Account Glossary
Table of Contents
- Users, accounts, and members
- Email addresses
- Access and permissions
- Sign-in and security
- Billing and subscription
- Have more questions?
A reference for Account terminology at DNSimple. For how users, accounts, and members fit together, see Users, Accounts, and Members at DNSimple.
Users, accounts, and members
User
A person who signs in to DNSimple. A user has credentials (user email and password, and MFA if enabled) and can belong to one or more accounts.
Learn more:
Account
A DNSimple workspace that holds a subscription, domains, billing settings, and (on eligible plans) members. You choose the active account from the account switcher.
Learn more:
Member
A user who has been invited into an account. Members sign in with their own user email and credentials. On Teams and Enterprise plans, members can be assigned seats and Domain Access Control permissions.
Learn more:
Seat
A paid slot that allows a member to access an account on Teams or Enterprise plans. The Teams plan includes one seat; additional seats incur extra cost. Enterprise seat counts are custom.
Learn more:
Email addresses
User email
The email address tied to a DNSimple user. It is used to sign in and to receive user-level messages such as password reset and email verification. It is not the same as a notification email.
Learn more:
Notification email
The email address where DNSimple sends account messages for a specific account, such as renewals and payment notices. If none is set, account administrators receive those messages by default.
Learn more:
Billing email
On Teams plans and higher, an optional address for invoice delivery. It is separate from the user email and from the notification email. A billing email alone does not grant account access.
Learn more:
Access and permissions
Domain Access Control (DAC)
A feature on eligible plans that limits what each member can see and change, including access per domain. Combined with MFA and activity tracking, it supports least-privilege access.
Learn more:
Full Access
An account-level access setting that lets a member use all resources in the account, including domains, contacts, certificates, templates, billing, and account settings.
Learn more:
Limited Access
An account-level access setting that lets a member join the account without domain access until you grant Domain Manager or Zone Operator permissions on specific domains.
Learn more:
Domain Manager
A domain-level role for a member with Limited Access. A Domain Manager can manage the full domain, including DNS, registration details, certificates, and other domain operations where access is permitted.
Learn more:
Zone Operator
A domain-level role for a member with Limited Access. A Zone Operator can manage only the DNS zone for that domain (records, import/export, One-click Services) and cannot change registration, billing, or other domain settings outside the zone.
Learn more:
User token
An API token tied to a user. When used against an account, access follows the Domain Access Control permissions of that member.
Learn more:
Account token
An API token tied to an account. Account tokens have full account access for automation and are not limited by the Domain Access Control permissions of an individual member.
Learn more:
Sign-in and security
Single sign-on (SSO)
A way for users on eligible plans to sign in to DNSimple through an identity provider instead of (or in addition to) a password-only login.
Learn more:
Identity provider (IdP)
An external system that authenticates users for SSO. DNSimple supports Google, Okta, and Microsoft Entra as identity providers.
Learn more:
Multi-factor authentication (MFA)
An extra verification step at sign-in, such as a one-time password from an authenticator app or a security key. MFA is configured on the user, not on the account subscription.
Learn more:
MFA enforcement
An account setting on eligible plans that requires every member to have MFA enabled before they can access the account.
Learn more:
Activity tracking
An audit log of actions in an account. Use it to review who changed domains, members, billing, or other settings.
Learn more:
Billing and subscription
Subscription
The recurring plan that keeps an account active for DNSimple services. Subscriptions renew on a billing cycle. Canceling or failing to pay can stop service while domains and records may remain in the account.
Learn more:
Dunned invoice
A renewal invoice that failed collection and is in the retry window. DNSimple retries periodically, and you can also retry manually from invoice history.
Learn more:
Deactivated account
An account where DNSimple services have stopped. Domains using DNSimple name servers no longer resolve, auto-renewal and WHOIS privacy are disabled, and the domains, records, and account history remain in the account. Deactivation follows either a canceled subscription after failed payment, which you can resolve by reactivating, or a DNSimple restriction for billing, security, or policy reasons, which requires contacting support. Sometimes described as a suspended account.
Learn more:
- Deactivated Account
- What Happens if I Stop Paying for My DNSimple Subscription?
- Reactivate Your Subscription
Have more questions?
If you have questions about Account terminology, contact support, and we will be happy to help.