RHost Documentation
Everything you can do with RHost — register or transfer a .rw domain, manage its DNS, and keep it renewed, all from one account.
Introduction#
What is RHost?#
RHost is an accredited RICTA registrar. It brings your domain registration and its DNS together under one account: register a new .rw domain, transfer one in, or bring a domain you own elsewhere and host its DNS here.
Everything a domain needs is in one dashboard — records, DNSSEC, glue hosts, zone import and export, WHOIS contacts, transfer locks and auth codes, expiry alerts and renewals.
RHost's DNS is powered by PowerDNS — a proven, high-performance open-source nameserver used by some of the world's largest DNS operators. Changes you make in the dashboard are reflected in the DNS within seconds.
How it works#
The flow to get your domain live on RHost is straightforward:
- 1
Add your domain
Enter your domain name in the Domains dashboard. RHost immediately creates a DNS zone and seeds it with default SOA and NS records.
- 2
Set up your DNS records
Add all the records your domain needs — A, AAAA, MX, CNAME, TXT, and so on. If RHost can auto-import your existing records from your current provider, it will do so automatically.
- 3
Point your nameservers
Log in to your domain registrar and update the nameservers to RHost's nameservers. Once propagated, all DNS queries for your domain will be answered by RHost.
Platform nameservers#
When adding a domain to RHost, you will need to update your nameservers at your registrar to point to the following:
| Nameserver | Role |
|---|---|
ns1.rhost.rw | Primary nameserver |
ns2.rhost.rw | Secondary nameserver |
Both nameservers read from the same database. Changes you make are immediately available on both ns1 and ns2 — there is no zone transfer delay.
Getting Started#
Create an account#
Navigate to rhost.rw/auth/signup and complete the three-step registration form:
- Step 1 — Personal information: first name, last name, email address, and optional phone number.
- Step 2 — Organisation details: company name, address, city, and country (all optional).
- Step 3 — Password: choose a strong password, confirm it, and accept the terms of service.
You can also sign up using your Google or GitHub account via the OAuth buttons on the signup page. After registration, a verification email will be sent to your address.
Enable two-factor authentication (2FA) after registration. Go to Settings → Security and toggle on Email OTP authentication for an additional layer of account protection.
Your account#
Your account groups your domains, DNS zones, and team members together — every domain belongs to your account. It's created automatically when you sign up; there's nothing to set up.
Team members can be invited to your account with their own roles and permissions.
Add your first domain#
Once you have a workspace selected, navigate to Domains in the sidebar. In the Add a domain you already own panel, type your domain name and click Add domain.
RHost will immediately:
- Create a DNS zone for your domain.
- Seed the zone with default SOA and NS records.
- Attempt to auto-import your existing DNS records from your current provider.
You will be redirected to the domain detail page where you can review imported records, add new ones, and eventually point your nameservers to go live.
Buying a Domain#
Search & availability#
To register a brand-new domain, go to Domains → Register and type the name you want. RHost checks availability live against the global registry (via RDAP) and shows you which extensions are free, which are taken, and the yearly price of each.
- Available — free to register right now, with its price shown per year.
- Registered — already owned by someone else. If you own it elsewhere, you can add it as an external domain or transfer it in instead.
- Unsupported — the extension (TLD) is not one RHost sells yet.
Prices vary by extension — for example .com, .rw, and .io each have their own yearly rate. The price you see at search is the price you pay at checkout.
Registering a domain#
Pick one or more available domains and continue to checkout. You'll choose a registrant contact (the legal owner of the domain — see below), then pay securely by card. As soon as payment succeeds, RHost:
- Registers the domain in your name.
- Creates its DNS zone and points it at RHost's nameservers automatically — no manual nameserver step needed for domains bought here.
- Adds it to your Domains dashboard, ready for records.
Registered vs external domains#
RHost handles two kinds of domain. The difference is only about where the registration lives — both get the full DNS dashboard.
| Registered with RHost | External (registered elsewhere) |
|---|---|
| You buy and renew the domain here; billed yearly. | You keep it at your current registrar; you renew it there. |
| Nameservers are pointed automatically. | You point the nameservers to RHost yourself. |
| Included in the registration price. | A small yearly managed-DNS-hosting fee applies. |
Domain contacts#
Every registered domain needs a registrant contact — the person or organisation that legally owns it. Manage these under Contacts. You can reuse one contact across many domains, and update details (address, phone, email) in one place.
RHost keeps your personal contact details private in public WHOIS/RDAP lookups. Registrant information is redacted so your name, address, and email are not exposed to the public internet.
Transferring a domain in#
To move a domain's registration to RHost, open Domains → Transfer in, enter the domain and the authorization (EPP) code from your current registrar, and submit. You can track the request's status and cancel it while it is still pending. Transfers follow the standard registry process, so they can take a few days to complete.
Domain Management#
Adding an external domain#
An external domain is a domain you registered at a third-party registrar (Namecheap, GoDaddy, Cloudflare Registrar, etc.) that you want RHost to manage DNS for. You do not need to transfer your domain registration — only the nameservers need to change.
Enter just the root domain (e.g. example.rw) without a trailing dot or any subdomain prefix. RHost normalises the input automatically.
If you add a domain that is already managed by another DNS provider, do not update your nameservers until you have fully configured all your records in RHost. Switching nameservers before your records are ready will cause downtime.
Domain lifecycle#
Every domain in your inventory has two status indicators:
| Badge | Meaning |
|---|---|
| Active | Zone exists and is configured in RHost. DNS records can be managed. |
| Nameservers not pointed | Zone is ready but the domain's nameservers at the registrar still point elsewhere. Queries will not reach RHost yet. |
| Live | Nameservers are confirmed to be pointing to RHost. The domain is fully live. |
| Suspended | Domain has been suspended. Contact support. |
Pointing nameservers#
Once your DNS records are fully configured, the final step is to update your nameservers at your registrar. The exact steps depend on your registrar but generally follow this pattern:
- 1Log in to your domain registrar's control panel.
- 2Navigate to your domain's management page.
- 3Find the Nameservers or DNS section.
- 4Switch from the default nameservers to custom nameservers.
- 5Enter ns1.rhost.rw and ns2.rhost.rw.
- 6Save the changes.
After saving, use the Check nameservers button on the domain detail page to confirm that RHost can see the NS change. Propagation typically takes between 30 seconds and 48 hours depending on your registrar and the TTL of your previous NS records.
To minimise propagation time, lower your NS record TTL to 300 seconds (5 minutes) at your current provider at least 24 hours before switching. This means resolvers around the world will refresh their cache within 5 minutes of your change.
Expiry alerts#
RHost can notify you before a domain expires so you can take action in time. To configure alerts:
- Open a domain's detail page.
- Click Expiry alerts in the header.
- Choose which days before expiry you want to be alerted (e.g. 90, 30, 7, 1 days).
- Toggle email and in-app notifications on or off independently.
- Use the Send test email button to verify delivery.
Expiry alerts are sent daily at 08:00 UTC. If you configure an alert for 30 days before expiry and today is exactly 30 days before the expiry date, you will receive the notification that morning.
DNS Records#
Record types reference#
RHost supports all standard DNS record types. Below is a reference of the most commonly used ones:
| Type | Description | Value example |
|---|---|---|
A | Maps a hostname to an IPv4 address. | 192.168.1.1 |
AAAA | Maps a hostname to an IPv6 address. | 2001:db8::1 |
CNAME | Canonical name — aliases one hostname to another. Cannot coexist with other records at the same name. | www → example.rw. |
MX | Mail exchange — specifies the mail server responsible for accepting email for the domain. Requires a priority value. | 10 mail.example.rw. |
TXT | Arbitrary text data. Used for SPF, DKIM, DMARC, site verification, and other purposes. | v=spf1 include:_spf.google.com ~all |
NS | Nameserver records — delegates a zone to a set of nameservers. Locked by RHost and cannot be edited directly. | ns1.rhost.rw. |
SOA | Start of Authority — metadata about the zone (primary NS, contact email, serial, refresh intervals). Managed automatically by RHost. | ns1.rhost.rw. hostmaster.example.rw. 1 … |
SRV | Service locator — specifies host and port for a specific service. Requires priority, weight, and port. | 10 20 5060 sip.example.rw. |
CAA | Certification Authority Authorisation — restricts which CAs can issue SSL/TLS certificates for the domain. | 0 issue letsencrypt.org |
PTR | Pointer record for reverse DNS lookups. Maps an IP address back to a hostname. | example.rw. |
Creating records#
Navigate to a domain's DNS Records tab and click Add record. Fill in the record modal:
- TypeSelect the DNS record type from the dropdown.
- NameThe hostname. Use @ for the zone apex (root domain), or enter a relative label like www, mail, _dmarc. RHost will automatically append the domain name.
- ValueThe record's content. For A records this is an IPv4 address; for CNAME it is the target hostname ending with a dot; for MX it is the mail server hostname.
- TTLTime To Live in seconds. Controls how long resolvers cache this record. Default is 300 seconds. Lower values allow faster changes but increase DNS query load.
- PriorityOnly visible for MX and SRV records. Lower numbers have higher priority.
Newly created records are immediately active and served by PowerDNS. There is no confirmation step for manually created records — only auto-imported records require confirmation.
Editing and deleting records#
Hover over any record row in the DNS tab and click the edit (pencil) icon to modify it, or the delete (trash) icon to remove it.
SOA and NS records are locked and cannot be edited or deleted. These records are managed by RHost to ensure zone integrity.
Deleting an A or MX record that is actively in use will immediately stop DNS resolution for that hostname. Always confirm records are no longer needed before deleting them.
Pending vs active records#
When RHost auto-imports records from your existing DNS provider, they are created as pending. Pending records are stored in the database but are disabled in PowerDNS — resolvers will not serve them until you confirm.
This gives you the opportunity to review the imported records before they go live. In the DNS Records tab:
- Pending records are shown with an amber Pending badge.
- Click Confirm All to activate all pending records at once.
- Or select individual records and confirm them one at a time.
- Once confirmed, records are immediately served by PowerDNS.
History and rollback#
Every create, update, and delete action on DNS records is logged in the domain's History tab. Each entry shows:
- The action type (created, updated, deleted).
- The record type and name.
- The old and new values (for updates).
- The email address of the user who made the change.
- A timestamp.
Click Rollback on any history entry to instantly revert that record to its previous state. Rollbacks are themselves logged in the history.
Zone Management#
Importing a zone file#
RHost supports importing BIND-format zone files (.zone files). This is useful when migrating from another DNS provider that can export zone files.
Navigate to the Import / Export tab and paste or upload your zone file. RHost will:
- Validate the zone file format (must include SOA and at least two NS records).
- Delete existing non-locked records of the same types found in the import.
- Stage all parsed records as pending (disabled) for your review.
- Leave SOA and NS records untouched (they are locked).
After the import, go to the DNS Records tab and click Confirm All to activate the imported records.
A valid BIND zone file looks like this:
$ORIGIN example.rw.
$TTL 300
; SOA
@ IN SOA ns1.rhost.rw. hostmaster.example.rw. (
2024010101 ; serial
10800 ; refresh
3600 ; retry
604800 ; expire
300 ) ; minimum TTL
; Nameservers
@ IN NS ns1.rhost.rw.
@ IN NS ns2.rhost.rw.
; A records
@ IN A 192.168.1.1
www IN A 192.168.1.1
mail IN A 192.168.1.2
; MX record
@ IN MX 10 mail.example.rw.
; TXT record (SPF)
@ IN TXT "v=spf1 ip4:192.168.1.0/24 ~all"Exporting a zone file#
To export your zone as a BIND-format file, navigate to Import / Export and click Export zone file. The exported file contains all active records for the zone and can be imported into any BIND-compatible DNS server.
The SOA serial number is automatically incremented each time you export the zone file. This ensures that secondary nameservers correctly recognise the zone as newer.
Zone file editor#
For advanced users, RHost provides a full zone file text editor. Navigate to Import / Export → Open zone editor. You can edit the raw zone file directly and save — changes are parsed and staged as pending records, following the same import flow.
The zone editor is a power-user feature. Syntax errors will be rejected with a clear validation message, but always double-check your edits before saving. Incorrectly configured records can disrupt your site, email, or other services.
DNSSEC#
What is DNSSEC?#
DNSSEC (DNS Security Extensions) is a suite of specifications that adds cryptographic authentication to DNS responses. Without DNSSEC, an attacker who can intercept DNS traffic could forge responses and redirect your visitors to malicious servers — a technique called DNS cache poisoning.
When DNSSEC is enabled, each DNS response includes a digital signature. Validating resolvers check this signature against a chain of trust anchored at the root DNS zone. If the signature does not match, the resolver discards the response and the domain is unreachable from that resolver.
Enabling DNSSEC#
Navigate to the DNSSEC tab on your domain's detail page and click Enable DNSSEC. RHost will:
- Generate a KSK (Key Signing Key) using ECDSA P-256 SHA-256 (algorithm 13) — the recommended modern algorithm.
- Sign all records in the zone.
- Provide you with DS (Delegation Signer) records to add at your registrar.
DNSSEC is only effective once you have added the DS records at your registrar. Until the DS records are in place, DNSSEC is signed but not validated — resolvers will not enforce it. Publishing DS records without correct NSEC/RRSIG records will break resolution for validating resolvers.
DS records#
After enabling DNSSEC, the DS records panel will display the DS record(s) you need to add at your registrar. They look like this:
12345 13 2 ABCDEF1234567890ABCDEF1234567890ABCDEF1234567890ABCDEF1234567890
The fields are: Key Tag, Algorithm (13 = ECDSA P-256), Digest Type (2 = SHA-256), and the Digest itself.
Copy these values into your registrar's DNSSEC DS record configuration. Once the parent zone (e.g. the .com registry) publishes the DS record, the chain of trust is complete.
Billing & Payments#
How pricing works#
RHost only charges for what you switch on. There are a few kinds of charge:
- Domains — a yearly fee to register or renew (or a small yearly managed-DNS fee for external domains).
- Transfers — a flat fee to transfer a domain in, where one is published for that TLD.
If a promotion is running, the discount is shown right on the price (with the original struck through) and applied automatically at checkout.
Paying (checkout)#
All payments go through a secure checkout. You're redirected to enter your card details, and as soon as the payment succeeds RHost activates the service and brings you back to the dashboard. You never enter card numbers directly into RHost.
RHost will never ask you to send card numbers, passwords, or codes by email or chat. Enter payment details only on the secure checkout page you're redirected to.
Receipts & payment history#
The Billing page in the console lists every payment you have made, with a receipt for each one you can open and save as a PDF. Nothing is kept on file between payments — there is no stored card to manage, because each term is paid for when it falls due.
Renewals & auto-renew#
A domain is prepaid for its term. RHost emails you before it expires, and you renew by paying again for as many years as you want. Auto-renew can be switched on from the domain's page, but it only works where a payment method can be charged without you — otherwise the reminder is what keeps the domain alive, so do not ignore it.
Team & Members#
Your account & team#
Your account is the home for everything you own — your domains, DNS zones, billing, and the teammates who help you manage them. It's created automatically when you sign up; there's nothing to configure.
| Concept | Detail |
|---|---|
| Scope | All your domains, records, and history live under your account. |
| Team members | Invite people to help manage your domains, each with their own role. |
Inviting members#
To invite a team member to a workspace:
- 1Navigate to Settings → Workspace in the console.
- 2Click Invite member and enter their email address.
- 3Select their role (Owner, Admin, or Member).
- 4Click Send invitation.
The invitee will receive an email with a link to accept the invitation. They must have an RHost account (or create one) before the invitation can be accepted.
DNS Tools#
RHost provides a suite of free, public DNS diagnostic tools at /tools. No account is required.
DNS Lookup#
Query any DNS record type for any domain in real time. Enter a hostname, select a record type (A, MX, TXT, etc.), and get the current live response from a public resolver.
Useful for: verifying that a new record has propagated, checking MX configuration, confirming TXT records like SPF and DMARC are published correctly.
WHOIS Lookup#
Retrieve WHOIS registration data for any domain — registrar, registration date, expiry date, nameservers, and registrant contact information where publicly available.
Note that WHOIS privacy protection (offered by most registrars) will mask the registrant's personal contact details.
DNS Propagation Checker#
Check whether a DNS change has propagated to multiple public resolvers around the world simultaneously. Enter a hostname, select a record type, and see the response from Google (8.8.8.8), Cloudflare (1.1.1.1), Quad9 (9.9.9.9), and others.
Useful for: confirming that a nameserver change or record update has propagated globally, or diagnosing inconsistent resolution in different geographic regions.
DNS Health Checker#
Run a comprehensive health check on a domain's DNS configuration. The tool checks for common misconfigurations including:
- Missing or misconfigured MX records.
- Missing SPF, DKIM, and DMARC TXT records.
- SOA serial and refresh interval validity.
- Nameserver consistency across multiple resolvers.
- DNSSEC chain-of-trust validation.
TTL Calculator#
Convert TTL values between seconds and human-readable formats (minutes, hours, days). Useful for planning TTL changes before a migration — enter a TTL in seconds and see exactly how long resolvers will cache that record.
Frequently Asked Questions#
How long does DNS propagation take?#
Propagation time depends on two things: the TTL of the record being changed, and how aggressively resolvers respect TTLs. In practice:
- Records with a TTL of 300 seconds (5 min) typically propagate globally within 5–15 minutes.
- Records with a TTL of 86400 seconds (24 hours) can take up to 48 hours to propagate fully.
- Nameserver changes (NS records) are typically slower — allow up to 48 hours even with a low TTL.
Before any major DNS change, lower your TTLs to 300 seconds at least 24 hours in advance. This ensures the old TTL has expired everywhere before you make the change.
The nameservers are not pointing — what should I do?#
If the Check nameservers button still shows "Nameservers not pointed" after waiting for propagation:
- Double-check that you saved the nameserver change at your registrar. Log back in and confirm ns1.rhost.rw and ns2.rhost.rw are listed.
- Some registrars require nameservers to be registered (glue records) before they can be used. RHost nameservers are already registered — no glue records needed.
- Wait the full 48 hours. Propagation for NS changes is legitimately slow with some registrars.
- Use the DNS Propagation Checker tool to query your domain's NS record type from multiple resolvers and confirm what they are returning.
I confirmed my records but they are not resolving#
If your records are confirmed (active, not pending) but queries are still not resolving as expected:
- Verify that your domain's nameservers are pointing to RHost (check the Live badge on the domain overview).
- Ensure the record type and name are correct. Use the DNS Lookup tool to query your domain directly.
- Check that you do not have a conflicting CNAME at the zone apex — CNAME records cannot coexist with other record types at the same name.
- If you recently added the record, allow a few seconds for it to propagate through the packet cache.
Should I enable DNSSEC?#
Yes, if your registrar supports DS record management (most modern registrars do). DNSSEC adds a meaningful layer of security against DNS spoofing and cache poisoning attacks with minimal performance overhead.
The main caveat is that once you enable DNSSEC and add DS records at your registrar, you must not disable DNSSEC or delete the zone in RHost without first removing the DS records from your registrar. Leaving orphaned DS records at the registrar will cause DNSSEC validation to fail and make your domain unreachable from validating resolvers.
Still have questions?
Contact our support team or browse the console to explore features hands-on.