# Connect your registrar

> Why Maildeck needs access to your domain registrar, what to enter in Quick Start and how to keep that access safe.

Source: https://docs.maildeck.co/domains-dns/connect-your-registrar/

To send email from your domains, each one needs a handful of technical settings called **DNS records**. You don't have
to set any of them yourself. Instead, you give Maildeck access to the registrar where you bought the domains, and our
team adds the records for you.

## What the access is used for

Your registrar is where your domains' settings live. With access, our team can:

- add the DNS records that let your domains send email (SPF, DKIM, DMARC and the rest),
- point the domains to Outlook, Google Workspace or your SMTP servers, depending on what you ordered,
- fix a record later if something stops checking out.

Quick Start says it plainly: credentials are encrypted and only used for DNS configuration.

> **Note**
> Curious what those records actually do? See [SPF, DKIM and DMARC](https://docs.maildeck.co/domains-dns/spf-dkim-dmarc/).

## What Quick Start asks for

In the **Domains** step of Quick Start you'll see a short form after you paste your domains:

| Field | Required? | What it is |
|---|---|---|
| Registrar | Yes | Porkbun, Namecheap, GoDaddy, or Other (then type its name) |
| Email / Username | Yes | The login for your registrar account |
| Password | Yes | The password for that account |
| Registrar API key | Optional | A key that lets software change DNS for you. Only fill it in if your registrar issued one. |
| Registrar secret key | Optional | Some registrars (Porkbun, for example) issue a secret key alongside the API key |

### Login vs API key

- **The login** (email and password) lets our team sign in to your registrar account and set the records by hand.
  Some registrars only let you change DNS from their website, which is why the login is required.
- **An API key** lets our tools change DNS records directly, without signing in. It's a nice extra where your registrar
  offers one. On Porkbun you'll find it under Account, then API Access, and it starts with `pk1_` (the secret key
  starts with `sk1_`).

## Turn off two-factor login for setup

If your registrar account uses two-factor authentication (2FA, the extra code from your phone or an app), Quick Start
asks you to **switch it off temporarily**. Our team can't receive your codes, so 2FA would block them from signing in.

1. Turn off 2FA in your registrar account settings.
2. Tick **I've disabled 2FA** in Quick Start.
3. Once your order shows as set up on the dashboard, turn 2FA back on.

## Keep your registrar access safe

- **Only enter credentials in Quick Start.** Never paste passwords or API keys into chat, email or Slack messages.
  Maya will never ask for them.
- **Use a separate registrar account for sending domains** if you can, so it doesn't hold your main company domain.
  That way, the access you share only touches the domains you bought for cold email.
- **Use a strong, unique password** for the registrar account.
- **Turn 2FA back on** once setup is done.
- **In a team workspace**, only Owners and Admins can see registrar logins in the app.

> **Caution: Changing the password later**
> If you change your registrar password after ordering, our team can't get in to fix records. Tell the team before you
> change it so nothing gets stuck.

## What if the access is wrong?

If the login doesn't work, or 2FA is still on, our team can't add the DNS records. Without those records the domains
can't send, so setup for those domains waits until access is fixed.

If you think you typed something wrong, or you changed your password, message a person rather than placing a new
order: use your private Slack channel or the chat bubble in the app. Don't send the new password in the message; the
team will tell you how to update it safely.

## Related

  - [Choosing and buying domains](https://docs.maildeck.co/domains-dns/domains/): Naming, how many you need and where to buy.
  - [SPF, DKIM and DMARC](https://docs.maildeck.co/domains-dns/spf-dkim-dmarc/): What we set up on your domains.
  - [Your first order](https://docs.maildeck.co/getting-started/your-first-order/): Quick Start, screen by screen.
  - [Getting help](https://docs.maildeck.co/support/getting-help/): Where to reach a person.
