Glossary
Glossary of terms
Domains, DNS records, mail, and SSL in plain language — no jargon where it can be avoided.
Domains and registration
- Domain
- A unique name in the domain name system that identifies a site, mail, or other service on the internet — for example,
example.com.ua. - Zone
- A part of the domain namespace under a given suffix, administered by its own registry — for example,
.com.uaor.ua. - Registry
- The organisation that keeps the database of all domains in a given zone and has the final say on whether a domain is free.
- Registrar
- A company accredited by a registry to register domains on behalf of customers — such as ZRAZU.
- Registrant
- The domain owner: the person or organisation the domain is registered to.
- Trademark
- A registered mark for goods and services; a second-level
.uadomain requires a trademark certificate or an international registration protected in Ukraine. - gTLD, ccTLD
- gTLD — generic top-level domains (
.com,.shop); ccTLD — country-code domains (.ua,.de). - IDN, Punycode
- IDN allows domains with Cyrillic or other non-Latin characters; Punycode is the technical Latin-script encoding of such a name (
xn--…) that every server understands.
DNS and records
- DNS
- The Domain Name System: a distributed database that turns a domain into an IP address and other technical data.
- NS (nameserver)
- A server that stores and serves a zone’s DNS records; a domain’s NS records determine who manages its DNS.
- A record
- A record pointing to a server’s IPv4 address — usually the one that shows where the site lives.
- AAAA record
- The same as an A record, but for an IPv6 address.
- CNAME
- An alias record: a domain or subdomain points to another name instead of a direct IP address. Not allowed on the root domain.
- MX
- A record that sets which server accepts mail for a domain; there can be several MX records with different priorities.
- TXT
- A free-form text record in the zone; often used to verify domain ownership and for SPF/DKIM/DMARC.
- TTL
- The time in seconds a resolver may keep a record cached before asking again.
- DNSSEC
- A DNS extension that cryptographically signs responses so they can’t be tampered with in transit.
- WHOIS
- A public protocol and service for checking who registered a domain, when, and when the registration expires.
- RDAP
- A modern replacement for WHOIS with structured data and clearer privacy rules.
Mail authentication
- SPF
- A TXT record listing the servers allowed to send mail on behalf of a domain.
- DKIM
- A digital signature on an email that confirms it wasn’t altered in transit and really was sent by the domain owner.
- DMARC
- A policy telling mail servers what to do with a message that fails SPF or DKIM, and where to send reports.
SSL and certificates
- SSL/TLS
- Protocols that encrypt the connection between a browser and a site; SSL is the older name — today it’s actually TLS doing the work.
- DV certificate
- A Domain Validation certificate: confirms only that the applicant controls the domain. The encryption is the same as a free certificate’s.
- OV certificate
- An Organization Validation certificate: additionally confirms the site’s owning organisation; the details are visible in the certificate.
- EV certificate
- An Extended Validation certificate with the most thorough organisation check; in modern browsers it looks the same as DV or OV.
- Wildcard certificate
- A certificate that covers a domain and all its subdomains at one level at once (
*.example.com.ua). - ACME
- A protocol for automatically issuing and reissuing SSL certificates (for example, for Let’s Encrypt) with no manual steps.
- Let’s Encrypt
- Let’s Encrypt — a certificate authority that issues free DV certificates with automatic reissuing.
Transfer and lifecycle
- Transfer code (auth code)
- A secret code that confirms the domain owner is the one requesting the transfer to another registrar.
- Transfer lock
- A safeguard that blocks a domain transfer until the owner deliberately lifts it.
- Grace period
- The time after a registration expires when the domain still works and the owner can renew it on ordinary terms.
- Redemption period
- The time after the grace period when the domain no longer works but the owner can still recover it — usually at a higher cost.
- Pending delete
- The final short stage before a domain becomes free for anyone; it can no longer be recovered at this stage.
Technical definitions follow the relevant standards (RFCs); product terms are given as ZRAZU uses them.