menu
small_header_domains.svg

netcup wiki

Domain

DNS Settings

Advanced Guide to Modifying DNS Configuration in CCP

This section is intended only for experienced individuals and can cause problems if used improperly.

Using netcup domains with netcup products such as netcup Server, SOGo or Webhosting is straightforward and requires no DNS changes here. Just refer to the linked instructions for this.

Inclusive domains with netcup web hosting are automatically connected to the booked web hosting instance.

You can adjust the DNS entries of your domain at any time. For instance, this is necessary to connect to web hosting or SOGo solutions from other providers.

To do this, open your Customer Control Panel (CCP) and go to the "Domains" section in the navigation bar on the left side. Find the domain you want to make changes to and click on the magnifying glass next to the domain. Then switch to the DNS tab.

Editing DNS Entries

Introduction

In this guide, you will learn how to edit the DNS entries of your domain.

Table of DNS Entries

The @ symbol represents the main domain (e.g., domain.tld).

The DNS tab is structured in the form of a table:

EntryDescription
HostSubdomain or Wildcard (*).
TypeType of entry.
MXFor type "MX", a priority is set here.
DestinationTarget of the entry.
ValidIndicates the validity of an entry.

Examples of Valid Entries

These are just examples. You can, for example, connect your domains with Google Workspace or Protonmail and still have the A-records point to netcup IPs.

Below are some examples of correctly formatted DNS entries.

A-Records

TypeDescriptionTarget IP
WildcardApplies to all subdomains of the zone.78.47.133.14
Main DomainSpecifically applies to the main domain.78.47.133.14

MX-Records

PriorityDescriptionTarget
10Forwarding to a specific servermail.qualitaet.ws

SRV-Records

HostTypeDestination
_Service._ProtocolSRVPriority Weight Port Target

Glue Records

TypeDescriptionAdditional Info
GlueWhen nameserver and domain are in the same zone.Required IP of the nameserver

Instructions

Save Changes

Global DNS servers can take up to 48 hours to recognize your changes, so we ask for your patience.

  1. After editing, click on "Save DNS Records".
  2. The system checks your entries for semantic correctness. Errors are displayed in a red box.
  3. Semantically correct changes are confirmed with a green box and are usually updated within about 10 minutes.

Resetting

Global DNS servers can take up to 48 hours to implement the reset, so we ask for your patience.

If you've made an error, you can easily reset the DNS entries.

  1. For this, check the box for "Set standard DNS settings".
  2. Then click on "Save DNS Records".
  3. The reset is usually updated within about 10 minutes.

Nameserver

By default, you use netcup's nameservers.

Own Nameserver

If ignored, your domain may not be accessible during the transition phase.

Global DNS servers can take up to 48 hours to implement the reset, so we ask for your patience.

Follow these steps to add your own nameserver entries. You will receive this data from your nameserver provider.

  1. Switch in the dropdown menu to "own nameserver".
  2. Now enter the hostname in the table above under Hostname. IPv4 and/or IPv6 addresses can also be specified if required by your provider.
  3. Click on "Save Nameserver".
Back to netcup's Nameserver

Global DNS servers can take up to 48 hours to implement the reset, so we ask for your patience.

  1. Switch in the dropdown menu to "netcup Nameserver".
  2. Click on "Save Nameserver".

DNSSEC

DNSSEC (Domain Name System Security Extensions) helps protect certain data when communicating with DNS servers.

netcup's DNSSEC

If ignored, your domain may not be accessible during the transition phase.

Global DNS servers can take up to 48 hours to implement the reset, so we ask for your patience.

  1. Activate DNSSEC by clicking on the "DNSSEC Status" checkbox.
  2. Then click on "Save DNS Records".
DNSSEC with external nameservers

If ignored, your domain may not be accessible during the transition phase.

Global DNS servers can take up to 48 hours to implement the reset, so we ask for your patience.

The zone must be correctly signed by your nameserver before you can send the information to the registrar.

If using an external nameserver, you can, of course, also activate DNSSEC. You will receive this data from your nameserver provider.

  1. External nameservers should already be set up.
  2. Click on "+ New DNSSEC Entry".
  3. Enter the public key, flags, and algorithm.
Switching back to netcup's DNSSEC

If ignored, your domain may not be accessible during the transition phase.

Global DNS servers can take up to 48 hours to implement the reset, so we ask for your patience.

  1. Delete all DNSSEC keys in the panel.
  2. Retain keys in your nameserver for double TTL (usually 48 hours).
  3. Switch to netcup's nameservers and activate DNSSEC by clicking on the "DNSSEC Status" checkbox.
  4. Then click on "Save DNS Records".
Last update: 31/01/2024