# Set DNS with GoDaddy

Connect a GoDaddy account once. MainPath writes A and CNAME records into your zone.

> Source: https://www.mainpath.ai/en/docs/dns-godaddy/

If your domain lives at [GoDaddy](https://www.godaddy.com/), you no longer have to copy records by hand. You store access under **Connections**; once a project has domains, MainPath writes the records into the matching zone.

Manual DNS is still possible. See [Configure a DNS record]({{< relref "domain-how-to" >}}).

## Access at GoDaddy

MainPath talks to the **GoDaddy Domains API** (`api.godaddy.com`). A **Personal Access Token (PAT)** from the [developer portal](https://developer.godaddy.com/) is the recommended option. Classic key/secret pairs still work, but they are no longer the first choice for new connections.

1. Sign in to your GoDaddy account and open the [developer portal](https://developer.godaddy.com/).
2. Create a **Personal Access Token**. For DNS the scopes **`domains.domain:read`** and **`domains.dns:update`** are enough.
3. Copy the token. Alternatively create a classic API key and secret.

In MainPath:

- PAT: fill in only the token field and leave the secret empty.
- Classic: put key and secret in the two fields. Or `key:secret` in a single line in the key field.

The domain must use GoDaddy nameservers (`ns*.domaincontrol.com`). External nameservers (Cloudflare, Hetzner, …) cannot be managed through this API.

## Connection in MainPath

1. Open **Connections** and **Add connection**.
2. Under **DNS**, choose the **GoDaddy** tile.
3. Paste the credentials and save. MainPath checks whether they are valid and which domains they can see.

Several GoDaddy connections in one organization are allowed. If a hostname matches more than one zone, MainPath uses the most specific one.

## What is written

MainPath uses the same hosts you see under **Domains**.

- Records are only written when a real server address already exists.
- Existing records of the same name and type are updated; the whole zone is never replaced.
- Changes usually show up quickly.

```mermaid
flowchart LR
  org["GoDaddy connection"]
  domains["Domains in MainPath"]
  zone["GoDaddy zone"]
  server["Your server"]
  org --> zone
  domains -->|"A / CNAME"| zone
  zone --> server
```

After you save a project, MainPath tries to align missing or mismatched records. You can see the check status in the domain overview.

## SSL via DNS-01 (optional)

If Let's Encrypt cannot reach the server (no public HTTP/443, firewall, internal IP), open this connection's details and tick the affected domains. MainPath then writes the `_acme-challenge` TXT record into this zone. Unticked domains keep the existing TLS-ALPN challenge on the server.

## Troubleshooting

- **Invalid access**: Check that the PAT has `domains.domain:read` and `domains.dns:update`, or that key and secret have no spaces. A token from another GoDaddy product (Auctions, OTE sandbox) is the wrong type.
- **No record at GoDaddy**: The domain is not in this account, or it uses other nameservers.
- **Zone visible, domain unreachable**: The domain exists at GoDaddy, but the nameservers point elsewhere. MainPath flags this in the connection details and on Domains. Point the nameservers at the registrar to GoDaddy (`ns*.domaincontrol.com`).
- **Status in MainPath still red**: DNS often takes a few minutes, or the server does not have a known address yet.

## See also

- [Domain setup]({{< relref "domain" >}})
- [Configure a DNS record]({{< relref "domain-how-to" >}})
- [Connections]({{< relref "connections" >}})
- [Set DNS with Cloudflare]({{< relref "dns-cloudflare" >}})

