All use cases

For agencies

Manage client domains without master credentials.

Standardize client launches, DNS safety, and handoff without passing registrar passwords through email threads.

agencies
$domani import clientsite.com
Domain added · verification pending
$domani connect clientsite.com netlify --dry-run
2 additions · 0 mail records removed
$domani connect clientsite.com netlify
Connection verified

What breaks today

Agencies inherit registrar logins, DNS access, and renewal responsibility through email threads and password managers. A small launch change can require broad access to unrelated client assets.

What changes with Domani

Domani lets an agency connect client hosting, use operation-scoped tokens, and document sensitive changes without making a shared registrar password the center of the workflow.

The workflow, end to end

Import or register

Bring an existing client domain into the workflow or register a new project name with visible ownership context.

Scope the work

Limit an operator or automation token to the operation types required for the engagement.

Ship safely

Preview DNS changes, preserve mail records, connect hosting, and keep a restorable zone history.

Hand off

Revoke agency access or transfer operational control without rotating unrelated credentials.

What Domani provides

Operation-level permissions

Grant DNS or email scopes without sharing the owner account credential.

DNS safety

Validate changes, protect MX records, and preserve a snapshot before publishing.

Provider connections

Standardize launches across common hosting platforms and explicit DNS records.

Activity history

Give clients and internal teams a record of who changed what and when.

The boundary that stays explicit

Current API tokens are scoped by operation type, not by individual domain. Use a separate Domani account when one client must be technically isolated from every other client asset. Legal ownership and authorization also remain an explicit agency responsibility.

Questions teams ask

Concrete answers before you change a production workflow.

Can each client domain have separate access?+

Not within one account today. Tokens can limit operation types, but not the individual domains they can see. Use a separate account when client-level isolation is required.

Can we avoid breaking client email during a launch?+

DNS validation includes mail-record safeguards, and zone snapshots provide a recovery point before sensitive changes.

Can we hand the domain back after the project?+

Yes. Access can be revoked independently, and eligible domains can follow the appropriate account or registrar transfer workflow.

Agents need domain access, not your account.