# Registering and Managing .nz Domains

Source: https://support.kapsulehost.com/en-nz/domains-nz-rules

New Zealand's .nz namespace runs on its own registry rules, and several of them differ enough from .com that the KPanel controls you expect to see are deliberately absent on a .nz domain.

Most of those differences come from the .nz rules themselves, and where a feature genuinely does not exist for .nz, KPanel says so rather than showing you a toggle that would fail. This guide covers what changes, what replaces it, what KPanel does not do for .nz, and what to watch on renewals and transfers.

## The .nz Namespace

.nz can be registered directly at the second level, or under one of its long-standing sub-domains:

`.nz`, `.co.nz`, `.net.nz`, `.org.nz`, `.kiwi.nz`, `.geek.nz`, `.maori.nz`, `.iwi.nz`, `.gen.nz`, `.ac.nz`, `.school.nz`, `.cri.nz`, `.health.nz`, `.govt.nz`, `.mil.nz`, `.parliament.nz`

Several of those are restricted to particular kinds of registrant. In everyday commercial use you are choosing between `.co.nz` and the shorter `.nz`.

> **Tip:** If `yourbrand.co.nz` is available, check `yourbrand.nz` too and consider taking both. `.co.nz` is the address most New Zealanders still type by habit, while the bare `.nz` is shorter and has far fewer names taken. Owning both means nobody registers the twin of your brand. Search them together in **Domains**, then **Bulk search**.

## Registrant Details Must Be Real

The .nz register is operated by InternetNZ and regulated by the Domain Name Commission, and registrant accuracy is taken seriously.

- Your name, address, email and phone must be genuine and current.
- The registrant must be the actual owner of the domain, not your web developer, your agency, or your hosting provider.
- The registry can cancel a registration for false or incomplete registrant data.

KapsuleHost collects these details at registration and passes them to the registry. Keep them current in KPanel from the domain's **Overview** tab, under **Registrant Contact**. Saving there queues a sync to the registry: KPanel confirms with "WHOIS contacts updated: registrar sync queued."

> **Warning:** If your only contact email is one hosted on the domain itself, a DNS or mail problem can lock you out of the messages you need to fix it. Use an address on a different domain for your registrant contact.

## Privacy on .nz Domains

This is the difference that surprises people most, and it is worth being exact about.

On most other domains, WHOIS privacy replaces your contact details with a privacy service. That service is not offered for .nz, so on a .nz domain the **Privacy & Lock** card on the **Security** tab shows the .nz privacy option in its place.

.nz has its own mechanism instead: the Individual Registrant Privacy Option, set out in the .nz Rules published by the Domain Name Commission. A registrant who is an individual, and who does not use the domain to any significant extent in trade, can ask their registrar to apply it. With it applied, the registrant's address and phone number are withheld from the public .nz lookup, while the name, email address and country stay visible. Companies, organisations and anyone trading on the domain are not eligible.

To turn it on, open the .nz domain's **Security** tab, tick "I am an individual and I do not use this domain name to a significant extent in trade.", then turn on **Keep my contact details private (.nz Individual Registrant Privacy Option)**. The switch stays off until the declaration is ticked. KPanel sends the change to the .nz register and reads it back before it confirms. The same control is under **Registrant Contact** on the **Overview** tab, and you can choose it when you register a .nz domain or transfer one to KapsuleHost. To turn it off, turn the switch off; that needs no declaration.

> **Warning:** Only individuals who are not using the name for trade can choose this. If that changes, you must turn it off. KapsuleHost keeps a record of each declaration: who made it, when, and the wording shown.

.nz also does not publish RDAP, the modern machine-readable successor to WHOIS. Lookups go to the registry's own WHOIS service instead. KPanel handles that for you: **Domains**, then **WHOIS Lookup**, returns .nz results in the same format as any other TLD.

![Privacy and Lock card on a .nz domain in KPanel](https://support.kapsulehost.com/help/screenshots/domains-nz-rules.e3bdd6b5.webp)

## Registrar Lock Does Not Exist Either

On a .com or .net, a registrar lock is the switch that stops an unauthorised outbound transfer. The .nz registry has no such concept, so KPanel shows the **Registrar Lock** row as **Not available** with the explanation: "The .nz registry does not support registrar lock. Transfers are protected by the UDAI auth code instead."

The **UDAI** is .nz's transfer authorisation code, the equivalent of an EPP or auth code elsewhere. Whoever holds a valid UDAI can move the domain.

> **Warning:** Because there is no lock to fall back on, the UDAI is the only thing standing between your .nz domain and someone else's registrar. Request one only when you actually intend to transfer, do not paste it into an email thread or a support chat, and keep the KPanel account that can request it protected with two-factor authentication. See [Two-Factor Authentication](https://support.kapsulehost.com/en-nz/two-factor-authentication).

## Transfers Are Fast

.nz transfers are dramatically quicker than the gTLD norm, in both directions:

| | .nz domains | Most other TLDs |
|---|---|---|
| Transfer time | Same day, often within hours | 5 to 7 days |
| Minimum domain age before transfer | No 60-day rule | 60 days (an ICANN rule for most gTLDs) |
| Authorisation | UDAI code | EPP or auth code |
| Registrar lock to release first | Not applicable | Yes |

Your DNS keeps resolving throughout a transfer either way. The domain does not go offline while it moves.

To move a .nz domain away from KapsuleHost, follow [Transferring Your Domain to Another Registrar](https://support.kapsulehost.com/en-nz/domains-transfer-out): the steps are the same, minus the unlock step that does not apply.

## Renewals and Auto-Renew

.nz registrations run in annual terms and auto-renew is on by default. Find it on the domain's **Settings** tab, under **Renewal & Transfer**:

- **Auto-renew on:** "We renew this domain automatically before it expires, at the renewal price shown."
- **Auto-renew off:** "You must renew manually before expiry, or the domain will be released."

KapsuleHost emails you before expiry at 60 days, 30 days and 7 days out, so a lapse should never come as a surprise.

The **Settings** tab also carries a **Renew Domain** add-on row showing your expiry date, with a button that adds another year to the registration whenever you want, without waiting for the renewal date.

> **Important:** Turning auto-renew off puts the entire responsibility for keeping the name on you. Once a domain is released back to the registry, recovering it is not a support ticket you can win: whoever registers it next owns it. Unless you deliberately want to drop a name, leave auto-renew on.

> **Note:** What happens between expiry and release is set by the registry, and the .nz rules are not the same as .com's. The safe operating assumption is that the window is shorter than you think. Do not plan around it: renew before the expiry date on your domain's Overview tab.

## DNSSEC on .nz

.nz domains registered through KapsuleHost can be signed like any other. Enable it on the domain's **Security** tab, and if the domain is registered with us, we publish and renew the DS record at the registry for you. See [Enabling DNSSEC for Your Domain](https://support.kapsulehost.com/en-nz/domains-dnssec).

## Troubleshooting

**The WHOIS Privacy toggle is missing on my .nz domain.** On .nz its place is taken by the .nz privacy option, because the privacy service used on other domains is not offered for .nz. See above for how to turn the option on.

**The Registrar Lock toggle will not turn on.** Same reason. .nz has no registrar lock. The UDAI is what protects the domain.

**A WHOIS lookup says my .nz domain is not registered.** Public tools that only speak RDAP report .nz domains as available, because .nz does not publish RDAP. Use KPanel's own **WHOIS Lookup** under **Domains**, which queries the .nz registry directly.

**My registrant details are wrong on the public record.** Update them under **Registrant Contact** on the domain's Overview tab and save. The registry sync is queued straight away and the public record catches up shortly after.

**I need to register a restricted .nz name** such as `.govt.nz` or `.ac.nz`. Those have eligibility criteria set by the registry. [Open a support ticket](https://support.kapsulehost.com/en-nz/opening-a-support-ticket) before you try, and tell us which entity is registering.

Related reading: [Transferring Your Domain to Another Registrar](https://support.kapsulehost.com/en-nz/domains-transfer-out), [Enabling DNSSEC for Your Domain](https://support.kapsulehost.com/en-nz/domains-dnssec), and [Nameservers](https://support.kapsulehost.com/en-nz/nameservers).
