Moving your DNS zone to a new provider and checking it before you switch

Changing nameservers is a switch: the instant the rest of the internet sees it, it starts asking the new provider, and if the zone there is incomplete, whatever is missing stops existing. The golden rule is to build the new zone and check it, by talking directly to the new servers, before you change the nameservers. For the Cloudflare case, the walkthrough is in taking the whole DNS zone to Cloudflare; this article holds for any provider.

Step by step

1 Get the real list. The only complete list is the one at the place where the zone lives today: the cPanel Zone Editor, or the old provider’s panel. If the panel can export the zone as a file, save it. Do not trust outside lookups: a name you do not know about (a forgotten subdomain) does not show up in any query.
2 Lower the TTL on the records that will change, at least a day ahead (changing the DNS of a domain already in use).
3 Build the zone at the new provider, record by record. Type by type, checking against the list from step 1.
4 Check it without switching anything. Ask the new servers directly (commands below) and compare with the old zone.
5 Change the nameservers at the registrar (the map every panel follows).
6 Confirm afterwards: the site opens, e-mail comes in and goes out, certificates renew. See I changed the DNS and nothing shows yet.
7 Do not delete the old zone for a few days. Anyone still holding the old answer in cache keeps being served (how long DNS changes take to propagate).

Checking before you switch, with dig

dig asks a DNS server you choose, instead of the usual one. That way you see the new zone before it is in use. Swap the name for your new server and the domain for yours:for t in A AAAA MX TXT CNAME CAA; do
echo "== $t"
dig @ns1.new.tld yourdomain.tld $t +short
done

Run the same loop pointed at the old server (your current nameserver; dig NS yourdomain.tld +short tells you which) and compare the two outputs. Check the subdomains on your list too, such as www, mail or _dmarc.

Record What to check
A and AAAA The right addresses, and no forgotten AAAA pointing at an old server.
MX The same servers and the same priorities. If it is missing, e-mail stops.
TXT The SPF (only one per domain), the DKIM (a very long string: check the start and the end) and third-party verifications.
CNAME The ones pointing at outside services, like shops, newsletters and bookings.
CAA If any exist, they must still authorise whoever issues your certificates.
NS for subdomains Subdomains delegated to another provider must stay delegated.
Watch out for DNSSEC. If the domain has DNSSEC on, there is a DS record at the registry pointing at the old provider’s keys. If you change nameservers and that DS stays, validating resolvers stop resolving your domain. Remove the DS before you switch and turn DNSSEC on again at the new provider, if you want it.
If you use Interweb’s nameservers you need none of this to move the site elsewhere: just change the A record (changing the DNS of a domain already in use). You only change nameservers when you hand all DNS management to another provider.

Have the old zone and not sure it is complete? Send us the domain and we will help you check.

Open a support ticket

SEE ALSO

How to change the DNS of a domain already in use

Taking the whole DNS zone to Cloudflare without losing records

DNS records explained: A, CNAME, MX, TXT and TTL

Nameservers: what they are and which ones to use with us

RECOMMENDED PRODUCT

Register your .co.mz domain

Secure your company name before someone else registers it. from $62.53/yr

Search a domain
  • 0 Users Found This Useful
Was this answer helpful?