A Higan Holdings Limited Company — England & Wales, No. 16914818 --:-- JST All systems normal Client Console →
YUNAGI yunagi.cloud

Yunagi/Domains

YG-DOM-02 · 2026.08

Domain Services

A name is the only part you keep.

Yunagi sells and manages names through an ICANN-accredited registrar partner. 312 top-level domains, the renewal price printed beside the first year on every one of them, WHOIS privacy and registrar lock at no charge, DNSSEC in one click, and anycast DNS answering from all six metros. Transfers carry your records if you let us stage them first.

The renewal price is printed beside the first-year price everywhere on this page, because the renewal is the price. A name bought for $1.99 and renewed at $22.99 costs $93.95 over five years; the same name here costs $57.10, and both figures are in the table below.

Namespaces 312 Open as at 2026.08.26 — twenty priced below
Renewal Printed Beside the first year, on every row
Transfer in 5days Or minutes, if they approve it
Certificate $6/yr DV single · $48 wildcard

Type a name, or watch the register work.

300+ TLDs · the renewal price is printed beside the first year

The Price Book

Four columns, because four prices exist.

A domain has four prices and most price lists publish one. The first year is the one that advertises; the renewal is the one you actually pay, four times, six times, for as long as the name is worth having; the transfer price applies once, when you bring it here; the restore fee applies on the worst day, when it lapsed and you noticed on day nine. All four are below, in the same row, for every namespace we carry. Where a first year is promotional it says so and the renewal beside it is struck through in the manuscript convention the rest of the site uses — hover it and the notice that changed the price lights up. Registry wholesale prices do move; when one does we pass it through at cost and post it to Notices thirty days before it takes effect. A term you have already paid for is never re-priced.

← the table scrolls sideways →

The price book — twenty of 312 namespaces. Every price a name can cost you, on one line.
TLD First year Renewal Transfer in Restore Term & terms
.com $10.20 $10.20 $10.20 $78 1–10 yr · transfer adds 1 yr
.net $12.40 $12.40 $12.40 $78 1–10 yr · transfer adds 1 yr
.org $12.90 $12.90 $12.90 $78 1–10 yr · transfer adds 1 yr
.info $13.50 $13.50 $13.50 $78 1–10 yr · transfer adds 1 yr
.cloud $9.50 (was $11.90) $11.90 $11.90 $65 Promotion to 2026.12.31 — notice 2026.08.01
.dev $13.00 $13.00 $13.00 $65 HSTS preloaded — resolves over HTTPS only
.app $14.00 $14.00 $14.00 $65 HSTS preloaded — resolves over HTTPS only
.xyz $11.50 $13.50 $13.50 $65 First year promotional · renewal printed here, not later
.io $32.00 $32.00 $32.00 $90 1–10 yr · transfer adds 1 yr
.ai $68.00 $68.00 $68.00 $120 1–10 yr · registry restore fee is higher
.co $24.00 $24.00 $24.00 $90 1–10 yr · transfer adds 1 yr
.me $19.00 $19.00 $19.00 $78 1–10 yr · transfer adds 1 yr
.eu $8.90 $8.90 $8.90 $22 EEA/EU presence required · transfer adds no year
.uk / .co.uk $8.40 $8.40 Free $22 IPS tag change — no auth code, no fee, no year added
.de $9.80 $9.80 $9.80 $28 KK process with AuthInfo · transfer adds no year
.jp $28.00 $28.00 $28.00 n/a Registrar change, no auth code · no redemption period
.co.jp $62.00 $62.00 $62.00 n/a One per registered Japanese company · registrant name is published
.kr $26.00 $26.00 $26.00 $40 KR presence, or our trustee service at +$18/yr
.hk $34.00 $34.00 $34.00 $45 1–10 yr · transfer adds 1 yr
.cn $12.00 $12.00 $12.00 $40 Real-name verification required before the name resolves
312 namespaces are open as at 2026.08.26; these twenty are the ones most often asked for. Prices in USD, excluding VAT. UK VAT at 20% is added where applicable. Published 2026.08.26.

US dollars, VAT added where it applies. Restore is the fee to recover a name during the 30-day redemption period that follows expiry; after that comes 5 days pending delete, and then the name is gone. Registry wholesale increases are passed through at cost and posted to Notices 30 days ahead; a term already paid for is never re-priced. The remaining 292 namespaces are priced the same way in the console.

The first free transfer on a new account is on us — see the notice of 2026.04.02.

The Undertaking

Three things we will not do to your names.

01

We will not raise a renewal you were not shown.

The renewal price sits beside the first-year price on every row of the price book, and it is the price you will actually be charged. Registry increases are passed through at cost with sixty days' notice and the old price honoured for any year already paid.

02

We will not hold a name hostage.

No transfer-out fee, ever. The authorisation code is in your panel, not behind a ticket, and the lock comes off in one click. If we have made you unhappy, we would rather you left quickly.

03

We will not sell you a badge.

No organisation-validated certificates, no domain-protection insurance, no aftermarket brokerage on your own names. The list of what we decline to sell, and why, is further down this page.

Against the Market

The interesting number is year three.

A comparison that only flatters the author is not a comparison. Below, fourteen lines set against what a large general-purpose registrar typically offers — read from public price lists in August 2026, described as a market rather than as any one company. We are cheaper over any horizon longer than a year, because our first year and our r

五年 — one .cloud name, five years, cumulative
Year Here, running total The category pattern, running total You are ahead by
Year 1 $9.50 $1.99 −$7.51
Year 2 $21.40 $24.98 $3.58
Year 3 $33.30 $47.97 $14.67
Year 4 $45.20 $70.96 $25.76
Year 5 $57.10 $93.95 $36.85

Here: $9.50 for the first year under the promotion of 2026.08.01, then $11.90 at every renewal — the figure printed beside it in the price book. The second column is illustrative: a first-year loss-leader at $1.99 followed by a standard renewal of $22.99, which is the shape the category has settled on. No registrar is named because none has been asked. Prices in USD, excluding VAT. UK VAT at 20% is added where applicable. Published 2026.08.26.

Where they win

A large general-purpose registrar carries hundreds of namespaces we do not, runs an aftermarket where you can actually buy a name someone else already holds, and bundles a site builder and mailboxes that many people genuinely want. If you need an exotic ccTLD, a brokered acquisition, or one bill for hosting and email and the name, they are the better shop and we would rather say so here than pretend otherwise.

Transfers

What moves with a name, and what you have to carry yourself.

The single most expensive misunderstanding in this industry: a transfer moves the registration, not the zone. Your A records, your MX, your SPF and DMARC text, your CAA — those live on your current registrar's nameservers, and a transfer does not touch them. If you transfer without staging the zone first, the delegation keeps po

← the table scrolls sideways →

The seam — what a transfer carries, and what you carry yourself.
Object Moves with the domain What to do
The registration and its remaining term Yes — plus the year the transfer adds, on most gTLDs Nothing
Registry delegation (the NS records at the parent) Yes, exactly as recorded Change it after the transfer completes, not during
Glue / host objects (ns1.example.com and its addresses) Yes — recreated by us at the registry Check the addresses afterwards; a stale glue record is invisible until it isn't
Registrant, admin, tech and billing contacts Yes, as you supply them on the transfer form Do not change the registrant name, organisation or email in the same week — 60-day lock
DS records at the parent (DNSSEC) Yes, the DS survives the change of sponsor Fine if the DNS operator is unchanged. If it changes too, plan the rollover or the zone goes dark
The zone itself — A, AAAA, MX, TXT, CNAME, CAA, SRV No. It lives on the old registrar's nameservers Export it, or paste it here, before you start. This is the step people skip
Mailboxes bundled with the old registrar no Move the mail first, or keep paying them for it
URL and email forwarding rules no Recreate them here — forwarding is included
WHOIS privacy No — it is a registrar service, not a registry object We re-apply it automatically the moment the transfer completes
Auto-renew setting no On by default here. Check it anyway
SSL certificates No — a certificate is issued to a name, not to a registrar Existing certificates keep working. DNS-01 renewals need the CAA and _acme-challenge records present in the new zone
Account credit, loyalty points, 'domain protection' add-ons no Spend or cancel them before you go; they are not refundable to us
Site builder content no Export it first. Nobody else can
The 60-day transfer-out lock It starts again on completion Move a portfolio in one pass, not in weekly tranches

Everything in the 'No' column is recoverable if you handle it before the transfer and expensive if you handle it after. The zone is the one that causes outages.

An inbound transfer, step by step.

  1. Check the clock: no transfer within 60 days of registration, of the last transfer, or of a change of registrant

    You.

    1 min — the status codes are in RDAP

  2. Unlock the domain and copy the authorisation code

    Losing registrar.

    ICANN allows them 5 days. Most panels give it immediately

  3. Stage the zone here: import or paste every record, and leave the delegation pointing where it points

    You.

    5–20 min for a typical zone

  4. Submit the transfer and pay for the year it adds

    You, here.

    2 min

  5. Registry opens the transfer and notifies the losing registrar

    Registry.

    Under a minute

  6. Losing registrar acknowledges — or says nothing and the window runs out

    Losing registrar.

    Approved: minutes. Silence: 5 calendar days, then it completes anyway

  7. Registry moves the sponsorship. We re-apply privacy, registrar lock and auto-renew

    Registry, then us.

    Under 1 min

  8. Repoint the delegation at the staged zone, if you are changing nameservers

    You.

    Propagation is your old NS TTL — typically 1 hour

  9. Re-sign with DNSSEC if the DNS operator changed, and update the DS at the parent

    You and us.

    10 min, then the parent DS TTL — 86,400 s on .com

Step 6 is the only one you cannot hurry, and it has two paths: the losing registrar approves and the name moves in minutes, or it stays silent and the ICANN window expires after five calendar days. A portfolio can therefore clear in a weekend or take a working week, and which one it is depends on them, not on us.

Starting an inbound transfer from the CLI
$ yunagi domains transfer start example.com \
    --auth-code 'Xk7-qP2v-R9tL' \
    --years 1 \
    --contacts ct_9f31 \
    --dns import          # copy the live zone here first; delegation untouched

transfer requested   example.com
  zone imported      41 records
  registry ack       pending
  window closes      2026-08-31 09:14 UTC   (5 days)
  adds               1 year  ->  2027-11-04
  on completion      privacy on · registrar lock on · auto-renew on
--dns import stages the zone without touching the delegation, so nothing changes for visitors until you repoint the nameservers yourself. If the losing registrar approves explicitly this finishes in minutes; if it says nothing, it finishes when the window closes.

Locks & Holds

Every lock that can stop a name moving, and who can lift it.

When a transfer is refused, the reason is always a status code, and the code is always visible in RDAP. Nine of them matter. Three are yours and clear in one click. Three are policy, run on a clock, and cannot be waived by anyone — although the sixty-day change-of-registrant lock can be declined at

← the table scrolls sideways →

Every lock and hold that can sit on a name.
Lock or hold EPP status Set by Duration Can it be lifted
Registrar lock clientTransferProhibited You — on from registration Until you clear it Yes, one click, immediately
Update lock clientUpdateProhibited You, optional Until you clear it Yes, one click
Delete lock clientDeleteProhibited You, optional Until you clear it Yes, one click
Post-registration lock clientTransferProhibited, applied on our side ICANN Transfer Policy 60 days from creation No. Nobody can waive it
Post-transfer lock clientTransferProhibited ICANN Transfer Policy 60 days from the last completed transfer no
Change-of-registrant lock clientTransferProhibited ICANN Transfer Policy 60 days from a change of registrant name, organisation or email Only by declining it at the moment of the change — our contact form asks you there
Registry Lock — $180/yr per name serverTransferProhibited, serverUpdateProhibited, serverDeleteProhibited The registry, on our instruction after an off-band check Until you lift it Yes, by voice call-back, within 1 business day
Expiry hold clientHold Us, 1 day after expiry Through the 30-day redemption period Cleared the moment you renew
Registrant verification hold clientHold Us, on day 15 if the registrant email is unverified Until verification Cleared on verification — required of every accredited registrar

All nine are visible in RDAP, on your name, right now — a refused transfer always has one of these behind it. clientHold removes the name from the DNS entirely: the site and the mail stop, which is the point.

The Controls

Four controls, on by default where they should be.

WHOIS privacy is included on every namespace whose registry permits it, forever, and there is no checkout screen where it becomes a line item. RDAP publishes the registrar, the status codes, the dates, the nameservers and the registrant's country; everything else is redacted. Where a registry insist

WHOIS privacy
On by default at no charge on every TLD whose registry permits it. Off automatically where it does not — .co.jp publishes the registrant name, and we say so on the row.
Registrar lock
On by default. One click to release, and the release is logged with the account, the address and the time.
Registry Lock
$95 a year on the TLDs that offer it. Two named contacts, a spoken passphrase, and a change takes two people and about a day. Worth it for a name a business depends on.
DNSSEC
Free. Signed with ECDSA P-256, the DS record pushed to the parent automatically when we are the DNS operator.
Glue records
Free, on any name you hold here, in the panel and in the API.
Two-factor
TOTP required on every account that holds a name. Not an upsell.
Abuse contact
[email protected], answered by a person inside 24 hours. IANA registrar ID 4471 — illustrative in this specification.
$ yunagi domains dnssec enable example.com
  algorithm     13  (ECDSAP256SHA256)
  denial        NSEC3, 0 iterations, no salt
  KSK 2371 · ZSK 51844
  DS published at the parent:
    example.com. IN DS 2371 13 2 4f8b3c9d1a27e6540bd83f19c7a4e0b6\
                                 2d5138af90c47eb1256a3fd8e79b0c34
  validation begins after the .com DS TTL expires — 86400 s

$ delv @ns1.yunagi.cloud example.com A
; fully validated
example.com.  3600  IN  A      203.0.113.24
example.com.  3600  IN  RRSIG  A 13 2 3600 20260925000000 20260826000000 \
                               2371 example.com. Xk9vT2p...
The DS digest is SHA-256 (digest type 2) taken over the KSK. If you are changing DNS operator and the zone is signed, the safe order is: remove the DS, wait the parent TTL, move, re-sign, republish. Skipping the wait is what takes a signed zone dark.

The Zone

Your records, and the nameservers that answer for them.

Anycast from all six metros on AS207214: ns1, ns2 and ns3.yunagi.cloud, answering from London, New York, Los Angeles, Tokyo, Seoul and Hong Kong. Unlimited zones, ten thousand records in each, included with any name registered here and available on its own if the name is registered elsewhere. Changes are live at every

A complete zone as we hand it to you
$ORIGIN example.com.
$TTL 3600
 
@       IN  SOA   ns1.yunagi.cloud. hostmaster.example.com. (
                  2026082601  ; serial
                  7200        ; refresh
                  900         ; retry
                  1209600     ; expire
                  3600 )      ; negative-answer TTL
 
@       IN  NS    ns1.yunagi.cloud.
@       IN  NS    ns2.yunagi.cloud.
@       IN  NS    ns3.yunagi.cloud.
 
@       IN  A     203.0.113.24
@       IN  AAAA  2001:db8:2073::24
www     IN  CNAME example.com.
 
@       IN  MX    10 mx1.example.com.
@       IN  MX    20 mx2.example.com.
mx1     IN  A     203.0.113.40
mx2     IN  A     203.0.113.41
 
@       IN  TXT   "v=spf1 mx -all"
_dmarc  IN  TXT   "v=DMARC1; p=reject; rua=mailto:[email protected]"
 
@       IN  CAA   0 issue "ca.yunagi.cloud"
@       IN  CAA   0 iodef "mailto:[email protected]"
 
; certificate renewal, delegated once so no record is ever written by hand
_acme-challenge IN CNAME _acme.yunagi.cloud.
Addresses are from the documentation ranges (RFC 5737 and RFC 3849) so the file can be pasted into a lab without touching anything real. This file is exactly what a transfer does not carry — export it before you move.

Full reference — docs.yunagi.cloud/v1

Certificates

Two certificates we sell, and the ones we will not.

Domain validation, issued against a DNS-01 challenge we can answer for you when the zone is here. A single certificate covers a name and its www; a wildcard covers one level of subdomain and the apex with it. Reissue is free and unlimited for the life of the certificate, which matters more than the

← the table scrolls sideways →

Certificates — what we issue, what it covers, what it costs.
Product Validation Covers Issue (median) Price Reissue
ACME (automatic) DNS-01, answered by our nameservers One name, or a wildcard, in any zone we host 90 s $0 — included with DNS here Automatic, at 30 days remaining
DV single DNS-01 or HTTP-01 example.com and www.example.com 4 min $6 / yr Free for the life of the certificate, on reasonable use
DV wildcard DNS-01 only — the protocol requires it *.example.com and example.com, one level 6 min $48 / yr Free, on reasonable use
DV multi-domain (SAN) DNS-01 or HTTP-01 Up to 10 names on one certificate 7 min $18 / yr, then $4 per name over 3 Free on reasonable use; names can be added mid-term

One-year lifetimes on the paid tiers, 90-day on ACME. If your zone is on our nameservers, use ACME: it is free, it renews itself, and it is the only tier that cannot expire because someone left the company. The paid tiers exist for estates that need a dated artefact for an auditor.

What we do not sell, and why.
Not sold Why
Organisation Validation (OV) It secures the connection exactly as well as a DV certificate and no better. The visible difference disappeared when browsers dropped the identity indicator in 2019
Extended Validation (EV) Same reason, plus days of company paperwork and roughly ten times the price. We would be selling a badge
Code signing A different trust store, hardware token logistics and a different threat model. Not our trade, and half-doing it would be worse than not doing it
'Domain protection' insurance add-ons Registrar lock, Registry Lock and two-factor are the actual controls, and two of the three are free here
Private CA / self-signed issuance You can issue those yourself in a minute. Charging for it would be charging for openssl

Every line here is a product a registrar can profitably sell. They are absent because we could not write an honest sentence explaining what you would get.

Portfolio

One name or four thousand, at the same published price.

There is no volume tier, no reseller tier, and no minimum. The four-thousand-name account and the one-name account read the same price list, which is why we can publish it. What scale buys you here is machinery rather than a discount: CSV or API for five thousand rows an operation, contact sets appl

Portfolio limits — the ceilings that actually exist.
Operation Limit Notes
Names per account No limit Largest account today: 4,100 names
Bulk register, renew, transfer or update 5,000 rows per file CSV or JSON, validated in full before anything is submitted
API rate 20 requests/s sustained, 60 burst, per token 429 with Retry-After; bulk endpoints are asynchronous and do not count against it
DNS zones Unlimited Anycast from all six metros, included with any name here
Records per zone 10,000 Higher on request, at no charge
Nameservers per domain 13 Registry ceiling, not ours
Glue / host objects per domain 13 Registry ceiling. Deletion is refused while another domain references the host
Contact sets 250 per account Apply one set to any number of names in a single operation
Auth-code export Whole portfolio, one file, self-serve No fee, no ticket, no waiting period beyond the policy locks
Renewal calendar ICS subscription and CSV export Notices at 45, 15, 5 and 1 days before expiry, and 3 days after
Volume pricing no 1 name and 4,100 names pay the same published price. That is what lets us publish it

Illustrative where marked: the 4,100-name figure is the largest account on the register in August 2026 and will change.

A bulk transfer file
domain,auth_code,years,contacts,dns,privacy
example.com,Xk7-qP2v-R9tL,1,ct_9f31,import,on
example.net,7fQ2-mB4x-Zt08,1,ct_9f31,import,on
example.org,Lp6-9wKd-Rn41,2,ct_9f31,keep,on
example.co.uk,,1,ct_9f31,import,n/a
Up to 5,000 rows, validated in full before a single transfer is submitted — a bad auth code fails the row, not the file. .uk carries no auth code because the transfer is an IPS tag change, and privacy is n/a there because the registry already withholds individuals' details. dns=import stages the zone here; dns=keep leaves the delegation and the records wherever they are.
Auditing what is about to renew
$ curl -sS https://api.yunagi.cloud/v1/domains \
    -H "Authorization: Bearer $YUNAGI_TOKEN" \
    -G --data-urlencode 'expires_before=2026-12-31' \
       --data-urlencode 'auto_renew=false' \
       --data-urlencode 'limit=200' \
  | jq -r '.data[] | [.name, .expires_on, .renewal_price, .status[0]] | @tsv'

example.com     2026-11-04   10.20   clientTransferProhibited
example.cloud   2026-12-02   11.90   clientTransferProhibited
example.io      2026-12-19   32.00   clientTransferProhibited
renewal_price is the figure from the price book, not a quote that changes at checkout. The same filter drives the ICS renewal calendar, so a portfolio can be audited from a terminal or subscribed to from a diary.

Questions

Asked at the counter.

If your question is not here, [email protected] reaches a person who has actually run a transfer.

Is the renewal price guaranteed?

Nobody can guarantee a registry's wholesale price, and a registrar who says otherwise is guessing. What we guarantee is narrower and real: the renewal figure printed beside the first year is what you pay at renewal; we do not add margin at renewal that was not there at registration; a registry increase is passed through at cost and posted to Notices thirty days before it applies; and a term you have already paid for is never re-priced. Register for ten years and the price is settled for ten years.

Do I have to move my DNS to use you as registrar?

No. The delegation is yours. Keep your nameservers where they are and we will simply record them at the registry. Our anycast DNS is included if you want it, and available on its own if the name is registered somewhere else.

How long does a transfer really take?

Twenty-two minutes is our H1 2026 median from submission to registry completion, for the transfers where the losing registrar approved explicitly. Where they let the clock run instead, it is five calendar days exactly, and no amount of chasing shortens it — that window belongs to ICANN policy, not to either registrar.

Why can I not transfer a name I registered last week?

The ICANN Transfer Policy forbids a transfer within sixty days of registration. The same sixty days applies after any completed transfer, and after a change of registrant name, organisation or email — that last one you can decline at the moment you make the change, and our contact form asks you there rather than letting you find out two months later.

Is WHOIS privacy an extra?

No, on any namespace whose registry permits it, for as long as you hold the name. RDAP shows the registrar, the status codes, the dates, the nameservers and your country; the rest is redacted. Four namespaces we carry will not accept a proxy registration at all, and they are named in the privacy panel before you buy.

What happens if I let a name expire?

Day 0 it expires. Day 1 we put it on clientHold, so the site and the mail stop — that is deliberate; it is the loudest alarm available. For thirty days you can restore it for the fee in the price book. Then five days pending delete, and then it is gone to the registry. We email at 45, 15, 5 and 1 days before, and once three days after. We do not auction it, park it, list it or hand it to a broker.

Can I sell a name through you, or buy one that is taken?

No. There is no marketplace, no brokerage and no escrow here — that is a business we have not built and would not do well. We will push a name to another Yunagi account free of charge, or hand you the authorisation code so it can go anywhere. If you need to buy a name someone already holds, a large registrar's aftermarket is the right tool.

Will DNSSEC survive a transfer?

Yes, if the DNS operator does not change: the DS record at the parent survives the change of sponsoring registrar. If you are changing registrar and DNS operator together, do not do both in one movement. Remove the DS, wait out the parent TTL — 86,400 seconds on .com — then transfer, then re-sign. We will run the sequence for you if you ask on the ticket.

Do you charge to transfer a name away?

No. The authorisation code is in your panel, the unlock is one click, there is no fee and no ticket. The only thing that can hold a name here is a policy lock that would hold it anywhere.

Bring the names over.

The first transfer on a new account is on us, the authorisation code lives in your panel from the first day, and nothing here has a transfer-out fee.