Crypto-paid domains

Buy your name in crypto. Own every answer under it.

A domain is not a file you own — it is a chain of delegation, and the only part that matters is where it stops being somebody else’s and becomes yours. From that ring inward, every record is yours to edit, from your dashboard, taking effect in the live zone.

Prices per year. You'll sign in to finish — pay in crypto or from your wallet.

free WHOIS privacy · pay on-chain or from your wallet · no card, no bank

Official Bicrypto developer store4,000+ licenses sold worldwidePay in 300+ cryptocurrenciesInstant & automated — no sales calls
.comfrom $22.99/yr
.netfrom $20.99/yr
.orgfrom $19.99/yr
.iofrom $41.99/yr
.cofrom $25.99/yr
.xyzfrom $3.99/yr

Live prices, refreshed hourly — not a starting-from figure that changes at checkout.

Two ways to pay. One settlement.

One of them is instant and one of them waits for a blockchain. What they are not is two separate code paths that can disagree about whether you bought a domain.

The wallet lane is short because it is one transaction

If your store wallet covers the price, the order row and the debit are written together and the registration runs on the spot. If the balance turns out to be short, the order rolls back with it — which is why there is no such thing here as an order that is marked paid and was not funded.

The on-chain lane is longer because a chain is slow, not because it is different. The callback that eventually arrives is signature-verified and de-duplicated on the exact payment and status it claims to be, and then it calls the same settlement the wallet lane called directly.

And before it ever pays to register: Fulfilment checks whether the name is already ours. Only two definitive replies count as “safe to register”; anything ambiguous stops rather than risking a second paid registration on your behalf.

5

guided setups

each writing real provider records, not instructions

8

record types

A, AAAA, CNAME, MX, TXT, NS, CAA, SRV — validated server-side

3

records per click

apex, www and the wildcard, all at TTL 3600

0

DKIM invented

that key is your provider's; the recipe tells you where it goes

Recipes that write real records — and step over the ones you already added

The reason people are frightened of one-click DNS is that they have watched one wipe a verification record and take a mailbox down with it. So this one matches on what a record says, not just where it sits.

SPF and DMARC are matched by what they start with

A TXT record is a bag of unrelated strings that all live at the same name. Replacing “the TXT record” is therefore a destructive operation on a host that has three of them. The recipes match SPF on v=spf1 and DMARC on v=DMARC1, update those, and add anything missing — so your Google or Microsoft site-verification string is still there afterwards, and running a recipe twice does nothing the second time.

Five recipes exist: a website, Google Workspace, Microsoft 365, self-hosted mail, and an anti-spoof set for a domain that should never send mail — a null MX, a hard-fail SPF and a rejecting DMARC, which is the correct configuration for the brand domain nobody sends from and everybody forges.

DKIM is the one thing left to you, on purpose. It is generated by your mail provider and is specific to your tenant; a registrar that offered to fill it in would be guessing.

One click writes three records. The third is why SSL just works.

Everyone writes the apex and www. The wildcard is the one that saves you a DNS edit every time you add a subdomain — including the ones your control panel adds for you.

A subdomain that resolves is a subdomain that can get a certificate

Let’s Encrypt proves you control a hostname by resolving it. So a wildcard A record is not a convenience — it is the precondition for every future app., api. or admin. getting its own cert with no further DNS work from you. Virtualmin creating a sub-server on your box just works, rather than failing a challenge and leaving you to guess why.

All three records are written at a one-hour TTL against your server’s real address, read out of the linked server rather than typed by you. If the server has not finished provisioning yet, the action refuses and says so instead of writing a record that points nowhere.

Reminders at 30, 7 and 1 days. Then it charges itself.

Losing a name to a missed renewal is the one domain failure you cannot undo with money. The order these jobs run in is what prevents it.

The sweep that expires a domain runs after the one that renews it

That is not a detail, it is the whole guarantee: in every tick, renewal is attempted first and expiry is marked second, so a domain that could have been funded is never marked expired on a technicality. The loop runs every five minutes.

With auto-renew on, the wallet is charged from seven days out. Two schedulers run against the same rows, so before charging, each one takes an atomic claim — the loser skips rather than double-charging you. If the wallet is short, the email carries the shortfall and your live balance and a way to top up, not a generic failure.

Renewal is priced at the live renewal price for that extension, which is a genuinely different number from the registration price. You are shown that number rather than last year’s.

Then the part you actually use

Registration takes seconds. Everything below is the years afterwards.

Eight record types, edited live

A, AAAA, CNAME, MX, TXT, NS, CAA and SRV, from your dashboard, taking effect in the live zone rather than in a support queue. Every write is re-validated on the server: TTL between one hour and thirty days, priority within range, value length checked — so a typo is refused before it becomes an outage you have to diagnose.

WHOIS privacy on by default, on both paths

Your name, email and address stay off the public record on registration and on transfer alike, unless you deliberately untick it. It is not a line item, it is not an upsell, and it does not quietly lapse at renewal.

The domain and the server know about each other

A domain bought here can be linked to a server bought here, in the data model rather than in your head — which is how one click can read that server's real address, and how the dashboard card can tell you what a name currently points at without you going and checking.

Move one in, and move it out again if you want

Transferring in needs the auth code from your old registrar — stored encrypted, never in plain text — and adds a full year to your term, with privacy included. And you can point the nameservers somewhere else entirely whenever you like: the dashboard will warn you that records edited here stop taking effect, because that is true, and a registrar that hides it is hoping you will not leave.

Crypto all the way down, not just at the checkout

Your Bitcoin or USDT is not quietly converted into a card payment somewhere behind the scenes — registrations, renewals and transfers all settle in crypto end to end, the same way the hosting side runs. That is why there is no card form anywhere in this checkout, and why there is no bank that can decide your exchange is the wrong kind of business to serve.

FAQ

Domain questions, answered

Names are first-come. Check yours.

Search live availability and the real price, then register in crypto or straight from your wallet. With a name and a matching server, your exchange can be answering today.

pay in 300+ coins or from your store wallet · questions to support@mashdiv.com