Teams let other people sign in to your account as themselves instead of everyone sharing one password. Each person sees only the domains you assign them and can do only what you allow.
Available on Business, which includes 100 members, and Enterprise, which is unlimited. Members are managed under Team in the portal.
A member is not a separate account
A member works inside your account and draws on your plan. They do not have their own zone allowance, their own invoices or their own plan — everything they create counts against yours, and everything they do appears in your account's history.
That is the point of the feature rather than a limitation of it. It is what lets you hand somebody a domain without handing them a bill.
Adding someone
Team → Add someone. You need their email address and a group to put them in.
You then choose how they get their password:
- Send an invitation. They receive a link and set their own password. Nobody, including you, ever learns it. This is the default and it is the one to use unless you have a reason not to.
- Set a password yourself. You type one and pass it on however you like. No email is sent on this path, so if you mistype the address nothing tells you — the invitation path corrects itself, because whoever receives the link is whoever sets the password.
Either way the member can sign in straight away. There is no separate activation email to open: you vouched for the address when you added it.
Groups decide what a member can do
Permissions belong to a group, not to a person, so "what can a designer do here" is answered once and applied to everybody in that group.
There are twenty permissions across six areas — Zones and records, Protection, Recovery, Reporting, Automation and Account. They are deliberately fine-grained where it matters:
- View records is separate from editing. Without it a member sees the zone name and nothing inside it.
- Delete records is separate from adding and editing, because it is the one that loses data.
- Add new zones and Delete zones are separate again.
Create as many groups as you have kinds of person. A common set is one group that can edit records, one that can only look, and one that can do everything except billing.
Zones are assigned per member
A group says what someone may do; the zone assignment says where. A member with full record permissions who is assigned one domain can still only touch that domain.
Everything follows the assignment, not just the zone list — statistics, the recycle bin and any API key the member creates are all limited to the same domains. A member cannot widen their own access by going round the portal.
What stays yours
These cannot be granted to anyone, whatever group they are in:
- Invoices and billing
- Payment methods
- Changing the plan
- Closing the account
- The account profile
A member can run your DNS without ever seeing what you pay for it.
Capping what a member may create
If a group has Add new zones, you can also set a maximum number of zones for that group. A zone a member creates is assigned to them automatically, so the cap is what stops one person consuming the whole plan.
The cap counts what they hold, not what they created historically — which means it agrees with the zone list in front of them.
Two ways teams are usually used
Staff, one domain each. The person who runs the shop gets the shop's domain; the person who runs the mail server gets the domains whose MX they maintain. When somebody leaves you remove one member, rather than changing a shared password and telling everybody the new one.
Resellers sharing an allowance. Your plan's zones are a pool. Give each client a login capped at the number of zones you have sold them, with Add new zones enabled. They create and administer their own domains, see nobody else's, and cannot quietly grow past the cap.
Passwords
A member changes their own password under Change password. Members do not have the full profile page — name and company belong to the account, not to them, so those changes go through you.
If somebody is locked out you can either send them a reset link or set a new password for them from their row on the Team page.
Removing someone
Deleting a member removes their sign-in and revokes any API key they created. The zones stay — they belong to the account, not to the person — so removing somebody never takes a domain offline.
Last reviewed 2026-09-19.
Open a ticket from the control panel, or use the contact form if you cannot sign in. If a domain is down, the status page is the fastest way to find out whether it is us.