
Photo: Jordan Harrison
Clients often arrive with a Figma file and a company name. Then we stall on a different list: domain, hosting, DNS, nameservers, SSL, email / SMTP. None of that is the website design. All of it is the road the website drives on.
This is a map in everyday language. You do not need to configure these yourself. You do need to know what each invoice is for, and why “the site is ready but hello@yourbrand.com never arrives.”
If you already mix up WordPress.com and self-hosted WordPress, read that .org vs .com guide first. Hosting sits in that story too.
The one-sentence picture
Domain is the name people type. Hosting is the computer that stores the files. DNS / nameservers are the phone book that connects the name to that computer. SSL is the padlock (https). SMTP is how the site sends email (contact forms, password resets). Miss one, and the pretty pages never really “go live.”

Photo: Kvistholt Photography
1. Domain — the address
A domain is yourbrand.com (or .in, .co, .studio). You rent it yearly from a registrar (GoDaddy, Namecheap, Google Domains successors, your host’s domain shop). It is not the website. It is the sign on the street.
- Buy it in the company’s name, not the freelancer’s. You must be able to recover it if the designer leaves.
- Turn on privacy / WHOIS protection so your phone number is not on a public list.
- A
.comdomain is not the same as an account at WordPress.com. Same ending, different product.
Typical cost: about $10–20 per year for a common .com, more for trendy endings. Auto-renew. Losing a domain because a card expired is an expensive own-goal.
2. Hosting — the land and the building
Hosting is rented space on a computer that is always on. WordPress files, images, and the database live there. Shared hosting (Hostinger, SiteGround) is fine for most small sites. “Managed WordPress” costs more and handles speed and backups. A $2/month host plus 40 plugins is how sites get slow and hacked.
What you actually get:
- Disk space and traffic (bandwidth)
- A control panel (often cPanel or the host’s own app)
- One-click WordPress, backups, PHP version
- Often a free SSL certificate
The host should be in your account. The agency can have a login. If they own the hosting, you do not own the site.

Photo: Albert Stoynov
3. Nameservers — who runs the phone book
When you buy a domain, the registrar asks: which nameservers? They look like ns1.hostinger.com and ns2.hostinger.com, or Cloudflare’s ada.ns.cloudflare.com.
Nameservers tell the internet: “for this domain, go ask this company for the detailed address book.” Change nameservers when you want the host (or Cloudflare) to manage DNS. Leave the registrar’s nameservers if you will add A records there instead.
This takes hours to a day to spread worldwide (“propagation”). It is not instant. Do not panic-refresh for twenty minutes and then change it again.
4. DNS — the actual records
DNS is the address book inside whichever nameservers you chose. Common rows:
- A record —
yourbrand.compoints to a number (IP) of the host. This is “the website lives here.” - CNAME — an alias.
wwwoften points atyourbrand.com. Some hosts wantwwwas an A record instead. Follow their docs once. - MX — where email is received (Google Workspace, Microsoft 365, the host’s mail). Wrong MX = staff mailboxes die even if the website looks fine.
- TXT — proofs. Google Search Console, SPF, DKIM. Ugly text; important for mail and SEO verification.
- AAAA — like A, but IPv6. Optional until the host gives you one.
Rule of thumb: nameservers = which office holds the book. DNS records = the lines in the book. Mixing both (half the records at GoDaddy, half at Hostinger, nameservers already moved) is the usual “why is the old site still showing?” mess.
5. SSL / HTTPS — the padlock
SSL (now usually a Let’s Encrypt certificate from the host) makes the site https://. Browsers mark plain http as Not Secure. Most hosts turn this on with one click after DNS points at them.
If you see a padlock error after launch, DNS is still old, the cert was issued for www only, or the site still loads mixed http images. It is rarely “buy a $90 certificate.”

Photo: Tyler
6. SMTP — why the contact form never arrives
SMTP is the protocol servers use to send email. Your website is not Gmail. When someone submits Contact Form 7, WordPress tries to send a message. Cheap hosting often gets those messages dumped in spam, or blocked entirely.
Fix: a real sender.
- Transactional SMTP — services like Brevo, Mailgun, Postmark, Amazon SES. A plugin (WP Mail SMTP, FluentSMTP) uses their keys. Forms and “reset password” then land in the inbox.
- Google / Microsoft mailbox —
info@yourbrand.comfor humans. That uses MX records. You can still send form mail through SMTP from the same domain if SPF/DKIM are set. - SPF, DKIM, DMARC — TXT records that say “yes, this server may send as @yourbrand.com.” Without them, Gmail shrugs.
Hosting “email included” is fine for two light mailboxes. It is a poor SMTP engine for a marketing site. Budget SMTP as its own line, even $0–15/month.
Extras that show up on every real project
- SFTP / file manager — how a developer uploads WordPress or a child theme. Not something the client uses daily. Keep the password in a manager.
- Subdomain —
staging.yourbrand.comfor a preview before launch. Needs its own DNS A or CNAME. - CDN (Cloudflare, or the host’s CDN) — copies of images closer to visitors. Optional on day one; useful when the audience is global.
- WWW vs non-WWW — pick one (I prefer the naked domain) and redirect the other. Two versions split SEO.
Who buys what (so you do not lose the keys)
| Item | Who should own the account | Rough yearly feel |
|---|---|---|
| Domain | The company | $10–20 |
| Hosting | The company | ~$40–300+ |
| Google Workspace / Microsoft 365 | The company | per user / month |
| SMTP (forms) | The company, or on the host bill | often free tier, then cheap |
| WordPress / Elementor licenses | The company | theme/plugin list |
The agency builds. The client holds the logins (or a shared 1Password vault). That is how you stay free to change developers.
Launch checklist
- Domain registered, auto-renew on, in the company name
- Hosting account created, WordPress installed
- Nameservers pointed at the host (or Cloudflare), wait for DNS
- A / CNAME records match what the host printed
- SSL on, site loads as https
- MX records for real inboxes, if you use Google/Microsoft
- SMTP plugin + SPF/DKIM so forms do not vanish
- Then — and only then — the Figma-to-Elementor (or theme) build on that URL
Design without this stack is a movie with no cinema. Get the name, the land, the phone book, the padlock, and the mail truck first. The rest of the website can then go live without a week of “it works on my laptop.” Photos via Unsplash (credits under each image).
