Guides · Your domain name and DNS
Nameservers, DNSSEC and the transfer lock: your domain's DNS setup explained
Last reviewed by a person on October 4, 2026
A website depends on three separate services that people constantly mix up: where the domain name is registered, who answers DNS for it, and where the website itself is hosted. They are often three different companies, and knowing which is which is what lets you fix things quickly. This guide explains the DNS parts: nameservers, DNSSEC and the transfer lock.
Registrar, DNS host and web host
- The registrar is the company you bought the domain name from (GoDaddy, Namecheap, Google/Squarespace Domains, a local reseller). It holds your registration, renews it and lists which nameservers the domain uses.
- The DNS host runs the nameservers that answer "what is the address of www.example.com?" and hold your records (website, email, validation records). It is often the registrar, but not always: many people move DNS to Cloudflare, Amazon Route 53 or their hosting company.
- The web host is the server that actually serves your pages. DNS only points visitors at it.
Nameservers
The nameservers are the machines that hold your DNS records, named like ns1.example-dns.net or
anna.ns.cloudflare.com. Your registrar submits this list (the "delegation") to the registry, which publishes it in the
ending's own DNS (.com, .org…), and that is how the rest of the internet finds the right place to ask. To see yours:
dig NS example.com +short
Or use the DNS checker, which shows the nameservers, the DNS host when it recognises it, and the registrar, transfer lock and DNSSEC from the registry.
The names usually tell you who hosts your DNS. *.ns.cloudflare.com is Cloudflare, awsdns-* is Amazon Route 53,
domaincontrol.com is GoDaddy, registrar-servers.com is Namecheap. That is the place where you change
records: the website address, email (MX), the TXT records that prove you own the domain, and CAA records. Changing a record
at a company that is not your DNS host does nothing, which is a very common reason for "I changed it but nothing happened".
Be careful when changing nameservers. It moves all your DNS to a new provider. Copy every record to the new one first (website, email, verification records), or your site and email break the moment the change takes effect.
DNSSEC
Normal DNS answers are not signed: a resolver mostly has to trust what it hears. DNSSEC adds digital signatures to your DNS records, so a resolver that checks them can tell that an answer really came from your zone and was not forged along the way. It protects against attacks that feed visitors a false address for your domain.
- How it is set up: your DNS host signs the zone, and a "DS" record is published at the registry through your registrar to link the two. Both halves must match.
- The risk is breaking it. If the signatures are wrong, or your DNS host stops renewing them before their validity period ends, or the DS record at the registrar no longer matches (typically after moving DNS provider), resolvers that validate DNSSEC treat your domain as unreachable. Website and email can disappear for those users while it still works for others, which makes it hard to diagnose.
- When it is worth it: if your DNS host handles the keys for you (Cloudflare does, and some others), it is a reasonable extra layer; if you would have to manage keys by hand, be sure you can keep that up. If you move your DNS to another provider, turn DNSSEC off first (remove the DS record), move, then re-enable it there.
- Certificates: many certificate authorities, Let's Encrypt among them, look up DNS through resolvers that validate DNSSEC, and the industry rules don't let a CA ignore a CAA lookup that failed DNSSEC validation. So broken DNSSEC can make domain validation or the CAA check fail, and the certificate request with it.
The transfer lock
A domain with the transfer lock on (the registry status is "client transfer prohibited") cannot be moved to a different registrar until you unlock it at your current one. It is the simplest protection against someone moving your domain away: an extra step a hijacker has to get past. It isn't a guarantee, though: anyone who gets into your registrar account can turn it off, and it doesn't protect against a breach at the registrar or registry itself.
- Keep it on. Unlock it only when you really intend to transfer, then lock it again.
- Protect the account behind it. Use a strong, unique password and two-factor sign-in at your registrar, and keep the account's email address current. That mailbox is where renewal notices and transfer confirmations go.
- Some registries offer a stronger "registry lock" for valuable domains (it needs a manual step with the registry to change anything).
Where to see all of this
Each domain's DNS tab in CertAvert shows its nameservers (and the provider they point to when we recognise it), the registrar, whether DNSSEC is on, whether the transfer lock is on, and when the registration ends. It reads this from the domain registry's public RDAP service, so it works without an account at your registrar. For endings whose registry has no public lookup (such as .de) it falls back to the nameservers DNS reports. Monitor a domain with CertAvert to see yours.
Related: what happens when a domain name expires and CAA records.
Don't wait for the browser warning
Check any site's certificate in a few seconds with the SSL/TLS checker, or sign up free and CertAvert emails you before certificates expire.