# Set DNS with Hostinger

Connect a Hostinger API token once. MainPath writes A and CNAME records into your DNS zones.

> Source: https://www.mainpath.ai/en/docs/dns-hostinger/

If your domain's DNS zone lives at [Hostinger](https://www.hostinger.com/), you no longer have to copy records by hand. You store an API token under **Connections**; once a project has domains, MainPath writes the records into the matching zone.

Manual DNS is still possible. See [Configure a DNS record]({{< relref "domain-how-to" >}}).

## API token at Hostinger

MainPath talks to the **Hostinger DNS API** (`developers.hostinger.com`). The existing Hostinger connection under **Servers** is **not** reused automatically for DNS. DNS gets its own tile, even if you paste the same token text there.

1. Sign in to [hPanel](https://hpanel.hostinger.com/) and open **API** / tokens.
2. Create a token that can list domains and manage DNS zones.
3. Copy the token. It is shown only once.

The domain must use Hostinger nameservers, for example `ns1.dns-parking.com`, `ns1.ns.hostinger.com`, or `ns1.hostinger.com`.

## Connection in MainPath

1. Open **Connections** and **Add connection**.
2. Under **DNS**, choose the **Hostinger DNS** tile.
3. Paste the API token and save. MainPath checks whether the token is valid and which zones it can see.

Several Hostinger DNS connections in one organization are allowed. If a hostname matches more than one zone, MainPath uses the most specific one.

## What is written

MainPath uses the same hosts you see under **Domains**.

- Records are only written when a real server address already exists.
- Existing records of the same name and type are updated; the whole zone is never replaced.
- Changes usually show up quickly.

```mermaid
flowchart LR
  org["Hostinger DNS connection"]
  domains["Domains in MainPath"]
  zone["Hostinger zone"]
  server["Your server"]
  org --> zone
  domains -->|"A / CNAME"| zone
  zone --> server
```

After you save a project, MainPath tries to align missing or mismatched records. You can see the check status in the domain overview.

## SSL via DNS-01 (optional)

If Let's Encrypt cannot reach the server (no public HTTP/443, firewall, internal IP), open this connection's details and tick the affected domains. MainPath then writes the `_acme-challenge` TXT record into this zone. Unticked domains keep the existing TLS-ALPN challenge on the server.

## Troubleshooting

- **Invalid token**: Create a Hostinger API token with DNS rights. A token that can only manage VPS is not enough.
- **No record at Hostinger**: The domain is not in the account this token can see. Check the domain name.
- **Zone visible, domain unreachable**: The zone exists at Hostinger, but the domain's nameservers point elsewhere. Point the nameservers at the registrar to Hostinger (`*.dns-parking.com` / `*.ns.hostinger.com`).
- **Status in MainPath still red**: DNS often takes a few minutes, or the server does not have a known address yet.

## See also

- [Domain setup]({{< relref "domain" >}})
- [Configure a DNS record]({{< relref "domain-how-to" >}})
- [Connections]({{< relref "connections" >}})
- [Hostinger]({{< relref "hostinger-tutorial" >}})

