Guide

Safe nameserver migration

A nameserver change affects every service beneath a domain. The safest migration copies first, tests second and switches only after the destination answers correctly.

1. Build a complete inventory

Export or record A, AAAA, CNAME, MX, TXT, CAA and SRV data. Include subdomains, DKIM selectors, verification tokens and less visible operational names. Save TTLs and priorities as well as values.

2. Prepare the destination

Create the zone on both authoritative servers. Confirm that the secondary receives the same serial and record set. Test apex, wildcard, website, mail and verification names directly against each server.

3. Switch delegation

Update nameservers at the registrar only after the destination is complete. Keep the former service online during propagation. Public resolvers may retain prior answers until their cached TTL expires.

4. Verify from the outside

Check delegation, SOA serials and essential records using independent resolvers. Test the website over HTTPS and send mail through each configured provider. Watch for failures before retiring the old infrastructure.

5. Preserve a recovery point

Store a zone export and database backup outside the live service. A useful backup is readable, timestamped and verified—not merely created.

Do not migrate by recreating only the obvious website record. Missing MX, DKIM or verification data can cause failures hours later.

← Back to all guides