing something useful, it wants an A record so you can reach it by name in ordinary use, and it wants a PTR record — reverse DNS — if it will ever send email. Receiving servers check that the address a message comes from resolves back to a name that matches the one it claims, and a missing or mismatched PTR is a straightforward way to have mail rejected.
The PTR is set by whoever controls the address block, which means the provider rather than your registrar. That is the one DNS record you cannot add yourself in your own zone, and it catches people out reliably.

The name, the address and the console
Out-of-band console access comes with our VPS plans, which is what turns a lockout into a recoverable afternoon rather than a rebuild. Reverse DNS is the one entry you cannot add alongside your own records, because a PTR belongs to whoever holds the address block — so ask about it before the machine sends its first message rather than after.
The forward records — the A record for the machine, the hostname you actually publish — sit in the same panel as the rest of your zone, alongside the registration. One login for the name, one console for the machine.
- SSH, Git and Composer available on the developer plans
- Records and registration behind a single login
- DDoS traffic filtered at the network edge
- A desk staffed every hour of every day
Why Hosting & Domains
Standard on every plan
Address for admin, name for the public
A hostname resolves to wherever DNS currently says. During a migration that is a moving target, and the IP is not.
Host keys explained properly
Why the same machine prompts twice, and why a changed fingerprint on a familiar target means stop rather than accept.
Keys before lockdown
The public key is proven from a second terminal before password authentication is switched off, so the door is never closed on you.
Reverse DNS covered
The PTR record is the one entry you cannot add in your own zone, and it decides whether mail from the machine is accepted.
A way back that exists in advance
Out-of-band console access on our VPS plans, arranged before the day you need it rather than during it.
Honest about the port question
Moving SSH off 22 quietens the logs and is not a defence. Key-only authentication is the control that actually stops intrusions.
Quick Start
Order placed to site online
- 1
Take the address, username and port
IP, root on a fresh build, and 22 unless changed — all three in the provisioning email. Use the address rather than a hostname, particularly if any name is being repointed.
- 2
Connect once and record the fingerprint
ssh root@address from any terminal. Accept the host key the first time and note it. A changed fingerprint later means the server was rebuilt or the name now resolves elsewhere.
- 3
Generate a key pair with a passphrase
ssh-keygen -t ed25519 locally. The private key never leaves your machine and the passphrase on it is the one secret this whole exercise protects.
- 4
Install the public key and prove it from a second terminal
ssh-copy-id appends it to the server's authorised keys. Open a new session and confirm the key works before you close the one you already have.
- 5
Disable password login, then set the records
PasswordAuthentication no and reload. Afterwards add the A record for the machine, and ask for the PTR to be set on the address if it will ever send mail.
Built In
Fitted to every plan
- SSH, Git and Composer available on the developer plans
- Nameservers, contacts, privacy and locks in one place
- DDoS traffic filtered at the network edge
- A desk staffed every hour of every day
- The registration recorded in your own details
- Free SSL on every plan, reissued before the old one lapses
- A daily copy taken, with restores you run yourself
- NVMe SSD storage on every tier, not only the expensive ones
- A plan change applied to the account in place, with nothing migrated
- Thirty days' money back on hosting plans, seven on reseller
Frequently Asked
Questions we field again and again
Should I connect by IP address or by hostname?
By address for administration, always, and by hostname only when nothing is in motion. A hostname is a record that resolves to wherever DNS currently says, so during a migration, a delegation change or a repoint, the same command can reach two different machines on consecutive days with no indication of which one answered. The address is a fact about the machine; the name is a statement about where you would like traffic to go.
Why does SSH warn me about a changed host key?
Because the fingerprint it stored against that address or hostname no longer matches what the server presented. Two innocent causes: the machine was rebuilt, or the name now resolves to a different server after a DNS change. One less innocent cause: something is intercepting the connection. Work out which before you type anything, particularly if you were about to enter a password.
Do I need a reverse DNS record on the server?
If the machine will send email, yes. Receiving servers check that the sending address resolves back to a name matching the one the server claims, and a missing or mismatched PTR gets mail rejected or heavily penalised. The PTR is held by whoever controls the address block — the provider — rather than in your own zone, which is why you cannot simply add it alongside your A records. Ask for it to be set.
What if I lose the private key?
That way in is gone, which is exactly why a second key or a console route wants arranging before the day you need it. Out-of-band console access comes with our VPS plans, which makes a lockout a recoverable afternoon instead of a rebuild. Back the key up somewhere encrypted on the day you create it.
Keep reading
DirectAdmin Reseller Hosting
DirectAdmin reseller plans, for anybody holding accounts on behalf of other people.
WordPress Hosting
WordPress with LiteSpeed in the server, staging copies and a daily backup taken for you.
Changing provider? Work through this checklist beforehand.
A straightforward running order for a migration your visitors never spot: which files travel first, how to bring the mail across without dropping a single message, the right moment to repoint DNS, and the two errors that sit behind almost every outage we get called in to fix.
Administer the machine. Publish the name.
Out-of-band console access on VPS, records and registration in one login, and a desk that answers at any hour.
View DirectAdmin Reseller Hosting plans