Learn / Glossary

Glossary

Short explanations of the terms you run into when you manage a website. Use the box to filter.

.htaccess

A per-directory configuration file for Apache. WordPress uses it for pretty permalinks. A syntax error in it produces a 500 error.

A record

A DNS record that maps a hostname to an IPv4 address, such as 203.0.113.25. It is the record most sites depend on. If your site loads at the wrong server after a move, this is the first place to look.

AAAA record

The IPv6 version of an A record. If you publish one, make sure your server really answers on that address. A stale AAAA record pointing at an old host is a classic cause of "it works for some people".

Access log

A file in which the web server records every request it handles: who asked, for what, when, and with what result. The best source of truth about real traffic.

ACME

The protocol certificate authorities use to issue certificates automatically. A client proves it controls a domain and receives a certificate, which is what makes hands-off renewal possible.

Aftermarket

The secondary market where people buy and sell registered domain names, usually through brokers, auctions or marketplaces.

Anycast

A routing technique that gives many servers around the world the same address, so each visitor reaches the nearest one. Widely used by DNS providers and CDNs.

Apache

A web server that has been around since 1995 and still powers a large share of shared hosting. It can read per-folder settings from .htaccess files, which is convenient for WordPress and slightly slower than central configuration.

API

A way for one program to talk to another. In hosting, panels and DNS providers often have APIs so you can automate things like creating records or issuing certificates.

Authorisation code

Also called an EPP code or transfer key. A secret string from your current registrar that proves you are allowed to move a domain to another one.

Authoritative nameserver

The server that holds the actual records for a domain and gives the final answer, as opposed to a resolver that only repeats what it has been told.

Autoloaded options

Settings in the WordPress database that are loaded on every page request. If plugins leave too many large ones behind, every page gets slower.

Backorder

A request to a service to try to register a domain the moment it becomes available after expiry.

Backup

A copy of your files and databases that lets you recover after a mistake, a hack or a hardware failure. A backup only counts if it is stored somewhere separate from the original and you have tried restoring it.

Bandwidth

The amount of data your site sends to visitors over a period, usually a month. Not to be confused with network speed. A page of 2 MB viewed 10,000 times is roughly 20 GB.

Bot

A program that sends requests automatically. Some are useful, like search crawlers, and many are not, such as scrapers and vulnerability scanners.

Brotli

A compression method for web content, usually a bit smaller than Gzip for text such as HTML, CSS and JavaScript. Modern browsers support it over HTTPS.

Browser cache

Files that a visitor's browser keeps so it does not download them again. Controlled by headers such as Cache-Control and ETag.

CAA record

A DNS record that says which certificate authorities may issue certificates for your domain. It is a simple safeguard. If you add one, include the authority your host uses, or automatic renewal will fail.

Cache hit and miss

A hit means the answer was found in the cache and returned quickly. A miss means the system had to do the full work and then, usually, stored the result.

Cache purge

Deleting stored copies so that visitors see the latest version of a page or file. Most CDNs and caching plugins offer a button or an API for it.

Canonical URL

The preferred address for a page when several addresses lead to the same content. A tag in the page tells search engines which one to treat as the main version.

ccTLD

Country-code top-level domain, such as .bg, .de or .uk. Some have local presence or residency requirements.

CDN

A content delivery network: a set of servers around the world that keep copies of your files and deliver them from the nearest location. It speeds up static content and can absorb traffic spikes.

Certificate authority (CA)

An organisation that browsers trust to issue certificates. Let's Encrypt, DigiCert, Sectigo and GlobalSign are examples.

Certificate chain

Your certificate, plus one or more intermediate certificates that connect it to a root the browser trusts. If the server forgets to send the intermediates, some devices will show an error even though others cope.

Certificate Transparency

Public logs in which certificate authorities record every certificate they issue, so mistakes and abuse can be detected by anyone, including domain owners.

Cipher suite

The set of algorithms used to protect a TLS connection. Servers offer a list, and the browser picks one both support. Old, weak ones should be disabled.

Cloud hosting

Hosting on pooled infrastructure where resources can be added or removed quickly and billing is based on use.

Cluster

A group of servers that work together, sharing load or providing backups for each other.

CMS

Content management system. WordPress is the best known. It stores content in a database and builds pages when someone asks for them.

CNAME record

A DNS record that makes one name an alias for another. It cannot coexist with other records on the same name, which is why you cannot normally put one on the bare domain.

Container

A lightweight package that bundles an application with what it needs to run, so it behaves the same on any machine. Docker is the best-known tool.

Control panel

The web interface for managing hosting: domains, mail, databases, files and backups. cPanel, Plesk and DirectAdmin are common examples.

Cookie

A small piece of text a website stores in your browser to recognise you on later requests. Used for logins, baskets and preferences.

CPU limit

The cap on processing power an account may use. Reaching it slows the site or produces errors until usage falls.

Cron job

A task scheduled to run at set times on a server, such as a nightly backup. Often forgotten during migrations.

CSR

Certificate signing request. A block of text you generate on your server containing your public key and the names you want covered. You send it to the certificate authority; the private key never leaves your server.

DDoS

Distributed denial of service: an attack that floods a site with traffic from many sources until it cannot respond. CDNs and filtering services are the usual defence.

Dedicated IP

An IP address assigned to a single account rather than shared. Useful for firewall rules and isolated mail reputation.

Dedicated server

A physical server rented to a single customer. You get all of its resources and all of its maintenance.

DKIM

An email authentication method. Your mail server signs each outgoing message, and the matching public key is published in DNS so receivers can verify it.

DMARC

A DNS policy that tells receiving servers what to do with mail that fails SPF and DKIM checks for your domain, and where to send reports. Start with a monitoring-only policy and tighten it later.

DNS

The Domain Name System, which translates names such as example.com into the addresses computers use. Often described as the phone book of the internet, though it is closer to a huge, distributed set of cached answers.

DNS over HTTPS

A way of sending DNS lookups inside an encrypted HTTPS connection, so others on the network cannot easily see which names you ask for.

DNS resolver

The server that looks up DNS answers on behalf of your device, usually run by your internet provider or a public service, and caches them.

DNSSEC

A set of extensions that adds digital signatures to DNS data so that tampering can be detected. It has to be set up at both the DNS host and the registrar, and mistakes can make a domain unreachable.

Document root

The folder on the server from which a site's files are served, often called public_html or www.

Domain parking

Pointing a domain you are not using yet at a placeholder page, often with adverts, until you build something.

Domain registrar

A company accredited to sell domain registrations. It holds your contact details and lets you set nameservers.

Domain registry

The organisation that runs a top-level domain, such as Verisign for .com. You deal with registrars; registrars deal with registries.

Domain squatting

Registering names resembling a brand or well-known name in the hope of selling them or profiting from confusion.

Downtime

A period when a site or service is unavailable. Counted differently by different providers, and often subject to exclusions.

Drop-catching

Automated services that try to register domains within moments of their release after expiry.

DV certificate

Domain-validated certificate. The authority checks only that you control the domain. The majority of certificates are this type.

Edge server

A server located close to visitors, used by CDNs and edge platforms to deliver content or run code with less delay.

Egress

Outgoing data from a server or cloud platform. Some clouds charge for it, which can surprise people with media-heavy sites.

Encryption at rest

Encrypting data where it is stored, on disks or backups, as opposed to while it travels over the network.

Endpoint

A specific address where an application or API accepts requests, such as /wp-json/ or a payment callback address.

Entry processes

A limit on how many requests an account may be handling at the same moment on some shared hosts. Hitting it produces 503 or 508 errors.

Error log

A file where the server records problems. If a site shows a blank page or a 500 error, this is where the explanation usually is.

ETag

A short identifier the server attaches to a file so browsers can ask whether it changed and get a quick yes or no.

EV certificate

Extended validation. The authority also verifies the legal organisation. Browsers no longer display the special green bar, so the practical benefit is small.

Failover

Automatic switching to a standby system when the main one fails, so service continues with little or no interruption.

Fair use policy

A provider's rules about how much of a resource marked unlimited you may reasonably use before it intervenes.

File permissions

Settings that say who may read, write or execute each file and folder. Too loose is a security risk, too tight breaks the site.

Firewall

Software or hardware that allows or blocks network traffic according to rules. A web application firewall (WAF) specifically inspects HTTP requests.

Forward secrecy

A property of modern TLS: even if a server's private key is stolen later, past recorded traffic cannot be decrypted.

FQDN

Fully qualified domain name: the complete name of a host, such as www.example.com, including every label up to the top-level domain.

FTP and SFTP

File transfer protocols. Plain FTP sends passwords unencrypted, so use SFTP, which runs over SSH.

Git

A system for tracking changes to code. Many deployments pull a site's code from a Git repository.

Glue record

A DNS record held at the registry that supplies the address of a nameserver located inside the domain it serves, avoiding a circular lookup.

Grace period

A short time after a domain expires during which the owner can usually still renew it at the normal price.

gTLD

Generic top-level domain, such as .com, .org or .shop, as opposed to a country code.

Gzip

The long-standing method for compressing text-based web files in transit. Easy to enable and almost always worth it.

Handshake

The opening exchange between two machines to agree on how to communicate. The TLS handshake sets up encryption.

Hashing

Converting data into a fixed-length fingerprint that cannot be reversed. Passwords should be stored as salted hashes, never as plain text.

Header

Extra information sent with a request or response, such as content type, caching rules or cookies.

Honeypot

A hidden form field or fake resource designed to catch bots. Humans never fill it in, so anything that does is rejected.

Hosts file

A file on your own computer that overrides DNS for chosen names. Handy for testing a new server before switching DNS.

Hotlinking

Embedding an image or file directly from someone else's server, using their bandwidth for your page.

HSTS

HTTP Strict Transport Security. A header telling browsers to use HTTPS only for your site for a set period. Powerful, and hard to undo if you set it too aggressively.

HTTP method

The verb in a request: GET to read, POST to submit, PUT or PATCH to change, DELETE to remove.

HTTP/2 and HTTP/3

Newer versions of the web's main protocol. They allow many requests over a single connection, which speeds up pages with lots of small files.

HTTPS

HTTP sent over an encrypted TLS connection. The little padlock era is mostly over; today it is just the baseline.

Hypervisor

Software that divides a physical machine into several virtual ones. VPS and cloud platforms are built on it.

Idempotent

Describes an operation that gives the same result however many times it runs. Good practice for scheduled jobs.

IMAP

A mail protocol that leaves messages on the server and keeps your devices in sync. The one to use if you read mail on more than one device.

Incremental backup

A backup that copies only what changed since the previous one. Fast and small, but restoring needs the whole chain.

Inode

A filesystem entry representing one file or folder. Many hosts limit the total number you may have, and cache folders and old mail can eat through it surprisingly fast.

Intermediate certificate

A certificate that sits between your site's certificate and the trusted root. Your server must send it along with its own.

IP address

A numeric address identifying a machine on a network. IPv4 looks like 203.0.113.25, IPv6 like 2001:db8::25.

IPv6

The newer address format created because IPv4 addresses ran out. Increasingly expected, and worth enabling if your host supports it.

LAMP

Linux, Apache, MySQL (or MariaDB) and PHP. The classic combination behind a huge amount of the web.

Latency

The delay before a response starts, often dominated by distance. Measured in milliseconds.

Lazy loading

Delaying the loading of images or other content until the visitor scrolls near it, to speed up the first view.

Let's Encrypt

A free, automated certificate authority run as a non-profit. It popularised ACME and short-lived certificates.

Load balancer

A system that spreads incoming requests across several servers. Also helps keep a site up if one server fails.

Log rotation

Regularly archiving and trimming log files so they do not fill the disk.

Mail relay

A server that accepts email and passes it on to its destination. An open relay, one that accepts from anyone, is quickly abused by spammers.

Maintenance mode

A temporary state in which a site shows a notice instead of normal pages while updates are done.

Malware scan

An automated search of your files for known malicious code. Useful, but not a guarantee. It catches the obvious and misses the clever.

Memory limit

The most RAM a script or account may use. WordPress commonly needs 256 MB or more, depending on plugins.

Mixed content

A secure page that loads some resources over plain HTTP. Browsers may block them or show a warning.

Monitoring

Watching a system's health continuously, such as checking uptime, response time and certificate expiry, and alerting when something fails.

MTA

Mail transfer agent: the software, such as Postfix or Exim, that moves email between servers.

Multisite

A WordPress feature for running many sites from one installation, sharing code and users.

MX record

A DNS record that says which servers receive email for a domain. Each has a priority number; the lowest is tried first.

MySQL and MariaDB

Related open-source databases used by WordPress and countless other applications. MariaDB began as a fork of MySQL.

Nameserver

A server that answers DNS questions for a domain. Your registrar needs to know which ones are yours.

NAT

Network address translation. Lets many devices share one public address, as in a typical home network.

Nginx

A fast web server and reverse proxy. Often sits in front of Apache or PHP-FPM, and is popular on VPS and managed platforms.

Object cache

A cache holding the results of database queries or computed data in memory, often with Redis or Memcached.

OCSP stapling

A server feature that attaches proof of a certificate's current validity to the TLS handshake, so the browser does not have to look it up separately.

Opcode cache

A PHP feature that stores compiled code in memory so it is not re-parsed on every request. OPcache is the standard one.

Origin server

The real server where your site lives, as opposed to the CDN copies in front of it.

OV certificate

Organisation validated. The authority checks basic company details in addition to domain control.

Page cache

A stored, ready-made copy of a finished page, served directly to avoid running PHP and the database.

Permalink

The permanent address of a post or page. Changing the structure can break links unless redirects are added.

Phishing

Messages or pages that pretend to be a trusted organisation to trick people into giving up passwords or payment details.

PHP

A scripting language that runs on the server and powers WordPress, Drupal, Joomla and many other applications.

PHP-FPM

A process manager for PHP that runs separately from the web server and handles requests more efficiently, with per-site pools and limits.

POP3

An older mail protocol that downloads messages to one device and often removes them from the server. Fine for a single computer; awkward for several.

Port

A numbered channel on a machine through which a particular service communicates, such as 443 for HTTPS.

Private key

The secret half of a key pair, which must stay on your server. Anyone who has it can impersonate your site.

Propagation

The informal term for how long it takes for a DNS change to be seen everywhere. In practice it is the time old cached answers take to expire.

PTR record

Reverse DNS: maps an IP address back to a name. Mail servers use it as a basic sanity check on senders.

Public key

The shareable half of a key pair, contained in your certificate. Others use it to verify signatures or encrypt data for you.

RAID

A way of combining several disks so the loss of one does not lose data, or so reads and writes are faster. Not a substitute for backup.

Rate limiting

Restricting how many requests one client may make in a period, to protect against abuse and overload.

Redemption period

A stage after the grace period when an expired domain can still be recovered, usually for an extra fee.

Redirect

An instruction telling the browser to go to a different address. A 301 is permanent, a 302 is temporary.

Redis

An in-memory data store used for caching and sessions. Often added to speed up WordPress and other database-driven sites.

Registrant

The person or organisation named as the holder of a domain registration.

Registrar lock

A setting that prevents a domain from being transferred away without first being unlocked. A basic defence against hijacking.

Reseller hosting

A plan that lets you create and manage hosting accounts for your own customers, usually under your own brand.

Response time

How long a server takes to answer a request. Often reported as time to first byte.

Reverse proxy

A server that sits in front of one or more others and passes requests on to them, often adding caching or security.

Rollback

Returning to an earlier working version after a change causes problems.

Root access

Full administrator control of a server. Comes with a VPS or dedicated server, and with all the responsibilities that implies.

Root certificate

The top of a certificate chain, trusted because it ships with your operating system or browser.

Round trip

A message going to a server and a reply coming back. Many connection steps cost one round trip each.

Rsync

A command-line tool that copies only the differences between two sets of files, ideal for migrations and backups.

Sandbox

An isolated environment where code can run without affecting the rest of the system, used for testing and for containing risk.

Session

A server-side record of a visitor's activity, linked to their browser by a cookie.

SFTP

File transfer over SSH. Encrypted, and available on most hosts.

Shared IP

An IP address used by several accounts or sites on one server. Normal on shared hosting.

SLA

Service-level agreement. A written commitment about service, typically uptime, along with what the provider owes you if it falls short.

SMTP

The protocol used to send email between servers. Authenticated SMTP, which needs a login, is the right way for a website to send mail.

SNI

Server Name Indication. Lets a server host many HTTPS sites on one IP address by having the browser say which name it wants during the handshake.

SPF

A DNS record listing the servers allowed to send mail for your domain. It has a limit of ten DNS lookups, which adds up with several email services.

SQL injection

An attack that sneaks database commands into a form or address to read or change data. Prevented by safe coding practices and updates.

SSH

A secure way to log in to a server's command line. Use keys, not passwords, where you can.

SSL and TLS

The protocols that encrypt traffic between browser and server. TLS is the current name; SSL is the older one that stuck in everyday speech.

Staging site

A private copy of a live site used to test changes. Update there first, and only then on the real thing.

Status code

The three-digit number a web server returns with every response, such as 200, 301, 404 or 500.

Subdomain

A name added in front of your domain, such as blog.example.com. Each can point to a different server.

Subdomain takeover

When a DNS record points to a service you no longer use, letting someone else claim that service and serve content under your name.

Swap

Disk space used as overflow when RAM runs out. Heavy use of swap makes a server very slow.

Throttling

Deliberately slowing a connection or process when it uses too much of a resource.

TLD

Top-level domain: the last part of a name, such as .com, .org or .bg.

TLS 1.3

The current version of TLS, faster and simpler than earlier ones, with a one-round-trip handshake and only modern ciphers.

Transient

Temporary data WordPress stores with an expiry, such as cached API results. Expired ones sometimes pile up in the database.

TTL

Time to live. In DNS, how many seconds an answer may be cached. In HTTP caching, a similar idea for files.

Two-factor authentication

Requiring a second proof, such as a code from an app or a hardware key, in addition to a password.

TXT record

A DNS record that holds text. Used for SPF, DKIM, DMARC and for proving you own a domain to a service.

UPS

Uninterruptible power supply. A battery system that keeps equipment running briefly if mains power fails.

Uptime

The percentage of time a service is available. 99.9% allows roughly 8.8 hours of downtime per year.

URL

A full web address, including protocol, host and path, that identifies one resource.

User agent

The text a browser or bot sends to say what it is. Useful in logs, but easy to fake.

Virtual host

A configuration entry that lets one web server serve many different sites, selected by the hostname in the request.

VPN

A service that sends your traffic through an encrypted tunnel to another point, hiding it from the local network.

VPS

Virtual private server. A virtual machine with guaranteed resources and root access.

WAF

Web application firewall. Filters malicious requests such as SQL injection attempts before they reach your application.

White screen of death

A blank page in WordPress, usually caused by a fatal PHP error that is hidden from visitors.

WHOIS and RDAP

Public lookup systems for domain registration details. Much personal data is now redacted by default.

Wildcard certificate

A certificate that covers all first-level subdomains of a domain, such as *.example.com. Convenient, but one compromised key then affects them all.

WordPress

The most widely used CMS. Powers a large fraction of all websites.

XML-RPC

An older WordPress interface for remote publishing. Often disabled because attackers use it to try many passwords at once.

XSS

Cross-site scripting: injecting malicious scripts into pages that other users view. Prevented by sanitising output and by browser security headers.

Zero-day

A vulnerability that is exploited before the developer has had a chance to fix it.

Zone file

The collection of all DNS records for a domain, kept at the DNS provider.