# DNS records & traffic, from inside the project

> Edit a domain's DNS records and country filters in Project Settings — and give a collaborator the same access without handing over the domain.

Source: https://knowledge.estage.com/domains/dns-and-traffic/
Part of the ESTAGE knowledge base (https://knowledge.estage.com). Full corpus: https://knowledge.estage.com/llms-full.txt

---
A domain's **DNS records** and its **country filters** are about the site, not about the domain's
paperwork — so they live in the project that uses them: **Project Settings → Domain**, as
**DNS Records** and **Traffic Manager**.

They are the same two screens as in your account's domain page, against the same records. The
difference is where you are standing when you need them: adding an MX record for your site's mail
no longer means leaving the project and finding the right domain first.

## DNS Records

Every record in the zone — the site, your mail, verification strings, anything else it points at.
Add, edit and delete them without leaving the project.

Names are **relative to the zone**: type `_dmarc`, not `_dmarc.mysite.com`. Paste the full host
and it's trimmed for you.

Records marked **System** are Genesis's own — your domain's nameservers, its SOA, and the apex
record aliasing to your site. They aren't editable here, because Genesis rewrites them as your
setup changes.

The `www` record is an ordinary CNAME, so it *is* editable. Genesis creates it when you connect
the bare domain, and points it at the same place — change it only if you mean to.

:::caution
A DNS zone can't be divided. There is no "the part of the domain belonging to this project" — an
edit here reaches every site on the domain, and your email with it.
:::

## Traffic Manager

Which countries may reach the site. Blocked traffic is turned away at the edge, before it reaches
your site at all.

Pick countries by hand, or start from a **preset** — the presets block everything outside a
region, which is the usual shape of the request ("only my country and the EU").

## Connecting a domain

If the project has no custom domain yet, this is also where you connect one: pick a domain your
account already holds, choose whether the project answers on the bare domain or on a subdomain,
and click **Connect**. See [Connecting a domain to a project](/domains/connect/).

A domain that is still being set up — nameservers not pointed yet, or no certificate — is named
here but can't be connected. Finish it on the [domain's own page](/domains/) first.

## Letting a collaborator edit the records

This is the part that matters if you don't work alone. A domain belongs to the ESTAGE **account**
that added it, so until now only that account could change its records. That's fine when you build
for yourself, and wrong the moment you don't: an agency's client owns the domain, a project is
handed to a contractor, and the person actually building the site can't add the record they were
just asked for.

**Project Settings → Roles** now has a **Domain** permission, with the usual two ticks:

| Tick | What it allows |
| --- | --- |
| **View** | See the records and the country filters. Nothing is editable, and the page says so. |
| **Edit** | Change them — on a domain belonging to another account, as long as that domain serves this project. |

**Admin** roles have it already. **Contributor** and **Marketer** don't; a new permission is never
granted by an update.

It's marked **sensitive** for the reason in the caution above: the grant reaches the whole zone,
mail included, and every other site on the domain.

## What it doesn't cover

The Domain permission is records and country filters. It stops there:

- Buying, transferring and deleting a domain
- Nameservers, ownership verification and SSL certificates
- Which projects a domain serves

Those stay with the account that owns the domain, on the [Domains](/domains/) screen — and the
project settings page deliberately doesn't link to them. If the domain is your client's, it isn't
something to wander into from a project.

## Worth knowing

- **One domain, one set of records.** A domain serving several projects shows the same zone in
  each of them, because there is only one.
- **Mobile apps don't show the section.** An Expo app has no address to point anywhere; the domain
  belongs to the website, and is edited there.
