A subdomain is an extra name in front of your domain, such as shop.example.co.za or app.example.co.za, that you create yourself with a DNS record. It costs nothing to add, because you already own example.co.za, and it can point to a completely different server or service from your main website. Subdomains are the clean way to run an online shop, a web app, an API, a help centre or a staging copy of your site next to your main website without mixing them up.
This guide covers when a subdomain is the right choice, how to set one up and the security habit that stops abandoned subdomains from being hijacked.
How subdomains work
DNS names are read from right to left. In shop.example.co.za, za is the country domain, co.za is the second-level domain run by the registry, example is the part you registered, and shop is a label you added. You can add as many labels as you like: staging.app.example.co.za is a valid name too.
Each subdomain gets its own DNS records, so it can live anywhere. Your main website can be on one server, shop. on an e-commerce platform and mail. on your email host, all at the same time. www is itself a subdomain, which is why it needs its own record.
Common subdomains and what they are for
| Subdomain | Typical use |
|---|---|
www |
The main website (or a redirect to the bare domain) |
mail |
The mail server name used in email clients |
shop |
An online store on a different platform from the main site |
app |
A customer-facing web application or dashboard |
api |
An API that your app or partners call |
docs or help |
Documentation or a help centre |
staging |
A copy of the site for testing before changes go live |
status |
A status page that stays up when the main site is down |
Subdomain or subfolder?
blog.example.co.za and example.co.za/blog can show the same content, so which is better?
- Choose a subfolder when the content belongs to the main site, runs on the same platform and you want everything to build one site's reputation in search. A blog is usually best as
/blog. - Choose a subdomain when it is a separate system: a different platform, a different server, a different team, or something you might move independently later. A shop on a hosted e-commerce platform, a Node.js app or an API all fit here.
Search engines handle both, but they may treat a subdomain as a related yet separate site, so a subfolder is the safer default for content you want to rank with your main pages. The technical reality usually decides it: if the thing runs elsewhere, a subdomain is far simpler than proxying it into a folder.
How to create a subdomain
You create a subdomain by adding a DNS record wherever your domain's DNS is hosted.
Point it at a server: an A record
If the service gives you an IP address, add an A record:
app.example.co.za. 3600 IN A 203.0.113.25
Point it at a hosted service: a CNAME record
If the service gives you a hostname instead, add a CNAME:
shop.example.co.za. 3600 IN CNAME stores.example-platform.net.
A CNAME can't sit on the bare domain, but it works on any subdomain, which is one reason hosted services ask you to use a subdomain. For more on record types, see DNS records explained.
On NewHost
- A Node.js or Next.js app on its own subdomain: enter it as the custom domain when you create the application, for example
app.example.co.za, and add an A record pointing at the server IP shown on the app's page. SSL is issued automatically once the record resolves. - A record for a third-party service: if your domain uses NewHost DNS, open the domain under Domains in the dashboard and add the A or CNAME record the service gives you.
- A subdomain of a classic website: the Plesk control panel for your web hosting can add subdomains to the hosting account, within your plan's limits.
SSL for subdomains
Every hostname needs to be covered by a certificate. Let's Encrypt issues free certificates per name, so shop., app. and www. can each have their own, issued automatically where your host supports it. If you run many subdomains on the same server, a wildcard certificate for *.example.co.za covers them all with one certificate. SSL certificates explained covers the options.
Cookies and subdomains
Browsers scope cookies to hosts. A cookie set by app.example.co.za without a Domain attribute stays on app. only (a "host-only" cookie). If you set Domain=example.co.za, the cookie is sent to every subdomain, including ones you don't control closely, such as a marketing landing page built on a third-party tool. Keep session cookies host-only unless you genuinely need single sign-on across subdomains, and mark them Secure and HttpOnly.
Keep staging out of sight
A staging. subdomain is a full copy of your site, often with test data and fewer protections. Put it behind a password, and tell search engines not to index it with an X-Robots-Tag: noindex header, so it never competes with your real site in search results. For Git-based apps, preview deployments give you a staging URL per branch without managing subdomains by hand.
Avoid subdomain takeovers
Here is the security habit that matters most. Suppose shop.example.co.za has a CNAME pointing at a hosted platform, and you cancel that platform but leave the DNS record in place. On some services, someone else can then sign up and claim the name your record points to, and your subdomain starts serving their content, under your domain name, with a valid certificate.
The fix is simple:
- When you cancel a service, delete its DNS records the same day.
- Review your DNS zone a few times a year and remove anything you don't recognise.
- Keep a short list of what each subdomain is for and who owns it.
This belongs on the same list as the other items in our website security checklist for small businesses.
Frequently asked questions
Do I have to pay for a subdomain?
No. Subdomains of a domain you own are free to create; you only add DNS records. You may pay for whatever service the subdomain points to.
How long does a new subdomain take to work?
A brand-new name usually resolves within minutes, because nothing has cached it yet. Changing an existing record can take longer, depending on its TTL.
Can a subdomain have its own email addresses?
Yes, with its own MX records, for example [email protected]. Most businesses keep email on the main domain because it is simpler for customers to remember.
Is a subdomain bad for SEO?
Not inherently. It is a separate site from a search engine's point of view, which is fine for apps, shops and documentation. For blog content you want to rank alongside your main pages, a subfolder is usually the better choice.
Need DNS you can manage yourself? NewHost domains include a DNS editor for A, CNAME, MX, TXT and more, and Next.js hosting puts your app on its own subdomain with free SSL.