Skip to main content

Documentation

No results found.
Features Members

Domains & DNS

Connect your domain without leaving the dashboard. Domains & DNS is guided DNS setup, not a DNS editor: instead of a raw record table, it offers a handful of tasks where WebProCMS fills in the correct values for you — because the site a...

Connect your domain without leaving the dashboard. Domains & DNS is guided DNS setup, not a DNS editor: instead of a raw record table, it offers a handful of tasks where WebProCMS fills in the correct values for you — because the site already knows where it lives — shows exactly what will change, and only writes after you confirm. A read-only health check works with any DNS host, even ones the feature can't write to.


What it does

  • DNS health check (works with zero setup): six read-only checks for any domain — where its DNS is hosted, whether the domain and www point at this site, SPF sanity (exactly one record — multiples are invalid and kill deliverability), DMARC presence, and whether CAA records would block Let's Encrypt certificate renewal. Every failing check includes the exact record to add, so it's useful even when your DNS host isn't supported for direct editing — you get "type exactly this" instructions instead.
  • Connect this domain: points the domain and www at the site in one confirmed step. The target address is pre-filled (admin override → server address → DNS of the current host); on Cloudflare an "orange cloud" proxy toggle is offered and recommended.
  • Add a verification record: guided TXT for Google Search Console, Bing, DKIM keys from your email provider — any "paste this host and value" flow. Exact duplicates are detected and reported as already set.
  • Email deliverability: writes your SPF record (enforcing the single-record rule — an existing different SPF becomes a shown-diff replace, multiple existing SPFs are flagged for manual cleanup) and a starter DMARC (v=DMARC1; p=none; — monitoring-only, no delivery impact).
  • Before/after confirmation on every write: each task plans first and shows per-record actions — Add, Replace (with the old value struck through), Already set, or Blocked. Nothing is written until you confirm.
  • A hard safety guarantee: the feature keeps a ledger of every record it creates and can only remove records from that ledger. Records it didn't create are never deleted — conflicting records (an existing CNAME in the way, round-robin A sets) are surfaced with instructions, not auto-resolved.

Supported DNS providers

Provider Credential Notes
Cloudflare Scoped API token (Zone → DNS → Edit + Zone → Zone → Read) Never the Global API Key. Proxy (orange cloud) supported.
DigitalOcean Personal access token with domain read/write
Linode (Akamai) Personal access token, Domains scope Read/Write
Vultr Account API key Vultr enforces an IP allowlist — add the server's IP in Vultr's API settings.

Hosted elsewhere (GoDaddy, Namecheap, Squarespace, Route 53, …)? The health check detects that and the failing checks show the records to enter manually at your host.

Setup

  1. Turn on Settings → Features → Domains & DNS (Site & Compliance group).
  2. Open Settings → Domains (or the sidebar Domains entry → Settings), pick your provider, paste a token, and Save & verify — the zones the token can see are listed immediately as confirmation.
  3. Optionally set Where this site lives (server IP or hostname) if the site sits behind a load balancer or proxy; otherwise it's auto-detected.
  4. Open Domains in the sidebar, pick a zone, and run the health check or a guided task.

Security notes

  • API tokens are stored encrypted in the settings table. If the site's APP_KEY ever changes, the token degrades to a "re-enter your token" prompt — never an error page.
  • The token is write-only in the UI: it's never redisplayed, and never rendered into page payloads.
  • Scope tokens to DNS-only permissions (and, where the provider supports it, to specific zones) so the stored credential can't do anything beyond DNS on the zones you chose.
  • All destructive actions are ledger-gated: only records this site created can be removed from the dashboard.

For developers

  • Module: app/Features/Domains/ — DnsProvider contract (Contracts/), one driver per provider (Drivers/), DnsProviderManager (driver resolution + encrypted token store), GuidedDnsTasks (plan/apply engine), DnsHealthCheck + DnsLookup + NameserverDetector + InstallTarget (read-only layer), ManagedDnsRecord (the ledger).
  • Adding a provider driver: implement the 7-method DnsProvider contract (FQDN record names in, provider-relative out — see ConvertsRelativeRecordNames), register it in DnsProviderManager::providers() with a label/token-help URL, and add a driver contract test mirroring tests/Feature/Domains/CloudflareDnsProviderTest.php. No UI changes needed — the settings dropdown and all tasks pick it up.
  • Drivers use the Http client directly (no SDK dependencies) and map raw API errors to user-safe DnsProviderException messages.