Products
Domains & DNS
Full DNS control with fast propagation and automatic SSL, so pointing domains and subdomains is safe and simple.
Overview
Mahsumah runs its own authoritative DNS. Two BIND9 servers — ns1.mahsumaah.sa and ns2.mahsumaah.sa, both authoritative — answer queries for domains hosted with us. You point your domain's nameservers at ours and we manage the zone in-house.
Because DNS, hosting, and TLS all live on our side, connecting a domain is one coordinated step: delegate the nameservers, we create the records, and certbot issues the certificate. No third-party DNS provider sits between your domain and your site.
How it works
- 1
Delegate your nameservers
At your registrar, set the domain's nameservers to ns1.mahsumaah.sa and ns2.mahsumaah.sa. This hands authoritative DNS to us.
- 2
We create your zone
We add a zone on both BIND9 servers with the A/AAAA records pointing to your site, plus any CNAME, MX, or TXT records you need.
- 3
Propagation completes
Once resolvers pick up the new delegation, queries for your domain are answered from our authoritative servers.
- 4
TLS is issued automatically
certbot requests a Let's Encrypt certificate for the domain and www, and HTTPS is enforced from the first request.
Under the hood
Two authoritative BIND9 nameservers, ns1.mahsumaah.sa and ns2.mahsumaah.sa, for redundancy.
Full in-house zone management: A, AAAA, CNAME, MX, and TXT records edited directly on our servers.
Domains delegate to us by nameserver, so we control the authoritative answers rather than proxying a third-party DNS.
DNS, hosting, and certificate issuance are coordinated on the same infrastructure, which keeps domain setup and TLS in sync.
Key facts
- Nameservers
- ns1.mahsumaah.sa, ns2.mahsumaah.sa
- DNS software
- BIND9, authoritative
- Record types
- A, AAAA, CNAME, MX, TXT
- Delegation
- Point your nameservers to ns1/ns2
- Registration
- Bring your own domain (registrar-purchased)
What's included
Authoritative DNS on our own ns1/ns2 BIND9 servers
A and AAAA records pointing your domain to your site
CNAME records for subdomains and aliases
MX records for your email provider
TXT records for SPF, DKIM, DMARC, and domain verification
www and apex (root) domain both served
Automatic Let's Encrypt SSL once the domain resolves to us
In-house record changes handled by our team on request
Frequently asked questions
Do you register domains for me?
Today you register the domain with a registrar and delegate it to our nameservers; we host the zone. Standalone domain registration is on our roadmap but not live yet.
Can I keep my email when I move DNS to you?
Yes. We recreate your existing MX and any SPF/DKIM/DMARC TXT records in the new zone so mail keeps flowing to your provider without interruption.
How long does propagation take?
It depends on the registrar and resolver caching, typically from a few minutes up to a day. Once resolvers see the new delegation, our authoritative servers answer immediately.
Can I manage records myself?
Record changes are handled in-house by our team on request today. A self-serve DNS panel is part of the planned dashboard/API surface.
Start on Mahsumah Cloud
Start in minutes, or let our team migrate your current platform for you.