Domain, hosting and SSL: what a site needs to go live

What to buy before a site launches, how a domain differs from hosting, why SSL is not optional, and why all of it must be registered in your name rather than your contractor’s.

The site is finished but will not open. Or it opens and the browser says “Not secure”. Or everything works, and a year later it turns out the domain is registered to a former contractor who does not answer emails.

Development is only half of a launch. The other half is infrastructure: domain, DNS, server, certificate, mail. Here is what each of those is, in what order they appear, and which decisions are worth making once and correctly.

What a launch consists of

For someone to type an address and see your site, four things have to exist:

  • Domain — the name people type. bagyt.kz.
  • DNS — the directory that turns that name into a server address.
  • Server (hosting) — where the site physically lives and runs.
  • SSL certificate — what makes the address https and removes the browser warning.

Plus a fifth that people remember later: mail on your domain. info@yoursite.kz instead of a personal address on a free service.

The domain

Choosing a name

Short, sayable out loud, with no spelling traps. The test is simple: dictate the address over the phone. If the other person asks “is that with a hyphen?”, the name is bad.

Avoid digits standing in for words, doubled letters where two words meet, and transliterations that can be spelled two ways. tsvety or cvety — half your clients will end up somewhere else.

.kz or .com

.kz if your clients are in Kazakhstan. A national-zone domain gives a small edge in local results and simply reads as “a local company”.

.com if you work across several countries, or plan to.

Registering both and redirecting one to the other is a reasonable practice when the budget allows. Running two different sites on them is not: search engines will see duplicates.

Registering .kz requires company or sole-trader details — prepare the documents in advance, it is not a one-minute purchase like .com.

Whose name it goes in

Yours. Not the contractor’s, not “a friend who understands this stuff”, not an employee who leaves next month.

A domain is the one thing you cannot recover if you lose access. A site can be rewritten, a server rebuilt — but a domain belongs to whoever it is registered to. Arguing with a former contractor over your own name means months and lawyers.

The practical rule: open the registrar account yourself, on your own email, and pay for it yourself. Grant the contractor access when they need it, and revoke it when the work is done.

Renewal

A domain is not bought once, it is renewed every year. A missed renewal is the most avoidable outage there is: the site simply disappears, and after a while the name can go to someone else.

Turn on auto-renewal and keep money on the card. Set yourself a reminder a month before the date, in case the card expires.

DNS, and why a site does not open straight away

DNS is the address book of the internet. You tell it “example.kz lives at this server”, and it distributes that record around the world.

Not instantly. Updates take anywhere from minutes to a day — this is called DNS propagation. So on launch day it is normal for the site to open for you and not yet for a client in another city. That is not a fault, it just has to be waited out.

Which gives a practical rule: do not schedule a launch for Friday evening, and do not tie it tightly to the start of an ad campaign. Leave a day of slack.

The server: what to choose

Shared hosting

The cheap option: your site lives on one machine with hundreds of others. Fine for a simple brochure site with no load.

The downsides: you share resources with neighbours, you are limited in what you can configure, and if a neighbouring site draws heavy traffic or lands on a spam list, it can affect you too.

VPS

A dedicated virtual machine: your own resources, full control over the configuration. The standard choice for a real company site, a store or an application.

It needs administration — someone has to update the system, configure backups and watch that the server is alive. Usually that is the contractor, as part of support.

Cloud

Justified when load spikes: seasonal sales, advertising bursts, fast growth. Flexible, but harder to budget — you pay for what you consume.

Where, physically

If your audience is in Kazakhstan, keep the server nearby — in Kazakhstan or a neighbouring region. Distance to the server directly affects response time, and speed affects both search rankings and whether a visitor waits for the page at all.

SSL: required, not optional

An SSL certificate is what gives you https and the padlock in the address bar. Without it the browser shows “Not secure”, forms are flagged as unsafe, and search engines rank the site lower.

The good news: a basic certificate costs nothing. Let's Encrypt issues free certificates that are no worse than paid ones in terms of encryption or browser trust. They last 90 days and renew automatically — if auto-renewal is configured. If it is not, one morning the site will greet visitors with a red warning.

Paid certificates are for narrow cases: extended organisation validation, insurance, a wildcard across many subdomains. An ordinary company site does not need them.

Mail on your domain

info@company.kz instead of company2019@mail.ru is not about aesthetics, it is about trust. A free-mailbox address in a commercial proposal reads as “we are not here for long”.

It is set up through a mail service tied to the domain. The part people forget: SPF, DKIM and DMARC — DNS records that confirm a message really came from you. Without them your emails to clients will regularly land in spam, and your domain can be used as cover by scammers.

The access checklist

By launch day you should hold:

  • The registrar account — in your name, on your email
  • Access to the DNS panel
  • Access to the server or the hosting panel
  • The mail service account
  • The code repository
  • Analytics accounts — Google Analytics, Yandex.Metrica
  • Google Search Console and Yandex.Webmaster
  • Payment gateway access, if payments are involved

A simple health check on the arrangement: ask your contractor what happens if you decide tomorrow to work with another studio. If the answer is specific — “we hand over these accesses, here is the list” — you are fine. If the answer is vague, you do not own your own site.

The order of operations

  1. Check and register the domain — before development starts; names get taken.
  2. Decide on the server closer to delivery, when the load is understood.
  3. A week before launch: bring up the server, configure DNS, issue SSL.
  4. Set up mail and the SPF/DKIM/DMARC records.
  5. Launch, then check from different devices and networks.
  6. Connect analytics and the webmaster tools, submit the sitemap.
  7. Confirm that auto-renewal is on for both the domain and the certificate.

How we handle it

We take this part on: we register the domain, bring up the server, issue SSL, set up mail and the mail records. The first three months of domain and server are on us — they are included in every project.

Everything is registered in your name: the registrar account, the server, the repository, the analytics. The access is yours from day one, and you can move to another contractor whenever you like without having to ask for anything.

What a project includes end to end, and what it costs, is on the services page. You can size up budget and timeline for your own task in the calculator, and check an existing site with the express audit. Ready to talk — write to us.

Let's build something useful.

Tell us what you're working on. We'll review the idea and get back to you with the next steps.

Discuss your projectView our work
WhatsApp