Skip to content

Transfer domain control

Transferring domain control means that the DNS zone is served by WebShield nameservers. The domain remains with your registrar; you do not need to transfer the registrar account.

  1. Open Control panel → Domains.
  2. Click Add domain.
  3. Enter a domain, for example example.com.
  4. Save it.

The domain will appear in the table with its delegation status.

So that your website and email keep working after delegation, WebShield imports the domain’s current DNS records. The add dialog offers two methods.

WebShield queries public DNS for a list of common names (apex, www, mail, MX records, TXT/DMARC/DKIM, common SRV) and imports whatever answers at that moment. It always works and needs no setup, but may miss custom subdomains.

A full and exact import: WebShield requests the entire zone from your current DNS provider.

  1. In the add dialog choose Zone transfer (AXFR).
  2. At your current provider, allow zone transfer to the IP address shown in the dialog (the allow-transfer directive). Provide a TSIG key if required.
  3. The Current nameserver field is pre-filled from the current delegation; adjust it if needed.
  4. Save.

If the transfer fails (the provider does not allow it from our address), WebShield reports it. The domain is already created, so you can:

  • fix the allow-transfer settings at the provider and click Retry AXFR;
  • click Import via scan to import records with the automatic scan;
  • click Keep empty and add records manually later.

AXFR is disabled by default at most providers (Cloudflare, Route 53, registrar panels). This method is intended for self-hosted nameservers or providers where transfer can be enabled.

You can always edit the imported records in the DNS records section.

Set these nameservers at your registrar:

nsbox.webshield.pro
nshub.webshield.pro

You can copy them from the block above the domain table.

Click Check in the domain table. Possible statuses:

  • Delegated - the domain already uses WebShield NS.
  • Not delegated - the registrar still has other NS values or the change has not propagated yet.
  • Unknown - the check has not run yet or the result is temporarily unavailable.

A domain can be removed from the panel only when its status is Not delegated. This prevents accidental deletion of an active zone that is serving traffic.