Identify the authoritative boundary
Record the registrar, authoritative nameservers, DNS provider, zone contents, DNSSEC state, certificate validation records, and every service depending on the domain. The visible website is only one consumer; email, APIs, verification, and redirects may rely on less obvious records.
Export the existing zone and compare it with the destination using normalized names and record types.
Stage the destination
Create records before delegating nameservers, and obtain certificates using a supported validation method. If moving only an origin, test the new server with a temporary hostname or local resolution override.
Lower TTLs early enough to matter, but keep in mind that nameserver delegation and resolver behavior have separate caching rules.
- Preserve MX, SPF, DKIM, DMARC, CAA, and verification records.
- Avoid a DNSSEC mismatch during delegation.
- Use explicit apex and www behavior.
- Prepare a rollback value and decision time.
Observe from outside
Query multiple public recursive resolvers and authoritative servers, then test HTTP, HTTPS, email, and critical APIs. Provider dashboards can report a healthy configuration while public resolvers still see the previous state.
Keep the old destination serving compatible content through the transition when possible.
Compare authoritative answers with at least two public resolvers, inspect the certificate for both hostnames, and verify web and mail flows before declaring the change complete.