System Status
System Status
n

Articles

How to Become a CO.ZA Registrar in 6 Steps
09.28.2026

A CO.ZA domain may be a customer’s public identity, email route and route to critical online services. That makes becoming a registrar more than a domain resale opportunity. Organisations considering how to become a CO.ZA registrar need the commercial capability, technical controls and operational discipline to manage domain lifecycles reliably.

A registrar is the customer-facing member of the domain ecosystem. It accepts registrations, renewals, transfers and updates from registrants, then submits authorised changes to the registry through secure systems. The registry operates the shared namespace infrastructure; the registrar carries the day-to-day responsibility for customer service, identity and payment processes, and the safe handling of domain instructions.

For hosting providers, ISPs and established digital-service businesses, accreditation can create a closer relationship with the .ZA domain ecosystem and a more integrated customer offering. It also creates a direct obligation to protect registrants and uphold the stability of a national internet namespace.

1. Establish a registrar operating model

Start by defining the service you will actually provide. Some registrars offer domains alongside web hosting, managed DNS, email and security services. Others focus on wholesale distribution to resellers, or provide a self-service platform for small businesses. Each model has different demands for support, billing, automation and risk management.

Be clear about who will own each part of the customer journey. Customers need a straightforward way to register a domain, supply correct contact information, renew on time, update nameservers, request a transfer and recover account access. They also need to know where to turn when a domain affects a live website or business email service.

A sound operating model includes documented terms, transparent pricing, a billing process that can handle renewals, and a support route for urgent domain issues. Domains are time-sensitive assets. A missed expiry notice or an unresolved account-access problem can have consequences far beyond the value of a registration fee.

2. Read the policies before designing the platform

Accreditation is based on compliance as well as capability. Before building workflows or committing engineering resource, review the current registrar accreditation requirements, applicable namespace policies, lifecycle rules, transfer procedures and technical documentation for CO.ZA.

This work should shape the platform rather than be treated as a final compliance check. For example, your customer interface and internal processes must accommodate required registrant data, domain status rules, renewal and expiry handling, and the procedures that apply when a registrant wants to move to another registrar.

Your team should also understand the distinction between a registry policy requirement and a commercial choice. You may choose to offer managed DNS, premium support or bundled hosting. You cannot choose to ignore the rules that protect registrant rights and support consistent operation across the namespace.

Legal, finance, support and technical teams should all be involved at this stage. A policy requirement can affect customer wording, system validation, credit controls and incident handling. Early cross-functional review is usually cheaper than changing a live registrar portal later.

3. Build secure EPP integration and test it properly

Registrar-to-registry communication is generally performed through the Extensible Provisioning Protocol, or EPP. Your integration must be able to create, renew, update, transfer and delete domain objects in accordance with the relevant commands, responses and constraints. It must also process notifications and maintain an accurate record of what happened.

Do not regard EPP as a simple API connection. It is a control point for changes to valuable digital assets. Credentials, certificates and access permissions should be protected as production secrets, with access restricted to authorised systems and personnel. Logging should allow your team to investigate a disputed instruction without exposing sensitive customer information.

Technical readiness includes more than successful domain creation. Test failure conditions, duplicate requests, malformed data, time-outs and customer actions that arrive at the wrong point in a domain lifecycle. Consider what happens if a payment completes but a provisioning request fails, or if a transfer request needs action while a customer is locked out of their account.

A practical test plan should cover at least these areas:

  • domain registration, renewal, update and deletion flows;
  • contact and nameserver management, including validation failures;
  • transfer requests, authorisation and status handling;
  • EPP error processing, retries and reconciliation; and
  • audit logs, access controls and operational alerts.

Technical onboarding and test environments exist to help prospective registrars demonstrate that their systems can interact predictably with registry services. Treat the testing phase as evidence that your processes are ready for real registrants, not simply as a hurdle before launch.

4. Design for DNS integrity and domain security

A domain registration is only useful when its DNS configuration is correct and resilient. Although a registrar may not operate authoritative DNS for every customer, it must provide reliable mechanisms for customers to delegate domains, change nameservers and understand the consequences of those changes.

Nameserver changes deserve particular care. A malicious or mistaken update can take a business website and email service offline, redirect visitors or enable impersonation. Use strong account authentication, appropriate approval controls and clear notifications for high-impact actions. For larger customers and resellers, role-based access can reduce the risk created by shared credentials.

Support for DNSSEC is another important capability for registrars serving security-conscious organisations. DNSSEC helps protect DNS responses from certain forms of tampering, but it requires accurate handling of delegation signer information and a clear support model. It may not be appropriate for every customer on day one, yet your technical team should understand the operational implications before offering it.

Plan for exceptional cases as well. Registry lock, status changes, abuse complaints, court orders and verified takedown requests need controlled procedures. A reliable registrar does not make irreversible changes on an informal request or rely solely on an individual staff member’s judgement.

5. Prepare customer support, abuse handling and continuity plans

The visible quality of a registrar is often measured when something goes wrong. A customer may report that their website no longer resolves, that email has stopped after a nameserver update, or that they did not authorise a transfer request. Your support team needs access to accurate account and domain-status information, plus an escalation path to staff who understand DNS and EPP operations.

Create playbooks for common incidents. These should identify the first checks to make, the evidence to collect, the customer communications to send and the point at which the matter must be escalated. A support agent should not have to improvise when a customer reports suspected account compromise or a domain is close to expiry.

Abuse management also requires a documented approach. Registrars may receive reports involving phishing, malware, impersonation, copyright concerns or other harmful activity. Reports should be assessed fairly, logged securely and handled in line with applicable policy and legal obligations. Speed matters, but so do due process, evidence and accurate communication.

Continuity planning is equally important. Identify how you will maintain domain operations during staff absence, a billing-system outage, a hosting incident or a cyber-security event. Maintain tested backups of essential registrar data, segregate critical access, and ensure more than one trained person can perform operational tasks. National internet infrastructure depends on many organisations doing the basics consistently well.

6. Apply for accreditation and launch with control

Once the business, policy, technical and operational foundations are in place, submit an application through the established accreditation process. The application will require current organisational, technical and contractual information, so use the latest published requirements rather than relying on an older checklist or assumptions from another namespace.

ZARC’s role is to operate the registry infrastructure and support an accredited registrar channel, not to compete for end-user registrations. During onboarding, respond completely to requests for information and use technical testing to resolve gaps before production access is granted. A rushed launch creates avoidable risk for your first customers and for the wider namespace.

After accreditation, begin with measured volumes and close operational monitoring. Reconcile registry transactions against your billing and customer systems daily at first. Review failed commands, pending transfers, expiring domains, support tickets and access logs. This gives your team an early view of where automation and customer guidance need improvement.

How to become a CO.ZA registrar with lasting capability

Successful registrar businesses are built on trust earned over thousands of routine actions: a renewal processed correctly, a transfer handled fairly, a DNS change authenticated properly, and an abuse report answered responsibly. Commercial ambition matters, but it must be matched by disciplined operations.

If your organisation is ready to invest in secure integration, trained people and clear customer processes, accreditation can be a meaningful contribution to South Africa’s digital economy. Build the service around the registrar’s long-term duty of care, and your customers will have a more dependable foundation for their online presence.

Other Posts