Skip to content
WebShield Docs

Transfer domain control

How to connect a domain and delegate DNS to WebShield.

Transferring control means moving the domain’s DNS zone to WebShield nameservers. The domain itself stays put: it remains with your registrar, and you don’t need to change registrars.

Rather not change nameservers? You can connect a site with records at your DNS provider, see Connect without changing nameservers.

  1. Open Control panel → Domains.
  2. Click Add domain.
  3. Enter a domain, for example example.com.
  4. Save it.

The domain will appear in the table with its delegation status.

So that your website and email keep working after delegation, WebShield imports the domain’s current DNS records. The add dialog offers two methods.

WebShield queries public DNS for a list of common names (apex, www, mail, MX records, TXT/DMARC/DKIM, common SRV) and imports whatever answers at that moment. It always works and needs no setup, but may miss custom subdomains.

A full and exact import: WebShield requests the entire zone from your current DNS provider.

  1. In the add dialog choose Zone transfer (AXFR).
  2. At your current provider, allow zone transfer to the IP address shown in the dialog (the allow-transfer directive). Provide a TSIG key if required.
  3. The Current nameserver field is pre-filled from the current delegation; adjust it if needed.
  4. Save.

If the transfer fails (the provider does not allow it from our address), WebShield reports it. The domain is already created, so you can:

  • fix the allow-transfer settings at the provider and click Retry AXFR;
  • click Import via scan to import records with the automatic scan;
  • click Keep empty and add records manually later.

AXFR is disabled by default at most providers (Cloudflare, Route 53, registrar panels). This method is intended for self-hosted nameservers or providers where transfer can be enabled.

You can always edit the imported records in the DNS records section.

Set these nameservers at your registrar:

nsbox.webshield.pro
nshub.webshield.pro

You can copy them from the block above the domain table.

Listing both is the point; if your registrar accepts only one, the domain still works — you simply have less resilience. Leaving a foreign nameserver in the list is another matter: resolvers will occasionally go to your previous provider, bypassing protection, and the domain will not be marked as delegated.

Instead of the shared names, a domain can be delegated to your own: ns1.example.com, ns2.example.com. The option comes with the domain’s paid plans. From the outside they look like your own DNS servers. The addresses behind them stay ours, and WebShield keeps the records for those names — you neither need nor are allowed to create them by hand (they are protected from editing in the DNS records section). A CNAME will not do either: a nameserver name must point straight at an address.

Steps:

  1. Control panel → Domains → DNS, the Vanity nameservers card → Enable. Each name must be a subdomain of this very domain.
  2. Copy the addresses shown and create glue records at your registrar (panels call them “host records”, “child nameservers” or “register a nameserver”): one address per name.
  3. Change the domain’s nameservers at the registrar to those names.
  4. Press Check — once delegation is confirmed, the zone switches to the new names on its own.

Until step 3 is done the domain keeps running on the shared nameservers: we never switch the zone before the vanity names actually answer at the registrar.

You can go back to the shared nameservers at any time — re-delegate the domain at the registrar first, then press Back to shared nameservers. Moving to the free plan breaks nothing: vanity nameservers already in use stay, you just cannot change the set until the domain is on a paid plan again.

Nameserver addresses change rarely, but when they do we will warn you in advance: the glue records at the registrar have to be updated, otherwise the domain stops resolving.

A domain that is never delegated to WebShield nameservers is deleted after 30 days, together with its records and settings. Two emails come first: a week before and a day before. Delegate the domain and the deletion is cancelled automatically. Domains connected via records are not affected.

Click Check in the domain table. Possible statuses:

  • Delegated - the domain already uses WebShield NS.
  • Not delegated - the registrar still has other NS values or the change has not propagated yet.
  • Unknown - the check has not run yet or the result is temporarily unavailable.

A domain can be removed from the panel only when its status is Not delegated. This prevents accidental deletion of an active zone that is serving traffic.