Export your build, publish it, then paste these records into your registrar. SSL is issued automatically once the records resolve — no server config, no certificate wrangling.
Root + www recordsBoth point at your published site, written for you after delegation.
Ownership checkVerified through the delegated zone — no TXT token to copy anywhere.
SSL certificateIssued the moment DNS resolves, then auto-renewed for life.
www ↔ root redirectYou pick a primary; the other 301s to it permanently.
Propagation watchStudio keeps checking and flips the domain live the second it resolves.
Only your registrar can change who controls a domain, and registrars don't let a third party do that without your say-so — that's what stops domain hijacking. So there is always one action on your side: either delegate the nameservers once (automatic) or paste the records (manual). Everything after that is ours.
Use the CNAME-based verification instead of A records — in the connect flow, open Advanced and check "Domain uses Cloudflare or a similar proxy".
MX, SPF, DKIM and DMARC stay at your registrar. Pointing A records at the site does not touch mail as long as you leave the MX records alone.
You can buy one during publish and it gets connected automatically.
Site not built yet? Start a build → or let Onyx optimize the one you have.