If your domain lives at united-domains, you no longer have to copy records by hand. You store an API key under Connections; once a project has domains, MainPath writes the records into the matching zone.
Manual DNS is still possible. See Configure a DNS record.
API key at united-domains
This uses the united-domains DNS API (dnsapi.united-domains.de), the same API model as IONOS Hosting DNS. The domain reselling API and keys from IONOS Cloud will not work here.
- Sign in to your united-domains account.
- Book the DNS API product for the portfolio if it is not active yet.
- Open Getting started with the APIs and create an API key.
- Copy the public prefix and secret. In MainPath you enter them as a single line
prefix.secret(joined with a dot). Do not paste them with a space or a line break.
Without the DNS API product booked, united-domains rejects the key. The API covers every domain in the portfolio whose nameservers point to united-domains (ns.udag.de, ns.udag.net, ns.udag.org).
Connection in MainPath
- Open Connections and Add connection.
- Under DNS, choose the united-domains tile.
- Paste the API key and save. MainPath checks whether the key is valid and which zones it can see.
Several united-domains connections in one organization are allowed. If a hostname matches more than one zone, MainPath uses the most specific one (shop.example.com before example.com).
What is written
MainPath uses the same hosts you see under Domains.
- Records are only written when a real server address already exists.
- Existing records of the same type are updated; the whole zone is never replaced.
- Changes usually show up quickly.
flowchart LR org["united-domains connection"] domains["Domains in MainPath"] zone["united-domains zone"] server["Your server"] org --> zone domains -->|"A / CNAME"| zone zone --> server
After you save a project, MainPath tries to align missing or mismatched records. You can see the check status in the domain overview.
SSL via DNS-01 (optional)
If Let’s Encrypt cannot reach the server (no public HTTP/443, firewall, internal IP), open this connection’s details and tick the affected domains. MainPath then writes the _acme-challenge TXT record into this zone. Unticked domains keep the existing TLS-ALPN challenge on the server.
Troubleshooting
- Invalid key: Check the
prefix.secretformat (one dot, no spaces), book the DNS API in the portfolio, and update the connection. - No record at united-domains: The domain is not in a zone this key can see. Check the account or zone name.
- Zone visible, domain unreachable: The zone exists, but the domain’s nameservers point elsewhere. MainPath flags this in the connection details and on Domains. Point the nameservers at the registrar to
ns.udag.de,ns.udag.net, andns.udag.org. - Status in MainPath still red: DNS often takes a few minutes, or the server does not have a known address yet.