Products

Domains & DNS

Full DNS control with fast propagation and automatic SSL, so pointing domains and subdomains is safe and simple.

Overview

Mahsumah runs its own authoritative DNS. Two BIND9 servers — ns1.mahsumaah.sa and ns2.mahsumaah.sa, both authoritative — answer queries for domains hosted with us. You point your domain's nameservers at ours and we manage the zone in-house.

Because DNS, hosting, and TLS all live on our side, connecting a domain is one coordinated step: delegate the nameservers, we create the records, and certbot issues the certificate. No third-party DNS provider sits between your domain and your site.

How it works

  1. 1

    Delegate your nameservers

    At your registrar, set the domain's nameservers to ns1.mahsumaah.sa and ns2.mahsumaah.sa. This hands authoritative DNS to us.

  2. 2

    We create your zone

    We add a zone on both BIND9 servers with the A/AAAA records pointing to your site, plus any CNAME, MX, or TXT records you need.

  3. 3

    Propagation completes

    Once resolvers pick up the new delegation, queries for your domain are answered from our authoritative servers.

  4. 4

    TLS is issued automatically

    certbot requests a Let's Encrypt certificate for the domain and www, and HTTPS is enforced from the first request.

Under the hood

  • Two authoritative BIND9 nameservers, ns1.mahsumaah.sa and ns2.mahsumaah.sa, for redundancy.

  • Full in-house zone management: A, AAAA, CNAME, MX, and TXT records edited directly on our servers.

  • Domains delegate to us by nameserver, so we control the authoritative answers rather than proxying a third-party DNS.

  • DNS, hosting, and certificate issuance are coordinated on the same infrastructure, which keeps domain setup and TLS in sync.

Key facts

Nameservers
ns1.mahsumaah.sa, ns2.mahsumaah.sa
DNS software
BIND9, authoritative
Record types
A, AAAA, CNAME, MX, TXT
Delegation
Point your nameservers to ns1/ns2
Registration
Bring your own domain (registrar-purchased)

What's included

  • Authoritative DNS on our own ns1/ns2 BIND9 servers

  • A and AAAA records pointing your domain to your site

  • CNAME records for subdomains and aliases

  • MX records for your email provider

  • TXT records for SPF, DKIM, DMARC, and domain verification

  • www and apex (root) domain both served

  • Automatic Let's Encrypt SSL once the domain resolves to us

  • In-house record changes handled by our team on request

Frequently asked questions

Do you register domains for me?

Today you register the domain with a registrar and delegate it to our nameservers; we host the zone. Standalone domain registration is on our roadmap but not live yet.

Can I keep my email when I move DNS to you?

Yes. We recreate your existing MX and any SPF/DKIM/DMARC TXT records in the new zone so mail keeps flowing to your provider without interruption.

How long does propagation take?

It depends on the registrar and resolver caching, typically from a few minutes up to a day. Once resolvers see the new delegation, our authoritative servers answer immediately.

Can I manage records myself?

Record changes are handled in-house by our team on request today. A self-serve DNS panel is part of the planned dashboard/API surface.

Start on Mahsumah Cloud

Start in minutes, or let our team migrate your current platform for you.