Domains
What should I check before changing domain nameservers?
Short answer
Copy every existing DNS record first, because the new nameservers answer only with the records you create there. Check email, subdomains, verification records and DNSSEC, and lower TTLs ahead of the change.
What changes the answer
- A complete record inventory including MX and TXT
- DNSSEC status at the registrar
- Cached answers that last until TTL expires
The nameservers decide the answers
Nameserver records tell resolvers which servers are authoritative for your domain. When you change them, resolvers start asking a different DNS service. That service replies with the records configured there. Records left behind at the old service stop being used, so a missing record becomes a missing service.
Build a record inventory
Before the change, list every record at the current DNS provider: A and AAAA for addresses, CNAME for aliases, MX for mail, TXT for items such as SPF and site verification, and any others such as SRV or CAA. Compare that list with what is configured at the new provider. Email is the most common casualty, because mail records are easy to forget.
Check DNSSEC
If DNSSEC is enabled for the domain, the registrar holds a DS record that matches keys at the DNS provider. Cloudflare's documentation describes adding a DS record at the registrar when enabling DNSSEC. If you switch providers without handling it, the old DS record can fail to match the new keys and cause validation failures. Disable or migrate DNSSEC deliberately, following the documentation of both providers.
Plan for caching
Resolvers keep earlier answers until their TTL expires, so different networks can see the old and new setup for a time. Lower the TTL on important records ahead of the change, and keep the old DNS service available until you are sure the change has settled.
Verify afterwards
Query the new nameservers directly for each important record, then check from several networks. Send and receive a test email, load each hostname, and confirm the TLS certificate still renews. The troubleshooting checklist can help you organise what you observe.
Keep a rollback path
Write down the original nameserver values before you change them. If email or the website breaks, restoring them sends resolvers back to the previous service, subject to the same caching delay. Avoid making other changes at the same time, so any failure can be traced to the nameserver switch.