2026-07-15 Revision: 3.0
This document describes the sandbox environment offered by Punktum dk, the registry for the .dk country code top-level domain (ccTLD).
The sandbox environment allows registrars to develop and test their integrations with the .dk registry services in isolation from production. Typical use cases include testing EPP client implementations, onboarding of new registrars, and testing of domain registration, name server administration, and poll message handling.
New service releases may be deployed to the sandbox environment prior to being released to production. This allows registrars to test their integrations against upcoming changes before they take effect in production.
The document is intended for a technical audience at registrars integrating with the Punktum dk services.
This specification describes the Punktum dk sandbox environment.
Changes to this document and to the sandbox environment are listed in the Document History below.
This document is owned and maintained by Punktum dk A/S and must not be distributed without this information.
This document is copyright by Punktum dk A/S and is licensed under the MIT License, please see the separate LICENSE file for details.
3.0 2026-07-15
- Complete rewrite of the document, restructured around the individual sandbox services and their capabilities
- Removed the DSU service, which has been discontinued
- Added the RESTful WHOIS service
- Restructured sandbox limitations: limitations are now documented per service, each with a recommended workaround where available
- Removed limitations related to registrant management scenarios (self-service portal, order confirmation, privilege grants, role acceptance flows, and passwords), which are no longer applicable following the transition to registrar management on 1 July 2026
- Added limitation on creation of registrant managed domains
- Added the General section describing access, data persistence, service releases, and support
- Updated test data: dk-hostmaster.dk replaced by punktum.dk
- Updated all references to point to the current Punktum dk repositories on GitHub
2.9 2021-09-08
- Added new sections to the chapter on sandbox limitations on:
- [DNS]
- [Email]
- [Passwords]
2.8 2021-09-02
- Added information on WHOIS service
2.7 2021-08-23
- Updated information on simulation of 3rd. party interaction for [ID-control]
2.6 2021-05-26
- Added more information on the limitations on [ID-control]
2.5 2021-05-14
- Added two more limitations to the section on sandbox limitations
- [ID-control]
- [Role Acceptance For Role Invitations]
2.4 2021-05-13
- Added mention of tech-announce and linked to page in mailing list for subscription details
2.3 2021-05-07
- Added new section on sandbox limitations
2.2 2019-07-30
- Added more test data
- Improved description on test data
2.1 2019-07-30
- Added section on test data
2.0 2018-11-29
- DSU Service added to consolidated sandbox environment
1.0 2018-11-28
- Initial revision
Punktum dk is the registry for the Danish country-code top-level domain (.dk) and maintains the central DNS registry.
Punktum dk offers a number of services for interacting with the registry, such as EPP, DAS, WHOIS, and RESTful WHOIS. These services are described in separate specifications.
The sandbox environment described in this document makes these services available for test purposes.
The sandbox environment offers the Punktum dk services relevant for registrar integration: EPP, DAS, WHOIS, RESTful WHOIS, and the registrar portal (RP). The individual services and how to access them in the sandbox are described below.
The sandbox environment is isolated from production. Operations carried out in the sandbox, such as domain registrations and name server changes, have no effect on production data, making the environment safe for development, testing, and experimentation.
The sandbox environment does not support all features of the production environment. Known limitations and recommended workarounds are described per service in the Sandbox Environment chapter
Access to the sandbox services requires IP whitelisting, with the exception of the WHOIS service, which is publicly available. In addition, the EPP, DAS, and RP services require a sandbox user.
| Service | IP whitelisting | Sandbox user |
|---|---|---|
| EPP | Required | Required |
| RP | Required | Required |
| DAS | Not required | Required |
| WHOIS | Not required | Not required |
| RESTful WHOIS | Required | Not required |
Sandbox access is set up as follows:
- New registrars automatically have a sandbox user created for the RP as part of the onboarding process.
- Existing registrars without sandbox access can request a sandbox user by contacting Punktum dk at registrar@punktum.dk or via the registrar contact form. Sandbox users for the RP can only be created by Punktum dk.
- IP whitelisting for the sandbox services is managed by the registrar via the production RP.
- Service API users for the EPP and DAS sandbox services can be created by the registrar in the sandbox RP, once access to the sandbox RP has been established.
Data created in the sandbox environment is persistent and is not reset. The sandbox services share the same data set, so a domain registered via EPP or RP is reflected across all sandbox services and can, for example, be queried via DAS or looked up via WHOIS.
New XSD versions for the EPP service are deployed to the sandbox environment three months prior to release to production. This allows registrars to test and adapt their integrations before changes take effect in production. Other changes and releases may be deployed to the sandbox environment with shorter notice.
Releases are announced in the Document History of this document, on the Punktum dk status page, and via the Punktum dk registrar newsletter. To subscribe to the newsletter, please contact Punktum dk at registrar@punktum.dk.
The service versions currently deployed to the sandbox environment are listed in the sandbox environment wiki.
The sandbox environment is operated as a production-grade service. Do note, however, that resolution of errors in the sandbox environment may take longer than for errors in production.
For questions or issues regarding the sandbox environment, please contact Punktum dk at registrar@punktum.dk or use the registrar contact form.
The EPP (Extensible Provisioning Protocol) service is the primary integration point for registrars and supports provisioning and management of domains, contacts, and host objects. The service is described in the Punktum dk EPP Service Specification.
| Parameter | Value |
|---|---|
| Hostname | epp-sandbox.dk-hostmaster.dk |
| Port | 700 |
Access to the EPP sandbox service requires IP whitelisting and an EPP sandbox user, please see General for details. The EPP sandbox user is created by the registrar in the sandbox RP.
For further details on integrating with the EPP service, including transport and connection requirements, please refer to the Punktum dk EPP Service Specification.
The EPP sandbox service is suited for testing your EPP client implementation and most registrar workflows, including:
- Domain registration, including the complete application flow. Domain applications submitted in the sandbox are processed by a real back-end service, so status changes and poll messages occur as they would in production.
- Domain lifecycle management, such as renewal, deletion, and restore.
- Domain transfers between registrars.
- Contact management, such as creating and updating contact objects.
- Name server administration, such as creating and updating host objects.
- DNSSEC management, such as adding and updating DS records for a domain.
- Poll message handling, including retrieval and acknowledgement of poll messages.
For details on the individual EPP commands and their syntax, please refer to the Punktum dk EPP Service Specification.
Please note that the business rules of the production environment also apply in the sandbox environment. The limitations listed below are specific to the sandbox environment.
- ID-control cannot be completed: ID-control of registrants cannot be
completed in the sandbox environment. You can test that an ID-control
is initiated for a contact with a Danish address — the domain will not
be activated, as the system awaits the ID-control — but the ID-control
itself cannot be carried out. Note that as a sandbox-specific rule,
contacts with a non-Danish address are exempt from ID-control.
Workaround: Use contacts with a non-Danish address for testing
domain registration, or indicate that you, as the registrar, have
verified the registrant, using the
dkhm:contact_verificationextension. - Name servers cannot be changed on a domain: When changing the name servers of a domain, the system validates that the name servers answer authoritatively for the domain. As sandbox domains do not exist in the public DNS, this validation will fail, and the name server change will be rejected. Note that this only applies to changing the name servers of an existing domain; creating host objects and registering domains on name servers registered in the sandbox both work.
- No emails are sent: The sandbox environment does not send emails, neither to registrants nor to registrars. Workflows that depend on email, such as email-based acceptance flows, can therefore not be tested end-to-end. Workaround: Contact Punktum dk at registrar@punktum.dk to receive examples of the emails sent in a given workflow.
- Domain transfers require a counterpart: Testing transfers requires a second registrar account as the receiving or losing party. Workaround: Coordinate transfer testing with Punktum dk by contacting registrar@punktum.dk, or test in cooperation with another registrar.
You create your own test data, such as domains, contacts, and host objects, as part of testing in the sandbox environment. One exception is registrant managed domains, which cannot be created following the transition to registrar management on 1 July 2026. If you need to test workflows involving registrant managed domains, please contact Punktum dk at registrar@punktum.dk to have registrant managed test data made available.
The same applies if you need test domains in states that are difficult to produce yourself, such as expired or suspended domains. Contact Punktum dk at registrar@punktum.dk, and we will help set up the relevant test data.
The RP (registrar portal) is a web-based portal for registrars, offering management of domains and related objects, as well as administration of the registrar account. The RP operates on the same registry data as the EPP service, so domains and other objects can be managed interchangeably through either service. The service is described in the Punktum dk RP Service Specification.
| Parameter | Value |
|---|---|
| URL | https://rp-sandbox.dk-hostmaster.dk/ |
Access to the RP sandbox service requires IP whitelisting and an RP sandbox user, please see General for details. RP sandbox users can only be created by Punktum dk and are created automatically as part of the onboarding of new registrars.
If you do not have access to the RP sandbox, please contact Punktum dk at registrar@punktum.dk or via the registrar contact form.
The RP sandbox service is suited for testing and exploring most registrar workflows through the portal, including:
- Domain registration, including the complete application flow. Domain applications submitted in the sandbox are processed by a real back-end service, so status changes occur as they would in production.
- Domain lifecycle management, such as renewal, deletion, and restore.
- Domain transfers between registrars.
- Contact management, such as creating and updating contacts.
- Name server administration, such as creating and updating name servers.
- DNSSEC management, such as adding and updating DS records for a domain.
- User administration, such as creating additional RP users and Service API users for the EPP and DAS sandbox services.
Please note that the business rules of the production environment also apply in the sandbox environment. The limitations listed below are specific to the sandbox environment.
- ID-control cannot be completed: ID-control of registrants cannot be completed in the sandbox environment. You can test that an ID-control is initiated for a contact with a Danish address — the domain will not be activated, as the system awaits the ID-control — but the ID-control itself cannot be carried out. Note that as a sandbox-specific rule, contacts with a non-Danish address are exempt from ID-control. Workaround: Use contacts with a non-Danish address for testing domain registration, or indicate in the domain creation flow that you, as the registrar, have verified the registrant.
- Name servers cannot be changed on a domain: When changing the name servers of a domain, the system validates that the name servers answer authoritatively for the domain. As sandbox domains do not exist in the public DNS, this validation will fail, and the name server change will be rejected. Note that this only applies to changing the name servers of an existing domain; creating name servers and registering domains on name servers registered in the sandbox both work.
- No emails are sent: The sandbox environment does not send emails, neither to registrants nor to registrars. Workflows that depend on email, such as email-based acceptance flows, can therefore not be tested end-to-end. Workaround: Contact Punktum dk at registrar@punktum.dk to receive examples of the emails sent in a given workflow.
- Domain transfers require a counterpart: Testing transfers requires a second registrar account as the receiving or losing party. Workaround: Coordinate transfer testing with Punktum dk by contacting registrar@punktum.dk, or test in cooperation with another registrar.
The DAS (Domain Availability Service) is an HTTP-based service offering lookup of the availability of a given domain name. The service is described in the Punktum dk DAS Service Specification.
| Parameter | Value |
|---|---|
| URL | https://das-sandbox.dk-hostmaster.dk/ |
Access to the DAS sandbox service requires a Service API user created in the sandbox RP, please see General for details.
The DAS sandbox service can be used for testing your DAS client implementation, including availability lookups for both available and registered domain names. The service reflects all domains registered in the sandbox environment, including domains you have registered yourself via EPP or RP.
The following test domains are registered in the sandbox environment and can be used for lookups of registered domain names:
- punktum.dk
- eksempel.dk
- æøåöäüé.dk
The WHOIS service offers lookup of information on domain names, such as registration status, name servers, and registrant and registrar information. The service is described in the Punktum dk WHOIS Service Specification.
| Parameter | Value |
|---|---|
| Hostname | whois-sandbox.dk-hostmaster.dk |
| Port | 43 |
The WHOIS sandbox service is publicly available and requires neither IP whitelisting nor a sandbox user.
The WHOIS sandbox service can be used for testing your WHOIS client implementation and for looking up domains registered in the sandbox environment, including domains you have registered yourself via EPP or RP.
The following test domains are registered in the sandbox environment and can be used for lookups:
- punktum.dk
- eksempel.dk
- æøåöäüé.dk
The RESTful WHOIS service is an HTTP-based alternative to the WHOIS service, optimized for structured querying and machine-readable responses. It offers lookup of information on domain names, name servers, and registrars. The service is described in the Punktum dk RESTful WHOIS Service Specification.
| Parameter | Value |
|---|---|
| URL | https://whois-api-sandbox.dk-hostmaster.dk/ |
Access to the RESTful WHOIS sandbox service requires IP whitelisting, please see General for details.
The RESTful WHOIS sandbox service can be used for testing your client implementation and for looking up domains registered in the sandbox environment, including domains you have registered yourself via EPP or RP.
The following test domains are registered in the sandbox environment and can be used for lookups:
- punktum.dk
- eksempel.dk
- æøåöäüé.dk
