Extra Security Questions

Do you want extra security beyond Two-Factor Authentication, preventing transfers, and locking domains?

We can add an additional security question to your account. We would need to call you and get the correct answer to the question before we would make any changes to your account and domains. As an example, if somebody sends us documentation authorizing us to change the Registrant email address, we would still call you and require the correct answer to the security question before we would change the address.

Please contact us if you want to add an extra security question.

Refund Policy

We automatically refund any transfer that is not completed. The refund is made as soon as the transfer is canceled.

We cannot refund on registrations or renewals. The costs are non-refundable because it is not possible to unregister a domain or remove years from a domain.

Weebly

Weebly plans that are cancelled within 14 days are eligible for a refund. The cancelation must be completed within 14 days. We will refund the full costs for the cancelled Weebly plan, but not any domain name registration, transfer, or renewal charges.

Weebly plans that are upgraded or downgraded cannot be refunded. However, any remaining pre-paid full months of the previous plan are eligible for a credit towards the new plan, up to the cost of the new plan.

Example 1: If you pay for one year of a Pro Plan ($139/year) and upgrade to a Business Plan ($299/year) during the second month, you have 10 pre-paid full months. That will allow a credit of $115.83 towards the Business Plan.

Example 2: If you pay for one year of a Pro Plan ($139/year) and downgrade to a Starter Plan ($89/year) during the second month, you have 10 pre-paid full months. The credit cannot exceed the cost of the new plan ($89), so you would not get the same $115.83 credit that you would on an Upgrade. Instead, the credit would cover the entire cost of the Starter Plan for one year, but would not carry over to any other services of future years on the Starter Plan.

Protecting Domain Names

If you want to protect your domain, we have a setting to automatically reject outbound transfers. When you register a domain or transfer it to us, there is a checkbox to enable this setting. It is checked by default, so unless you uncheck it, you are already protected from unauthorized transfers.

You can change the setting at any time by following these steps:

  1. Log into the Domain Name Management System.
  2. Click the domain you want to update.
  3. To allow transfers, uncheck the box labeled Transfer Protection is ON, and click Update Protection. If you see Transfer Protection is OFF, then transfers are allowed.

    To prevent transfers, check the box labeled Transfer Protection is OFF, and click Update Protection. If you see Transfer Protection is ON, then transfers are not allowed.

Domain Locking

If you want more security, we allow you to lock domains. Locking prevents transfers and any changes to the name servers or contact information. Locking requires use of Two-Factor Authentication. If you want to lock a domain, you must first turn on Two-Factor Authentication.

Unlocking a domain requires logging in, requesting to unlock your domain, and then contacting us to confirm unlocking.

You can follow these steps to lock a domain:

  1. Log into the Domain Name Management System.
  2. Click the domain you want to lock.
  3. Click Lock.
  4. Agree to the terms of service, and click Lock.
  5. Read the warning message, and click Yes.

Information on unlocking a domain can be found in this Knowledge Base Article.

What is DNSSEC?

Domain Name System Security Extensions (DNSSEC) is a method of adding security to DNS to protect against forged or manipulated DNS information.

Standard DNS information is not authenticated, name servers trust any response they receive. Since they trust any response, it is possible for somebody to send incorrect information to a name server. Once the name server has the incorrect information, anyone else who uses that name server will see the incorrect info. An attacker could use this to temporarily disable or redirect a domain.

DNSSEC adds security by letting name servers verify that DNS info is coming from the correct place. When DNSSEC is set up, DNS records are digitally signed. When checking records, name servers check for a signature and compare it to the correct signature. If there is no signature or if the signatures don’t match, the name server will not trust or save the incorrect information.

Failure to keep DNSSEC records up to date can cause problems with resolving DNS records. If you use Pair Domains DNSSEC, we keep the records up to date, so this should only be an issue if a domain uses DNSSEC on other name servers.

The registry for UK domains, Nominet, accepts no liability in relation to the use or operation of DNSSEC records. They will take reasonable steps to correct any error that is the result of a mistake on Nominet’s part, but they accept no liability for the error.

To learn how to use DNSSEC, please visit our Knowledge Base article Using DNSSEC.

Two-Factor Authentication

We offer two-factor authentication as a way to keep your account more secure.

An account name and the associated password are required to log into an account. Two-factor authentication adds an extra level of security to the login process. After entering the account name and password, you will need to enter a single-use authentication code.

There are free authentication apps like Authy (which is available for Android and iOS) and Google Authenticator (which is available for Android and iOS). Most password management apps support two-factor authentication.

Codes cannot be sent by email and cannot be sent by a voice phone call.

Please follow these steps to turn on two-factor authentication:

  1. Log into the Domain Name Management System.
  2. Select Account Settings from the drop-down navigation menu.
  3. Click 2FA settings.
  4. Click Turn on 2FA.
  5. Use your authentication app to scan the QR code.
  6. Save your recovery information.
  7. Enter the code from your app, and select Complete 2FA Setup.

Setup Notes

1Password has a two-factor authentication setup guideLastPass has a two-factor authentication setup guide. Please note: setting this up requires logging in to LastPass through their website, not the desktop app.

If you want to use a YubiKey, please visit their support page for instructions.

If You Lose or Replace Your Phone

Depending on the app you use, you might be able to access codes on a new phone, or you might need to use your QR code or recovery key to set it up on the new phone. If you app does not have codes for us, we cannot provide a code or key. Those can only be obtained during the set up. If you don’t have recovery information, we will need to turn off two-factor authentication if you want to log in.

If you know you are going to replace your phone, you can export settings from Google Authenticator and then set them up on the new phone. Please visit our page about Exporting Authenticator Setups.

Turning Off Two-Factor Authentication

If you can log in, you can disable it from Account Settings. If you cannot login, please contact us. We will need to verify your identity before we can turn off two-factor authentication.

Transferring Between Accounts

If a domain is already with Pair Domains, you can change the ownership without needing to pay for a transfer. Instead, domain names can be moved between accounts. There is no charge for moving domain names between accounts or for creating new accounts.

To move a domain from one account to another account, you can log into the account that currently manages the domain:

  1. Log into the Domain Name Management System.
  2. Click the domain to move.
  3. Click Move Domains.
  4. If you want to create a new account, click Create a New Account.

    Alternately, if you want to move to an existing account, skip to
    Step 7.
  5. Fill in the Account Contact information for the new account.
  6. Choose an account name and password, and click Create.
  7. Select the domain(s) to move.
  8. Enter the new account name, and click Start Move.

You will be prompted to enter the password for the current account.

We will send an email to the current Registrant Email asking to confirm the move. After the current Registrant confirms the move, we will send an email to the new Registrant Email asking to confirm the move. The move will not be completed unless both the current Registrant and new Registrant confirm it within three days.

Please Note: Moving a domain name to a different account will  trigger a request to verify contact information on the new account. You can find more information about verifying contact information in our Knowledge Base.

Please Note: Domains with Weebly sites cannot be moved this way. If you have not done much work on the site yet, you can delete the Weebly site, and then move the domain.

If you need to keep the current site, we can move all Weebly sites associated with an account to a separate account that has never used Weebly before. However, we cannot move individual Weebly sites. So if you have multiple Weebly sites on an account, we can move all of them or none of them. If you want to move all of them, you can contact us to move the domains. Unfortunately, it is not possible to move domains to Weebly sites if the destination account has used Weebly before.

Verifying Contact Information

Registrars are required to verify that contact information is valid on all domain names. This means verifying that the email address listed for every contact reaches somebody, and verifying that the phone number listed for every contact reaches somebody.

Each email address or phone number only needs to be verified once per account. So if you have multiple domain names that all list you@example.com as the email address, you only have to verify you@example.com once. After that, you will not need to verify you@example.com again on that account.

If any contact information needs to be verified, you will see a prompt when you log into your account. If you close the prompt, you can select Account Settings from the drop-down navigation menu, and select Manage Contact Verification to bring up the prompt again. The verification prompt and the Manage Contact Verification link only appear if you need to verify information. If you do not see either, you do not need to verify anything.

You can follow these steps to update the Administrative, Technical, and/or Billing Contacts on a domain name:

  1. Log into the Domain Name Management System.
  2. Click the domain to update.
  3. Click Update Contact Info.
  4. Update the information, and click Submit Changes.

If you want to update the information on multiple domains, you can create or apply a Saved Contact and apply it to the domains:

  1. Log into the Domain Name Management System.
  2. Select Saved Contacts from the drop-down navigation menu.
  3. Click Create a New Saved Contact.

    If you already have a Saved Contact, you can skip this step and the next step.
  4. Enter contact information, and Click Create.
  5. Click Apply a Saved Contact to Your Domains.
  6. Select the Saved Contact to use.
  7. Check the boxes for the contacts and domains to update.
  8. Click Submit.

Verifying Email Addresses

The verification prompt allows you to send a verification email to each address that needs to be verified. The email has a link you can visit to verify the address. It also includes a numeric code that can be entered in your account to verify the address.

Verifying Phone Numbers

The verification prompt allows you to send a SMS (Text) message or an automated phone call to each number that needs to be verified. The SMS or automated phone call will give you a numeric code that can be entered in your account to verify the phone number.

Please Note: If your phone number requires entering an extension or selecting a menu option, the automated phone call option will not work. Please contact us and we can help you verify.

Verifying Other Information

In some cases, we need to verify the Registrant Organization or Registrant Postal Address for .co.uk, .me.uk, or .org.uk domain names. In many cases, the UK registry can automatically verify the Registrant Organization or Registrant Postal Address. They only ask us to verify information if they cannot verify it automatically.

If we need to verify this information, we will contact you with instructions. Verification usually requires the Registrant to send us a copy of a utility bill or bank statement from the past 3 months, a government issued ID (for individuals), or company letterhead or seal (for organizations).

Weebly File Size Limits

All Weebly plans have unlimited storage. However, there are limits on the size of individual files that can be uploaded:

  • Included plan: Maximum file size is 10 MB
  • Starter plan: Maximum file size is 100 MB
  • Pro plan: Maximum file size is 250 MB
  • Business plan: Maximum file size is 1 GB
  • Performance plan: Maximum file size is 1 GB

As long as each file is smaller than the maximum file size, you can upload as many as you want to. As an example, somebody with an Included plan could upload unlimited 9 MB files, but uploading a file larger than 10 MB would require upgrading to a Starter plan.

Dynamic DNS

If you have a server attached to a business-class network, the server probably has a static IP address. This means that the network address the server uses does not change from one day to the next. You can easily create Custom DNS records pointing to static IP addresses and they do not require using Dynamic DNS.

However, computers connecting to the Internet through residential Internet service (home fiber, cable modem, DSL, or dial-up) can have dynamic IP addresses. When you connect, the provider assigns an IP address. It may be an address you have used before, or it may be a new IP address. Depending on your Internet service provider, the IP address could change after weeks, days, or even hours.

Dynamic DNS updates DNS records on our name servers within minutes of a change to your IP address. It works by running a simple client on your computer, which connects to us frequently. When we detect that your IP address has changed, we update your DNS records to match.

For a practical example, let’s say you want to access your home computer while you are at work. You set up Pair Domains Dynamic DNS. With Dynamic DNS, you can create a host name like yourserver.example.com. This host name will allow you to find your home server even if your IP address changes.

Using Dynamic DNS

To use Dynamic DNS, you need to be using our name servers. Any domain registered with us can use our name servers and Dynamic DNS at no extra cost.

If you are not already using our Custom DNS, please follow these steps to set it up:

  1. Log into the Domain Name Management System.
  2. Click the domain to update.
  3. If Custom DNS is already on, click Edit DNS.
    If Custom DNS is not on, click Use our DNS, and confirm changing the name servers.
  4. Add any records that won’t be updated with Dynamic DNS. You can add records individually, or you can import a DNS zone file with multiple records
  5. Click Enable Dynamic DNS.
  6. Read and agree to the Pair Domains Terms of Service and the Pair Domains Dynamic DNS Terms of Service.
  7. Click Enable Dynamic DNS.
  8. You will be given a  Dynamic DNS Key. You will need this later. It is a good idea to copy it and save it somewhere, but you can come back to this screen to get the key again later.

Finally, you will need to set up a client on your computer to contact us when your IP address changes. We provide a Web client:

  1. Go to: https://dynamicdns.pairdomains.com/
  2. Enter your Dynamic DNS Key and the hostname you want to update. If you want to update dynamic.example.com, you would enter it here, and click Continue.

    *Important* If you previously had a record set up in your Custom DNS for dynamic.example.com, it will now be over-written, and the old information will be lost.
  3. Read the next page, agree to the Terms of Service, and click Enable Dynamic DNS.
  4. Minimize your browser window and leave it running. As long as the window is open, your DNS will continue to update.

Other Dynamic DNS Clients

You can use other Dynamic DNS clients that support the dyndns2 protocol. When you set up your client, you can enter this information:

Username: pairdomains
Password: dynamic_dns_key
Alias or Host Name: the domain or sub-domain that you want to update
Dynamic DNS Server Name: dynamic.pairdomains.com
Dynamic DNS Server URL: /nic/update?
IP Server Name: myip.pairdomains.com /

The IP Server Name field might need to be entered as “Other Information” or “Other Settings” using this format: ip_server_name myip.pairdomains.com /

Please note: connections should be limited to every 5 minutes (300 seconds).

Direct URL

If you want to call a URL directly, this format will work:

https://pairdomains:dynamic_dns_key@dynamic.pairdomains.com/nic/update?hostname=hostname_to_update

ddclient

ddclient is a Perl based dynamic DNS client available from SourceForge. To run ddclient, you should create a configuration file named ddclient.conf. It should contain this information:

daemon=300 # check every 300 seconds
syslog=yes # log update msgs to syslog
pid=/var/run/ddclient.pid
ssl=yes
use=web,
web=https://myip.pairdomains.com/,
web-skip=’IP Address:’
protocol=dyndns2
server=dynamic.pairdomains.com
login=pairdomains
password=dynamic_dns_key
hostname_to_update

Before running it, make sure that there is a /var/cache directory on your computer. If you do not have one already, you can make one. Then this command can be used to run ddclient:

sudo /full/path/to/ddclient -daemon=0 -file /full/path/to/ddclient.conf

If you run into problems with ddclient, please run this command and send us the full output:

sudo /full/path/to/ddclient -debug -verbose -noquiet -daemon=0 -file /full/path/to/ddclient.conf

Router Software

DD-WRT software can be run directly on some routers. These settings should work:

DDNS Service: Custom DYNDNS
DYNDNS Server: dynamic.pairdomains.com
Username: pairdomains
Password: dynamic_dns_key
Hostname: hostname you want to update
URL: /nic/update?
Additional DDNS Options: –ip_server_name myip.pairdomains.com /
Use external ip check: no
Use SSL: yes
Force update interval:10

pfSense is an open source firewall/router computer software distribution based on FreeBSD. These settings should work:

Service Type: Custom
Username: [leave blank]
Password: [leave blank]
Update URL: https://pairdomains:dynamic_dns_key@dynamic.pairdomains.com/nic/update?hostname=hostname_to_update

Unifi Gateway

If you use Unifi Gateway, you can use this information in your configuration file

Service: custom
hostname = “hostname you want to update”
username = “pairdomains”
password = “dynamic_dns_key”
ddns-server = “dynamic.pairdomains.com/nic/update?hostname=hostname_to_update”

Pointing Domains to Other Providers

Some hosting providers give you name servers to use with your domain and some ask you to create DNS records. You can find instructions for changing name servers or for creating records for several popular providers below.

Is your provider not listed above? Are any instructions for providers out-of-date? Please contact us and we can help you update your domain, and we can add or update instructions on this page.