Domain & DNS Dictionary
APIs: how names and zones get changed without a human
You hold more names than a control panel makes comfortable, and one record now has to change on all of them.
The short answer
An API is the agreed contract two systems use to exchange data and issue instructions, and in domain work it is the thing that edits a zone, renews a portfolio or unlocks a name with nobody opening a panel at all.
Three layers sit on top of one another. The registry speaks EPP, the protocol that actually creates, renews and transfers a registration. Your registrar wraps that in an API of its own. Whoever hosts your DNS publishes a separate one for records inside the zone.
Knowing which of those three a call reaches is the whole skill, because it decides whether you are editing a record you can undo in seconds or moving an asset you may not get back.
By the Hosting & Domains team · Reviewed 18 August 2026
0
Terms we leave undefined
100+
Entries, all cross-referenced
Real
Zones and transfers, real ones
Free
Free to read, no sign-up
Nearly every domain API is ordinary HTTP with JSON going in and JSON coming back. You address an endpoint, you get a structured answer, and a key or token in the header proves who is asking. It is the same web your visitors use, pointed at a machine instead of a browser.
Scope is what separates them. A DNS API changes records: an A record's target, a TXT value, a TTL. A registrar API changes the registration itself: lock state, registrant contacts, nameserver delegation, renewal, transfer. Mistakes in the first class cost you a minute. Mistakes in the second can cost you the name.
Which makes a key rather more than a password. It is a password with a blast radius, and the radius is exactly as wide as the permissions you granted it.
Which layer your call is actually reaching
Write a TXT record and nothing you did went near the registry; you changed a file that your nameservers serve. Change the nameservers themselves and the instruction travels from your registrar to the registry, gets written into the delegation, and is republished to the world. Two requests that look alike in a terminal, two entirely different systems of record.
Get into the habit of naming the target before you send anything. Registry, registrar, DNS host, mail host: one of the four owns the setting in front of you, and only that one can change it.
What a domain API is genuinely good at
Repetition across a portfolio. Adding a sending service to the SPF record of forty names is an afternoon of panel work and a five-minute script. So is auditing the lot: expiry date, auto-renew flag, lock state, whether privacy is on, which nameservers each name currently answers with.
That audit is the underrated one. Portfolios rot quietly. A name whose delegation still points at a host you left two years ago is invisible in a panel and obvious in a list of forty rows.
The key that can move a name
Give a monitoring script a read-only key and the worst it can do is tell you something. Give it a key carrying transfer and contact-change permission and you have handed the name itself to whatever machine holds that file. Scope every key to the narrowest job that works, pin it to known addresses where the provider allows it, and rotate it the moment you suspect it has travelled.
The classic incident is not clever. A key with full registrar permissions is committed to a repository, the repository goes public, and the registrant contact on a name is changed by somebody who found it with a search.
Where automation and the registry clock disagree
A success response from a registrar API means your instruction was accepted, not that the registry has finished acting on it. Renewals, transfers and delegation changes each carry their own timing, and none of them care that your script has moved on to the next row.
The same gap appears on the DNS side, where a written record is not a visible record until the old TTL has run out. Automate the write, then verify against a public resolver rather than against the API that told you it worked.
What you can reach from your own account. The panel covers everything most portfolios ever need, and the client area holds the registration side: locks, contacts, delegation, renewal. If this entry landed, the neighbours worth reading are Webhook, DNS, Nameserver and TXT Record.
Order annually and year one of the name is included.

A dictionary written from the registry outwards
Every confusing term about names, records and transfers eventually arrives as a support ticket, so we wrote the hundred commonest ones down properly — once, in the same language we use on the desk.
The rate you register at is the rate you renew at, so year two costs exactly what year one did — nothing waiting on the invoice.
- 100+ entries, written in plain English
- Registry, registrar, reseller and host kept apart
- The record, the clock and the failure mode named
- Written by the people who run the transfers
Why Hosting & Domains
Standard on every plan
Written from the registry outwards
Every entry says where the record actually lives, and which of registry, registrar or host owns it.
Registry, registrar, reseller, host
Four parties with four different powers. We keep them apart, because that distinction is the whole job.
Examples from real zones
Record names, selectors and hostnames as you would actually type them, rather than an abstract diagram.
The failure mode, not just the definition
Each term arrives with the thing that breaks when it is wrong — usually email, and usually quietly.
Cross-referenced on purpose
Neighbouring records and protocols point at each other, so one lookup turns into working knowledge.
API, located
API defined, placed against the registration it belongs to, and shown where the change is made.
Quick Start
Order placed to site online
- 1
Work out who owns the setting
Registry, registrar, DNS host, mail host: only one of the four can change the thing in front of you. Establish which before you change anything.
- 2
Find the record, not the setting
Open the DNS zone for the name and read what is actually published there. A term stops being abstract the moment you see it in your own zone.
- 3
Read the neighbouring entries
Names travel in groups — Webhook, DNS and Nameserver complete this one's picture, each a two-minute read away.
Built In
Fitted to every plan
- Mailboxes that answer at the name you own
- The PHP version chosen per site, from the panel
- SSH, Git and Composer available on the developer plans
- WordPress and 400+ further applications in a single click
- NVMe SSD storage under every tier, not only the dear ones
- cPanel — the panel most of the industry already runs
- A copy taken daily, and restores you run yourself
- Plan changes applied in place — the account moves up, the site stays put
- Softaculous included, so applications install in one click
- Webmail in the browser, with IMAP, POP and SMTP for any client
Frequently Asked
Questions we field again and again
Can nameservers be changed through an API?
Yes, but notice which system you are addressing. Delegation lives in the registration, so the call goes to your registrar and onward to the registry, and the change is republished in the TLD's zone rather than in yours. Records inside the zone are a separate API entirely. Confusing the two is how people edit an A record and wonder why delegation did not move.
Is an API worth it for a handful of names?
Rarely. Below about ten names the panel is quicker than writing anything, and the audit you would automate is a five-minute read. The threshold is not really a count, it is repetition: the moment the same edit has to land on every name you hold, a script stops being an indulgence.
Is EPP the same thing as a registrar API?
No. EPP is the protocol registrars use to talk to a registry, and it is what actually creates, renews and transfers a registration. A registrar API is a friendlier layer in front of it. The word survives in ordinary use as the EPP code, meaning the auth code you need in order to move a name elsewhere.
Does automation change how renewals are billed?
Not at all. Payment is by credit or debit card through a secure checkout, at the same rate as the original order, and every invoice sits in your client area. Auto-renewal is a toggle in the account rather than a phone call, whether you set it there or through an interface.
Keep reading
Drupal Hosting
Drupal with Composer, Drush and per-site PHP control to hand.
WordPress Hosting
WordPress looked after for you, with LiteSpeed caching, staging copies and a daily backup.
Changing provider? Work through this checklist beforehand.
A straightforward running order for a migration your visitors never spot: which files travel first, how to bring the mail across without dropping a single message, the right moment to repoint DNS, and the two errors that sit behind almost every outage we get called in to fix.
The name is the asset. Treat it like one.
Free SSL, a free migration, renewals at the rate you registered at, and a person on support at any hour.
View Drupal Hosting plans