Self-Service Guide
Signing up, choosing a plan, verification, and managing your DNS Armor™ subscription — for self-service Personal, Business, and Education & Library accounts.
Signing Up, Choosing a Plan, and Managing Your DNS Armor™ Subscription
1. Introduction
This guide is for individuals, businesses, schools, and libraries who create their own DNS Armor™ account online — no sales contact, no onboarding project. You sign up in minutes, start a free trial, and manage your plan, seats, and billing yourself from inside the portal. Enterprise and MSP customers are onboarded under separate agreements and can skip this guide entirely.
1.1 What a Self-Service Account Is
A self-service account is a full DNS Armor™ tenant that you create and pay for yourself, with a card, on a monthly or annual subscription. It comes in three account types — Personal, Business, and Education & Library — chosen on the first signup step. The account type sets the device ceiling, the details you are asked for at signup, and (for Education & Library) the pricing entitlement. Everything inside the portal afterwards — the dashboard, policies, endpoints, analytics — is the same DNS Armor™ platform described in the Administration Guide (§1.3).
1.2 The Products
- DNS Armor™ Protect (DNS Firewall) — protective DNS for your devices. Your DNS queries are answered by DNS Armor™ resolvers, and access to malicious or otherwise harmful destinations is filtered according to your security policies. Protect is priced per seat, and one seat protects one device (§3.2).
- DNS Armor™ Resolve (Authoritative DNS) — a separately licensed product that hosts DNS zones and records for domains you own on the DNS Armor™ authoritative name-server network, with DNSSEC included. Resolve is licensed in its own right — it is not an extension of Protect — and is billed by usage, in blocks of zones and records (§3.4).
Protect and Resolve are two separate licenses, and neither depends on the other: you can subscribe to Protect alone, to Resolve alone, or to both. Choosing both is simply a convenience — one checkout and one invoice — with each license priced and shown as its own line.
1.3 How This Guide Fits with the Other Guides
This guide covers what is unique to self-service accounts: signing up, plans and pricing behaviour, the free trial, Education & Library verification, the Manage Subscription page, and the non-payment lifecycle. For everything you do inside the portal after that, use the existing guides — the features behave identically for self-service and standard accounts:
- Administration Guide — security policies, local rulesets, endpoints, networks, users, MFA, DNS monitoring and analytics.
- Authoritative DNS Guide — zones, records, DNSSEC, traffic steering, and statistics for DNS Armor™ Resolve.
- Endpoint Agent Deployment Guide — installing the agent that brings your devices under Protect.
2. Creating Your Account
Where to find it: the DNS Armor™ portal login page → Don't have an account? Sign up
Signup is a short guided chain with a progress bar across the top: Type → Account → Verify → Plan → Payment. You can stop after any completed step and pick up where you left off by signing back in.
2.1 Step 1 — Account Type
The first step, "Who are you protecting?", asks you to pick the account type that fits — it sets your device limits and the details you are asked for:
| Account type | Who it is for | Email requirement |
|---|---|---|
| Personal | Your own devices and home network | Any email address |
| Business | A company fleet | Business email address required |
| Education & Library | Schools, universities, and libraries — organization details now, verification later (§4) | Business email address required |
Each card shows its current device ceiling (for example "Up to … devices"); the Education & Library card shows the devices-per-seat entitlement that applies after verification ("1 seat = … devices"). These figures are published live on the signup page for your deployment. Fleets beyond the self-service ceilings belong in DNS Armor™ Enterprise — the page asks "Need 1,000+ devices?" and links to Talk to Enterprise.
Business email rule: Business and Education & Library accounts must sign up with a business email address. Consumer mailbox domains are refused with "Please use your business email address" — on the email path and equally after a Google, Apple, or Facebook sign-in that resolves to a consumer mailbox. Personal accounts are never gated. You can change your mind at any time with Change account type.
2.2 Step 2 — Your Details, Region, and Terms
The "Create your account" step collects, in one card:
- First name and Last name — everyone.
- Organization name, Organization website (optional), Contact number, and Role / job title — Business and Education & Library only.
- Select your region — the data-residency choice. Your DNS logs are archived and stored in the region you pick, so choose the location closest to you or the one your data-residency rules require. The picker lists every currently available region with its city and country.
- Terms of Service — tick "I agree to the Terms of Service and Privacy Policy"; the View link opens the full DNS Armor™ Self-Signup Terms of Service. After signup you receive a confirmation email with a copy of the Terms. If the Terms are later updated, the portal asks you to review and accept the updated version before you continue using the service.
2.3 Verifying Your Email (One-Time Code)
The default identity method is your email address plus a one-time code:
- Enter your email, complete the automated verification challenge, and click Send me a code.
- The "Check your email" step appears — a 6-digit code has been sent to your address.
- Type or paste the code and click Verify.
Codes expire after 10 minutes, can be used only once, and allow only a limited number of attempts — after too many wrong entries the code is invalidated ("Too many attempts. Please request a new code.") and you must request a new one. Re-requesting a code for the same address is paused for about a minute between sends — if you mistyped the address, use Go back and correct it; a corrected address is not subject to the pause.
2.4 Signing Up with Google, Apple, or Facebook
Where the deployment has them enabled, the same step offers Continue with Google, Continue with Apple, and Continue with Facebook above the "or continue with email" divider — only the providers actually available are shown. Complete your details and accept the Terms of Service (§2.2) before choosing a provider. A provider sign-in replaces the one-time code: the provider verifies your address and you continue straight to the plan step. The business-email rule of §2.1 still applies — a provider account on a consumer mailbox cannot open a Business or Education & Library account. You can later use a different enabled provider with the same email address; it signs you into the same account.
2.5 If Your Email Is Already Registered
An email address that already belongs to a standard DNS Armor™ portal account (an Enterprise or MSP-managed user) cannot open a self-service account. For security, the signup page behaves the same either way — but no code is sent; instead, the owner of the address receives an email explaining that they already have an account and should sign in from the login page. The code screen carries the matching hint: "Didn't get a code? If this email is already registered with a standard portal account, no code is sent — sign in from the login page instead."
3. Choosing Your Plan
After verification, the "Choose your plan" step presents your selection: one Protect tier (or none), DNS Armor™ Resolve if you want it, the seat count, and the billing interval. The two products are licensed separately, so you may take either one on its own or both in the same checkout. The same picker reappears later on the Manage Subscription page whenever you change plans (§6.2).
3.1 Protect Tiers — Basic and Advanced
DNS Armor™ Protect comes in two per-seat tiers, shown in the portal as "DNS Armor™ Protect — Basic" and "DNS Armor™ Protect — Advanced":
- Basic — fixed allowances. Includes 2 security policies, 2 local rulesets, and 2 portal users, with 1 protected device per purchased seat. Local resolvers, external RPZ feeds, networks, and DDNS names are Advanced features.
- Advanced — grows with your fleet. Entitlements grow every 200 devices, up to plan maximums: each full 200 devices adds further security policies, local rulesets, portal users, local resolvers, and external RPZ feeds, and external/private networks and DDNS names scale per device. The exact per-tier entitlements, growth steps, and caps are printed on the plan cards themselves (the information icon on each card opens the full breakdown), so the portal is always the authoritative list.
You may also select no Protect tier at all and continue with Resolve only ("Skip device protection — continue with Resolve only.").
3.2 Seats Are Devices
Protect is sold per seat, and one seat protects one device — the picker's counter is labelled Protected devices and shows the resulting device total as you adjust it. The one exception is a verified Education & Library account, where each seat covers multiple devices according to the devices-per-seat entitlement published at signup and on the plan pages (§4.2) — the picker then shows the arithmetic explicitly (for example "10 seats × ratio = devices") together with the "Education pricing" note. Seat counts are capped per account type; at the cap, the picker offers Contact Sales / Contact Enterprise Sales for larger deployments.
3.3 Monthly or Annual
A Monthly / Annual toggle sets the billing interval for the whole bundle. Annual billing is discounted — the current discount is displayed on the toggle and reflected in the per-device prices shown beneath it. Subscriptions are billed automatically in advance: on each renewal date your card is charged for the upcoming period according to the subscription active at that moment.
3.4 DNS Armor™ Resolve — a Separate License
The "DNS Armor™ Resolve" block selects authoritative DNS hosting. Resolve is its own license, not an extension of Protect: you may take it on its own, or alongside a Protect tier in the same checkout, and it appears as its own line on the invoice either way. Unlike Protect there is no quantity to choose — Resolve is billed by usage, in blocks of hosted zones and DNS records (currently 10 zones per zone block and 100 records per record block, up to the caps shown in the portal for your account type). Block counts follow your live usage automatically: create more zones or records and the additional blocks appear on your next invoice; delete usage and the next renewal reflects the reduction. On annual plans, blocks added mid-year are prorated for the remainder of the year. DNSSEC is included. Managing zones and records is covered in the Authoritative DNS Guide.
3.5 Prices Are Always Live
Every price on the plan picker — per-device monthly and annual prices, the running bundle total, and the Resolve block prices — is retrieved live from the billing system at the moment it is displayed. This guide therefore quotes no amounts: the price you see on the page is the price that applies. Prices may exclude taxes, which are added where required by law, and a price change never affects a period you have already paid for.
3.6 Payment Method and the 30-Day Free Trial
Continue to payment opens the "Payment method" step. Your card is collected through a secure Stripe payment element and stored with Stripe — DNS Armor™ never stores your card number. Click Save card & start to create the subscription.
First-time subscribers receive a 30-day free trial:
- You are not charged during the trial — the page says so as you save the card: "Your free trial starts now — you will not be charged until it ends."
- The first charge is taken automatically when the trial ends, for the plan, seat count, and interval in effect at that moment. The Next bill tile (§6.3) shows you that exact upcoming charge at all times.
- The trial is offered once per person and per account, ever. If the account has previously held a subscription — including one that was cancelled or lapsed — a new subscription is billed from its start date without a further trial.
- Cancelling during the trial (§6.7) ends the subscription at trial end with no charge.
4. Education & Library Verification
Education & Library accounts are reserved for accredited educational institutions and public or community libraries, and eligibility is verified before you can purchase a plan. Signup itself completes normally (§2), but the plan step is replaced by a verification gate until your organization is approved.
4.1 While Verification Is Pending
The "Verification in progress" screen confirms your account is created and your organization is being reviewed — verification usually takes less than one business day. You receive an email the moment the account is approved; then simply sign back in to choose your plan — everything you entered is saved. Until approval, plans cannot be purchased or changed, and the Manage Subscription page shows the same "Education & Library verification" notice in place of the plan controls.
4.2 When Approved
Approved accounts unlock the plan step with two Education & Library entitlements:
- Education pricing — dedicated education prices, shown live on the plan picker like all other prices (§3.5).
- The device multiplier — each purchased seat covers multiple devices, at the devices-per-seat ratio published at signup and on your plan pages. The picker shows the seat-to-device arithmetic as you choose a seat count.
These entitlements apply while your verified status is active, as set out in the Terms of Service.
4.3 If Verification Is Not Approved
If eligibility cannot be confirmed, the signup page shows "About your Education & Library request" (and the Manage Subscription page shows "Verification not approved"). Two paths forward:
- Continue as a Business account — same protection, per-device pricing; contact support and they will help you switch.
- Appeal — reply to the notification email with accreditation or registration documents and the request is reviewed again.
5. Signing In and Multiple Accounts
5.1 Signing In
The signup page doubles as the self-service sign-in: verify your email with a one-time code, or use Continue with Google / Apple / Facebook, exactly as at signup — a returning address signs you straight into your account instead of creating a new one (or into the Manage Subscription page if the account is inactive, §7.2; an address holding several accounts gets the account picker, §5.2). If you prefer the classic login form, request a password first: on the Manage Subscription page, Security & data → Email me a temporary password sends you a temporary password you can use (and then change) on the standard portal login page.
5.2 The Account Picker
One email address can hold several self-service accounts — for example a Protect subscription for your devices and a separate Resolve-only account for your domains. When an address with more than one account signs in, the "Choose an account" screen lists them, each labelled with its plan bundle (or "No plan yet") and an Active / Inactive status chip. Pick one to enter it.
5.3 Switching Accounts In-Session
Inside the portal, the Manage Subscription page shows a "Your products" card whenever you hold more than one account. Click another account's button to switch to it without signing out — the portal reloads into the selected account.
6. Managing Your Subscription
Where to find it: Sidebar → Manage Subscription (a top-level entry shown for self-service accounts), or the avatar menu in the top bar → Manage Subscription
6.1 Page Overview
The header card names your current bundle (for example "DNS Armor™ Protect — Advanced + DNS Armor™ Resolve") with a product chip per component and a status chip — Active, Inactive, or Payment issue. Beneath it, a row of tiles summarises the subscription at a glance:
- Billing — "Billed monthly" or "Billed annually".
- Protected devices — your current seat count.
- Renews on — the next renewal date (it becomes Access until once a cancellation is scheduled).
- Next bill — the real upcoming charge, clickable for a full breakdown (§6.3).
- Resolve usage — zones and records in use, when Resolve is on the bundle (§6.4).
Below the header sit the Payment method, Your products (§5.3), Billing history, and Security & data cards.
6.2 Changing Plan or Seats
Click Change plan (or Start subscription if you have not subscribed yet — a payment method must be on file first: "Add a payment method first, then choose your plan."). The dialog contains the same bundle picker as signup, with live prices and totals; adjust the Protect tier, whether the Resolve license is included, Protected devices, and the interval, then Confirm.
The "Next charge" preview. While the dialog is open, every change you make is simulated against your real billing state and shown before you confirm: "Next charge: {amount} on {date}", with Show breakdown expanding the full line-item detail — prorations included; during a trial it is the trial-end invoice at the new quantities. Nothing is charged until you confirm.
How changes are billed:
- Upgrades and seat increases take effect immediately — the added capacity is usable at once. The prorated cost of the increase for the remainder of the current period is billed in arrears on your next invoice, together with the upcoming period at the new plan and seat count. This works the same way on monthly and annual plans; the only interval-specific rule concerns Resolve usage blocks, which on annual plans are prorated for the remainder of the year (§3.4).
- Downgrades and seat decreases also take effect immediately, with a prorated credit applied to your next invoice.
- Seat decreases are refused while usage exceeds the reduced allowance. Per-seat quotas (devices, and on Advanced also networks and DDNS names) shrink with the seat count, so the portal blocks the change and lists the exact violations — remove the excess usage first, then retry. Seat increases always pass.
6.3 The Next Bill Tile
The Next bill tile shows the amount your card will actually be charged next, and on what date — including the first real charge at the end of a trial. Click it (View bill breakdown) to open the line-item dialog: each line with its quantity and period, prorations marked Proration, then Subtotal, Discount, Tax, any Account credit applied, and the bold Amount due. If the headline is lower than the sum of the lines, the Account credit row is the reason — credit accrued from downgrades (or from plan switches during a trial) is consumed before your card is charged.
6.4 Resolve Usage
With Resolve on the bundle, the Resolve usage tile shows your current zones and records against their caps and how they translate into billed blocks (or "No usage yet — nothing billed"). Because Resolve billing follows what you create (§3.4), this tile is the live answer to "what will Resolve cost me at renewal".
6.5 Billing History and Invoice PDFs
The Billing history card lists every invoice with its number, date, amount, and status. Under each invoice number a reason label explains why the invoice exists — Signup, Plan change, Renewal, or Other — which is especially useful for the zero-amount proration invoices produced by plan changes during a trial. The download icon (Download PDF) saves the official invoice PDF. Each successful payment is also confirmed by a receipt email carrying the invoice number, date, amount, reason, and billing period, the same line-item price breakdown as the Next bill dialog, and a link to the PDF.
6.6 Updating Your Payment Method
The Payment method card shows the card on file (brand, last four digits, expiry — or the wallet name for wallet-based methods). Update payment method opens a secure form for a new card; on save it immediately becomes the default for all future renewals.
6.7 Cancelling and Reactivating
Cancel subscription schedules the cancellation for the end of the period you have already paid for — the confirmation dialog states the exact date: access continues until then, after which the subscription ends and no further charges occur. The header tile switches to Access until, and a confirmation email is sent. Any time before that date, Reactivate resumes the subscription as if nothing happened, with billing continuing at the next renewal. Cancelling during the free trial simply ends the subscription at trial end with no charge. Refunds are not provided for partial periods except where the law requires.
6.8 Security & Data
The Security & data card offers three account-level actions:
- Email me a temporary password — for signing in through the classic login form (§5.1).
- Download my data — exports your account data as a JSON file.
- Delete account — opens a checklist of your accounts so you delete exactly the ones you intend to. Deletion takes effect immediately and is permanent: all configuration, DNS zones, and data are removed at once (invoices are retained as required by law), and it cannot be undone. Billing stops separately: any active subscription is set to cancel at the end of the current paid period, so no further renewal is charged — the account itself does not remain available until then.
7. If a Payment Fails
7.1 Payment Problems and Retries
If a renewal charge fails, the payment is retried automatically and you are notified by email so you can act. In the portal, the subscription chip changes to Payment issue and a "Payment problem" banner appears on Manage Subscription with the two possible fixes side by side: Confirm payment (when your bank requires you to approve the charge) and Update payment method (when the card itself is the problem). Resolving either clears the banner and the subscription continues normally. A payment dispute or chargeback may suspend the service while it is under investigation, and plan, seat, and billing changes are unavailable until it is resolved; a dispute resolved against DNS Armor™ cancels the subscription.
7.2 The Inactive Lockdown
If payment cannot be collected, service is suspended after the last day you have paid for and the account becomes Inactive. Signing in still works, and the Manage Subscription page remains fully available — but everything else in the portal is locked, and any attempt to use it routes you back to Manage Subscription. The page shows the "Subscription inactive" banner: "Your subscription is inactive, so access to the service is paused. Renew your plan to regain access — everything is restored the moment your payment goes through." Click Renew subscription, complete the payment, and full access returns within moments — no re-login required and nothing about your configuration is lost while inactive (until deletion, §7.3).
7.3 Data Retention and Deletion
Accounts with no active payment are permanently deleted 60 days after the last paid day. Warning emails are sent to your registered address ahead of the deadline so you can restore payment and keep the account. Deletion is irreversible and includes all account data, configuration, and DNS logs.
8. Using the Portal Day to Day
Beyond Manage Subscription, a self-service account is an ordinary DNS Armor™ tenant. The sidebar shows only the product blocks your licenses cover — DNS Firewall for Protect, Authoritative DNS for Resolve — so an account holding just one of the two licenses never sees the other product's menus at all, and every page behaves exactly as documented in the other guides; your plan tier only determines how many of each object you may create (§3.1):
- Security policies, local rulesets, bypass domains, networks, DDNS names, endpoints, monitoring, and analytics — see the Administration Guide.
- Protecting devices — install the agent on each device you want under Protect; see the Endpoint Agent Deployment Guide.
- Zones, records, DNSSEC, and traffic steering for Resolve — see the Authoritative DNS Guide.
ℹ️ NOTE: if a creation attempt is refused with a limit message, you have reached a plan entitlement — raise the seat count or move to Advanced from Manage Subscription → Change plan (§6.2), and the new allowance is usable immediately.
9. Troubleshooting
| Symptom | Likely cause | What to do |
|---|---|---|
| No signup code arrives | The code expired or was mistyped too often; the address may already belong to a standard portal account; or the resend pause is active | Check spam, wait a minute and request a new code (§2.3); if the address is already registered you received a "sign in instead" email (§2.5) |
| "Please use your business email address" | Business or Education & Library signup with a consumer mailbox domain | Use your organization's email domain, or choose Personal (§2.1) |
| The plan step never appears (Education & Library) | Verification is still pending or was not approved | Wait for the approval email and sign back in (§4.1); if rejected, continue as Business or appeal with documents (§4.3) |
| A seat decrease is refused ("Seat Change Blocked") | Current usage exceeds what the reduced seat count allows | Remove the listed excess devices, networks, or DDNS names, then retry (§6.2) |
| The next bill looks higher than the plan price | Prorated charges from a mid-cycle upgrade, or Resolve usage blocks grew | Open the Next bill breakdown — every line is itemised, prorations marked (§6.3) |
| The charge is lower than the invoice total | Account credit from a downgrade was applied | See the Account credit row in the breakdown (§6.3) |
| Portal pages all redirect to Manage Subscription | The subscription is inactive after failed payment | Click Renew subscription and complete payment — access is restored immediately (§7.2) |
| Renewals keep charging an old card | The new card was added but a renewal was already in flight | Confirm the card shows under Payment method; use Confirm payment on the banner if your bank requires approval (§6.6, §7.1) |
| No further trial on a new subscription | The account has already used its one-time trial | Expected: the trial is offered once per person and per account, ever (§3.6) |
END OF DOCUMENT
DNS Armor™ Self-Service Guide
v1.0 · July 2026
© 2026 Secure Domains - All Rights Reserved
For technical support: support@secure-domains.org
Portal: https://dnsarmor.secure-domains.org
Documentation: https://www.secure-domains.org/documentation