{"id":107,"date":"2026-07-17T21:00:00","date_gmt":"2026-07-17T21:00:00","guid":{"rendered":"https:\/\/dnsrecordschecker.com\/blog\/?p=107"},"modified":"2026-07-03T09:38:08","modified_gmt":"2026-07-03T09:38:08","slug":"audit-dns-records-before-migration","status":"publish","type":"post","link":"https:\/\/dnsrecordschecker.com\/blog\/audit-dns-records-before-migration\/","title":{"rendered":"How to Audit DNS Records Before Website Migration"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\"><strong>Quick Answer:<\/strong> Before migrating a website, perform a full DNS Records audit by mapping all active records, reducing your TTL (Time-to-Live) to 300 seconds, and documenting TXT records for email. Verify these records against your authoritative nameserver, not just a recursive cache, to ensure the new server will handle all traffic, subdomains, and mail services correctly upon cutover.<\/p>\n\n\n\n<div id=\"ez-toc-container\" class=\"ez-toc-v2_0_85 ez-toc-wrap-center counter-hierarchy ez-toc-counter ez-toc-grey ez-toc-container-direction\">\n<div class=\"ez-toc-title-container\">\n<p class=\"ez-toc-title\" style=\"cursor:inherit\">Table of Contents<\/p>\n<span class=\"ez-toc-title-toggle\"><a href=\"#\" class=\"ez-toc-pull-right ez-toc-btn ez-toc-btn-xs ez-toc-btn-default ez-toc-toggle\" aria-label=\"Toggle Table of Content\"><span class=\"ez-toc-js-icon-con\"><span class=\"\"><span class=\"eztoc-hide\" style=\"display:none;\">Toggle<\/span><span class=\"ez-toc-icon-toggle-span\"><svg style=\"fill: #000000;color:#000000\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" class=\"list-377408\" width=\"20px\" height=\"20px\" viewBox=\"0 0 24 24\" fill=\"none\"><path d=\"M6 6H4v2h2V6zm14 0H8v2h12V6zM4 11h2v2H4v-2zm16 0H8v2h12v-2zM4 16h2v2H4v-2zm16 0H8v2h12v-2z\" fill=\"currentColor\"><\/path><\/svg><svg style=\"fill: #000000;color:#000000\" class=\"arrow-unsorted-368013\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"10px\" height=\"10px\" viewBox=\"0 0 24 24\" version=\"1.2\" baseProfile=\"tiny\"><path d=\"M18.2 9.3l-6.2-6.3-6.2 6.3c-.2.2-.3.4-.3.7s.1.5.3.7c.2.2.4.3.7.3h11c.3 0 .5-.1.7-.3.2-.2.3-.5.3-.7s-.1-.5-.3-.7zM5.8 14.7l6.2 6.3 6.2-6.3c.2-.2.3-.5.3-.7s-.1-.5-.3-.7c-.2-.2-.4-.3-.7-.3h-11c-.3 0-.5.1-.7.3-.2.2-.3.5-.3.7s.1.5.3.7z\"\/><\/svg><\/span><\/span><\/span><\/a><\/span><\/div>\n<nav><ul class='ez-toc-list ez-toc-list-level-1 ' ><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-1\" href=\"https:\/\/dnsrecordschecker.com\/blog\/audit-dns-records-before-migration\/#Why_a_DNS_Audit_Matters_Before_Migration\" >Why a DNS Audit Matters Before Migration<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-2\" href=\"https:\/\/dnsrecordschecker.com\/blog\/audit-dns-records-before-migration\/#What_Is_a_DNS_Audit\" >What Is a DNS Audit?<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-3\" href=\"https:\/\/dnsrecordschecker.com\/blog\/audit-dns-records-before-migration\/#Comparison_Why_Audit_Manually_vs_Automated_Tools\" >Comparison: Why Audit Manually vs. Automated Tools<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-4\" href=\"https:\/\/dnsrecordschecker.com\/blog\/audit-dns-records-before-migration\/#How_to_Audit_DNS_Records_Before_Website_Migration\" >How to Audit DNS Records Before Website Migration<\/a><ul class='ez-toc-list-level-4' ><li class='ez-toc-heading-level-4'><ul class='ez-toc-list-level-4' ><li class='ez-toc-heading-level-4'><a class=\"ez-toc-link ez-toc-heading-5\" href=\"https:\/\/dnsrecordschecker.com\/blog\/audit-dns-records-before-migration\/#1_Export_Your_Current_Zone_File\" >1. Export Your Current Zone File<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-4'><a class=\"ez-toc-link ez-toc-heading-6\" href=\"https:\/\/dnsrecordschecker.com\/blog\/audit-dns-records-before-migration\/#2_Reduce_the_TTL_Time-to-Live\" >2. Reduce the TTL (Time-to-Live)<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-4'><a class=\"ez-toc-link ez-toc-heading-7\" href=\"https:\/\/dnsrecordschecker.com\/blog\/audit-dns-records-before-migration\/#3_Identify_and_Document_TXT_Records\" >3. Identify and Document TXT Records<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-4'><a class=\"ez-toc-link ez-toc-heading-8\" href=\"https:\/\/dnsrecordschecker.com\/blog\/audit-dns-records-before-migration\/#4_Audit_Subdomains_and_CNAMEs\" >4. Audit Subdomains and CNAMEs<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-4'><a class=\"ez-toc-link ez-toc-heading-9\" href=\"https:\/\/dnsrecordschecker.com\/blog\/audit-dns-records-before-migration\/#5_Verify_MX_Records\" >5. Verify MX Records<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-4'><a class=\"ez-toc-link ez-toc-heading-10\" href=\"https:\/\/dnsrecordschecker.com\/blog\/audit-dns-records-before-migration\/#6_Perform_the_%E2%80%9CAuthoritative_Query%E2%80%9D\" >6. Perform the &#8220;Authoritative Query&#8221;<\/a><\/li><\/ul><\/li><\/ul><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-11\" href=\"https:\/\/dnsrecordschecker.com\/blog\/audit-dns-records-before-migration\/#DNS_Propagation_After_Website_Migration\" >DNS Propagation After Website Migration<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-12\" href=\"https:\/\/dnsrecordschecker.com\/blog\/audit-dns-records-before-migration\/#DNS_Migration_Checklist_by_User_Role\" >DNS Migration Checklist by User Role<\/a><ul class='ez-toc-list-level-4' ><li class='ez-toc-heading-level-4'><ul class='ez-toc-list-level-4' ><li class='ez-toc-heading-level-4'><a class=\"ez-toc-link ez-toc-heading-13\" href=\"https:\/\/dnsrecordschecker.com\/blog\/audit-dns-records-before-migration\/#DNS_Audit_Tips_for_Developers\" >DNS Audit Tips for Developers<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-4'><a class=\"ez-toc-link ez-toc-heading-14\" href=\"https:\/\/dnsrecordschecker.com\/blog\/audit-dns-records-before-migration\/#DNS_Migration_Guide_for_Agency_Teams\" >DNS Migration Guide for Agency Teams<\/a><\/li><\/ul><\/li><\/ul><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-15\" href=\"https:\/\/dnsrecordschecker.com\/blog\/audit-dns-records-before-migration\/#Security_and_Best_Practices\" >Security and Best Practices<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-16\" href=\"https:\/\/dnsrecordschecker.com\/blog\/audit-dns-records-before-migration\/#Troubleshooting_The_%E2%80%9CMigration_Aftermath%E2%80%9D\" >Troubleshooting: The &#8220;Migration Aftermath&#8221;<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-17\" href=\"https:\/\/dnsrecordschecker.com\/blog\/audit-dns-records-before-migration\/#Conclusion_The_Migration_Check-up\" >Conclusion: The Migration Check-up<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-18\" href=\"https:\/\/dnsrecordschecker.com\/blog\/audit-dns-records-before-migration\/#Frequently_Asked_Questions\" >Frequently Asked Questions<\/a><ul class='ez-toc-list-level-3' ><li class='ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-19\" href=\"https:\/\/dnsrecordschecker.com\/blog\/audit-dns-records-before-migration\/#Does_a_DNS_audit_affect_my_websites_uptime\" >Does a DNS audit affect my website&#8217;s uptime?<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-20\" href=\"https:\/\/dnsrecordschecker.com\/blog\/audit-dns-records-before-migration\/#How_do_I_check_if_my_DNS_records_are_%E2%80%9Ccorrect%E2%80%9D\" >How do I check if my DNS records are &#8220;correct&#8221;?<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-21\" href=\"https:\/\/dnsrecordschecker.com\/blog\/audit-dns-records-before-migration\/#Should_I_change_my_DNS_provider_during_a_migration\" >Should I change my DNS provider during a migration?<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-22\" href=\"https:\/\/dnsrecordschecker.com\/blog\/audit-dns-records-before-migration\/#Is_it_safe_to_share_my_zone_file_with_the_new_host\" >Is it safe to share my zone file with the new host?<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-23\" href=\"https:\/\/dnsrecordschecker.com\/blog\/audit-dns-records-before-migration\/#What_is_the_most_common_DNS_record_people_forget\" >What is the most common DNS record people forget?<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-24\" href=\"https:\/\/dnsrecordschecker.com\/blog\/audit-dns-records-before-migration\/#Can_I_use_a_tool_to_audit_automatically\" >Can I use a tool to audit automatically?<\/a><\/li><\/ul><\/li><\/ul><\/nav><\/div>\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Why_a_DNS_Audit_Matters_Before_Migration\"><\/span>Why a DNS Audit Matters Before Migration<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">You have finished working on the website. The database is now synced, the files are in place, and the new server is ready to go. You update your DNS A record to point to the new server&#8217;s IP address. Then you wait to see what happens. An hour later, your inbox is full of tickets from users who are having problems. Your website is loading correctly for you. Your email is bouncing back, and some users are still seeing the old version of the website.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Most of the time, when you move a website, it does not go wrong because of code. It goes wrong because you do not really understand what your website does. A website is not a simple address that points to a web server. It is a collection of pointers for email, verification services, subdomains, and security protocols.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If you just update the IP address and think that&#8217;s it, you might cause problems you don&#8217;t even notice at first. These problems can cause a lot of trouble for your users. The only way to ensure everything goes smoothly is to <a href=\"https:\/\/dnsrecordschecker.com\/blog\/audit-dns-records-before-migration\/\">check your DNS before switching to the server<\/a>. This way, your users will not even notice that you moved the website to the server.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"What_Is_a_DNS_Audit\"><\/span>What Is a DNS Audit?<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">A DNS audit is the process of reviewing and documenting every existing record in your domain\u2019s zone file to ensure compatibility with your new hosting environment. Unlike a standard lookup, an audit requires you to compare your <em>authoritative<\/em> configuration with the raw data stored on your nameserver against the live environment to identify records that must be migrated, updated, or decommissioned.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Comparison_Why_Audit_Manually_vs_Automated_Tools\"><\/span>Comparison: Why Audit Manually vs. Automated Tools<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><tbody><tr><td><strong>Audit Method<\/strong><\/td><td><strong>Visibility<\/strong><\/td><td><strong>Best Use Case<\/strong><\/td><td><strong>Risk Level<\/strong><\/td><\/tr><tr><td><strong>Manual (CLI\/<\/strong><strong>dig<\/strong><strong>)<\/strong><\/td><td>Total (Raw Data)<\/td><td>Validating specific record accuracy<\/td><td>Low (Human error)<\/td><\/tr><tr><td><strong>Online Checkers<\/strong><\/td><td>Visual\/Aggregated<\/td><td>Quick verification of record existence<\/td><td>Medium (Cache issues)<\/td><\/tr><tr><td><strong>Automated Scripts<\/strong><\/td><td>High (Scale)<\/td><td>Large-scale inventory of multiple domains<\/td><td>Low (If well-written)<\/td><\/tr><tr><td><strong>Recommended for<\/strong><\/td><td>Systems Administrators<\/td><td>Site Owners<\/td><td>Managed Service Providers<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\"><strong><em>Worth knowing: <\/em><\/strong><em>Automated tools do not always handle TXT record syntax well. They often struggle with SPF strings or old DKIM keys. If you only use a web-based dashboard, you might miss the records that keep your emails delivered. These records are important for your email deliverability. TXT records and SPF strings are key to email deliverability.<\/em><\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"How_to_Audit_DNS_Records_Before_Website_Migration\"><\/span>How to Audit DNS Records Before Website Migration<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Do not touch your <a href=\"https:\/\/dnsrecordschecker.com\/\">DNS records checker<\/a> until you have completed this checklist. The goal is to create a &#8220;map&#8221; of your current state so you can reconstruct it on the new server.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"1_Export_Your_Current_Zone_File\"><\/span><strong>1. Export Your Current Zone File<\/strong><span class=\"ez-toc-section-end\"><\/span><\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">Most registrars let you save your zone file as a text file or a BIND file. You should do this now. This file is, like your record. If something goes wrong while you are moving things, you will need a copy of how they looked so you can change them back.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"2_Reduce_the_TTL_Time-to-Live\"><\/span><strong>2. Reduce the TTL (Time-to-Live)<\/strong><span class=\"ez-toc-section-end\"><\/span><\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">This is a technical step. Many records are set to 24 hours by default. This means the internet checks for updates once a day. If you change your IP address and something goes wrong, people will still see the incorrect information for a whole day. To prevent this, set your time-to-live to 300 or 5 minutes a day before you start moving things around. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">That way, if something does go wrong, it will only be a short time before it gets fixed, and people can see the correct information. You want to update your records and have the internet check for changes often, so set your TTLs low and give it some time to take effect. This way, you can avoid seeing your broken record for a long time.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"3_Identify_and_Document_TXT_Records\"><\/span><strong>3. Identify and Document TXT Records<\/strong><span class=\"ez-toc-section-end\"><\/span><\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">Web developers pay attention to A records. The people who handle the infrastructure focus on TXT records. These records include your Sender Policy Framework (SPF), your <a href=\"https:\/\/en.wikipedia.org\/wiki\/DomainKeys_Identified_Mail\" rel=\"nofollow noopener\" target=\"_blank\">DomainKeys Identified Mail<\/a> (DKIM), and your DMARC records. If you move your website to a new server and do not update these records, the mail you send out will be rejected or marked as spam right away. You should write down the words in your records.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"4_Audit_Subdomains_and_CNAMEs\"><\/span><strong>4. Audit Subdomains and CNAMEs<\/strong><span class=\"ez-toc-section-end\"><\/span><\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">Do you have a test environment on dev.example.com? We need to check subdomains like api.example.com and blog.example.com. Let&#8217;s review all subdomains of example.com because some might be on servers. A common mistake is moving the website. Forgetting about the blog subdomain. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The blog subdomain often has a setup. When example. Coms DNS is updated the blog subdomain stops working. So we should audit every subdomain on example.com. We should carefully check all subdomains of example.com.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"5_Verify_MX_Records\"><\/span><strong>5. Verify MX Records<\/strong><span class=\"ez-toc-section-end\"><\/span><\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">Your Mail Exchanger records decide where your email is sent. If your new host provides email services, you will probably need to update your Mail Exchanger records. If you are using a service such as Google Workspace or Microsoft 365, do not change your Mail Exchanger records. Make sure your Mail Exchanger records are pointing to the mail host. Also, make sure your Mail Exchanger records are not accidentally changed when you move to the host.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"6_Perform_the_%E2%80%9CAuthoritative_Query%E2%80%9D\"><\/span><strong>6. Perform the &#8220;Authoritative Query&#8221;<\/strong><span class=\"ez-toc-section-end\"><\/span><\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">Use dig to query your nameservers directly.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Bash# Example command to check your authoritative nameservers: dig @ns1.yourprovider.com example.com ANY.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This output is your source of truth. If the record isn&#8217;t in this list, it isn&#8217;t &#8220;live&#8221; on your authoritative server. Compare this output against the list of records you intend to migrate.<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"536\" src=\"https:\/\/dnsrecordschecker.com\/blog\/wp-content\/uploads\/2026\/07\/DNS-Propagation-After-Website-Migration-1024x536.png\" alt=\"DNS Propagation After Website Migration\" class=\"wp-image-226\" srcset=\"https:\/\/dnsrecordschecker.com\/blog\/wp-content\/uploads\/2026\/07\/DNS-Propagation-After-Website-Migration-1024x536.png 1024w, https:\/\/dnsrecordschecker.com\/blog\/wp-content\/uploads\/2026\/07\/DNS-Propagation-After-Website-Migration-300x157.png 300w, https:\/\/dnsrecordschecker.com\/blog\/wp-content\/uploads\/2026\/07\/DNS-Propagation-After-Website-Migration-768x402.png 768w, https:\/\/dnsrecordschecker.com\/blog\/wp-content\/uploads\/2026\/07\/DNS-Propagation-After-Website-Migration.png 1200w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"DNS_Propagation_After_Website_Migration\"><\/span>DNS Propagation After Website Migration<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Migration timelines are rarely &#8220;instant.&#8221; By default, DNS changes follow the TTL you have set.<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>TTL 300 (5 mins):<\/strong> 90% of global resolvers will update within 15 minutes.<\/li>\n\n\n\n<li><strong>TTL 3600 (1 hour):<\/strong> 90% of global resolvers will update within 2 hours.<\/li>\n\n\n\n<li><strong>TTL 86400 (24 hours):<\/strong> 90% of global resolvers will take up to 48 hours to fully clear.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\"><em>Source: Analysis of recursive resolver behavior suggests that while most nodes honor the TTL, some &#8220;stubborn&#8221; ISP resolvers ignore TTLs shorter than one hour. Always buffer your migration planning by at least 24 hours.<\/em><\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"DNS_Migration_Checklist_by_User_Role\"><\/span>DNS Migration Checklist by User Role<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Your role in the migration dictates how you approach the DNS audit.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"DNS_Audit_Tips_for_Developers\"><\/span>DNS Audit Tips for Developers<span class=\"ez-toc-section-end\"><\/span><\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">You should treat the DNS zone file like code. Commit the zone file (or a CSV of the records) to your repository. This allows you to diff your &#8220;before&#8221; and &#8220;after&#8221; states. You care about the precision of the record types and the specific IP addresses.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"DNS_Migration_Guide_for_Agency_Teams\"><\/span>DNS Migration Guide for Agency Teams<span class=\"ez-toc-section-end\"><\/span><\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">Your focus is on the client&#8217;s business continuity. Your audit must prioritize &#8220;uptime-critical&#8221; records: the A record for the main site, the MX records for their email, and the TXT records for their verification services. Missing a sub-domain verification can break a client&#8217;s third-party login system or marketing pixel.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Security_and_Best_Practices\"><\/span>Security and Best Practices<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">An audit is a perfect time to clean up technical debt and secure your domain.<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong>Remove Stale Records:<\/strong> Look for entries pointing to servers you no longer own. If you find a CNAME pointing to an expired service, delete it. This prevents &#8220;subdomain takeover,&#8221; where an attacker claims the expired service and hijacks your subdomain.<\/li>\n\n\n\n<li><strong>Enable DNSSEC:<\/strong> If your current registrar supports it, enable DNSSEC (Domain Name System Security Extensions). This adds a layer of authentication, ensuring that your DNS records are not being intercepted or modified in transit.<\/li>\n\n\n\n<li><strong>Audit API Keys:<\/strong> If you have verification records (like google-site-verification), check if they are still required. Keeping old verification records adds unnecessary noise to your zone file.<\/li>\n\n\n\n<li><strong>Lock the Registrar:<\/strong> Ensure your domain is locked at the registrar level. During the chaos of a migration, accidentally initiating a transfer is a nightmare scenario you want to avoid.<\/li>\n<\/ol>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Troubleshooting_The_%E2%80%9CMigration_Aftermath%E2%80%9D\"><\/span>Troubleshooting: The &#8220;Migration Aftermath&#8221;<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Even with a perfect audit, issues arise. Here is how to diagnose them quickly.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Problem: Email stopped working immediately after the DNS change.<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Cause:<\/strong> You likely changed your MX records or deleted the SPF\/DKIM TXT records during the switch.<\/li>\n\n\n\n<li><strong>Fix:<\/strong> Use a tool to query your <em>new<\/em> authoritative nameserver for MX and TXT records. If they are missing, manually recreate them.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Problem: The site is &#8220;down&#8221; for some users, but up for you.<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Cause:<\/strong> You did not lower your TTL before the migration. Users are hitting their local ISPs&#8217; caches for your old IP address.<\/li>\n\n\n\n<li><strong>Fix:<\/strong> Wait for the TTL to expire. There is no technical way to &#8220;flush&#8221; the internet&#8217;s cache. Tell your clients to use a public DNS (like 8.8.8.8) if they need immediate access.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Problem: Subdomains are resulting in a 404.<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Cause:<\/strong> You migrated the root domain but forgot to update the CNAME or A records for the subdomains to point to the new server&#8217;s IP address.<\/li>\n\n\n\n<li><strong>Fix:<\/strong> Check your zone file export. Ensure all CNAME\/A records for your subdomains were included in the new configuration.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Problem: The &#8220;Site Not Found&#8221; error appears on every page.<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Cause:<\/strong> Syntax error in the zone file. A missing period at the end of a CNAME or a typo in an IP address.<\/li>\n\n\n\n<li><strong>Fix:<\/strong> Revert to the exported zone file you saved in Step 1.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Problem: Third-party services (Maps, Analytics) are broken.<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Cause:<\/strong> You missed verification records. Many services verify ownership via a TXT or CNAME record.<\/li>\n\n\n\n<li><strong>Fix:<\/strong> Audit the &#8220;Site Settings&#8221; of your third-party tools. Find the required verification record and add it back to your DNS settings.<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Conclusion_The_Migration_Check-up\"><\/span>Conclusion: The Migration Check-up<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Your DNS audit is, as the saying goes, &#8220;measure cut once&#8221; in website management. It is a step. If you export, document, and verify your DNS records, then moving to a system is easy. It becomes a simple switch that your users do not even notice. The DNS audit helps ensure a transition. You take the time to review and confirm your records. This way, the migration process goes smoothly.<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong>Export everything<\/strong> before touching a single setting.<\/li>\n\n\n\n<li><strong>Lower your TTLs<\/strong> well in advance to give yourself a safety net.<\/li>\n\n\n\n<li><strong>Audit the &#8220;invisible&#8221; records<\/strong> like TXT and CNAMEs, not just your A records.<\/li>\n<\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">That said, here is the honest caveat: no matter how perfect your audit is, the DNS propagation delay is a law of the internet. Even if you do everything right, some users on slow-to-refresh ISP caches will still see the old site for a few hours. Communicate this clearly to your stakeholders: the migration is successful, but the internet&#8217;s &#8220;phone book&#8221; needs time to catch up. Use a tool like dnsrecordschecker.com to monitor the propagation, and stay patient.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Frequently_Asked_Questions\"><\/span>Frequently Asked Questions<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n<div id=\"rank-math-faq\" class=\"rank-math-block\">\n<div class=\"rank-math-list \">\n<div id=\"faq-question-1781866830535\" class=\"rank-math-list-item\">\n<h3 class=\"rank-math-question \"><span class=\"ez-toc-section\" id=\"Does_a_DNS_audit_affect_my_websites_uptime\"><\/span><strong>Does a DNS audit affect my website&#8217;s uptime?<\/strong><span class=\"ez-toc-section-end\"><\/span><\/h3>\n<div class=\"rank-math-answer \">\n\n<p>No. Performing an audit, essentially reading your existing records and documenting them, has no impact on your site&#8217;s uptime. It is a passive activity.<\/p>\n\n<\/div>\n<\/div>\n<div id=\"faq-question-1781866854846\" class=\"rank-math-list-item\">\n<h3 class=\"rank-math-question \"><span class=\"ez-toc-section\" id=\"How_do_I_check_if_my_DNS_records_are_%E2%80%9Ccorrect%E2%80%9D\"><\/span><strong>How do I check if my DNS records are &#8220;correct&#8221;?<\/strong><span class=\"ez-toc-section-end\"><\/span><\/h3>\n<div class=\"rank-math-answer \">\n\n<p>Correctness is contextual. A record is &#8220;correct&#8221; if it points to the destination you intend. Use a DNS Records Checker to compare your current live records against the IP addresses provided by your new hosting provider. If they match, the records are configured as you requested.<\/p>\n\n<\/div>\n<\/div>\n<div id=\"faq-question-1781866855679\" class=\"rank-math-list-item\">\n<h3 class=\"rank-math-question \"><span class=\"ez-toc-section\" id=\"Should_I_change_my_DNS_provider_during_a_migration\"><\/span><strong>Should I change my DNS provider during a migration?<\/strong><span class=\"ez-toc-section-end\"><\/span><\/h3>\n<div class=\"rank-math-answer \">\n\n<p>Try to avoid it. If you are changing hosts, keep your DNS provider the same. If you need to change your DNS provider, do it at least a week before the website migration. Never change the hosting provider and the DNS nameservers at the same time; it makes it impossible to isolate the cause if something breaks.<\/p>\n\n<\/div>\n<\/div>\n<div id=\"faq-question-1781866856844\" class=\"rank-math-list-item\">\n<h3 class=\"rank-math-question \"><span class=\"ez-toc-section\" id=\"Is_it_safe_to_share_my_zone_file_with_the_new_host\"><\/span><strong>Is it safe to share my zone file with the new host?<\/strong><span class=\"ez-toc-section-end\"><\/span><\/h3>\n<div class=\"rank-math-answer \">\n\n<p>Yes, but share it only with trusted technical support. Your zone file contains the structure of your infrastructure, which can be useful information for attackers, but it does not contain sensitive login credentials or passwords.<\/p>\n\n<\/div>\n<\/div>\n<div id=\"faq-question-1781866857979\" class=\"rank-math-list-item\">\n<h3 class=\"rank-math-question \"><span class=\"ez-toc-section\" id=\"What_is_the_most_common_DNS_record_people_forget\"><\/span><strong>What is the most common DNS record people forget?<\/strong><span class=\"ez-toc-section-end\"><\/span><\/h3>\n<div class=\"rank-math-answer \">\n\n<p>TXT records. Because they aren&#8217;t &#8220;visible&#8221; like an A record (which loads a website) or an MX record (which handles mail), people often ignore them. This breaks email deliverability and site verification services instantly.<\/p>\n\n<\/div>\n<\/div>\n<div id=\"faq-question-1781866860908\" class=\"rank-math-list-item\">\n<h3 class=\"rank-math-question \"><span class=\"ez-toc-section\" id=\"Can_I_use_a_tool_to_audit_automatically\"><\/span><strong>Can I use a tool to audit automatically?<\/strong><span class=\"ez-toc-section-end\"><\/span><\/h3>\n<div class=\"rank-math-answer \">\n\n<p>Yes, you can use CLI tools to pull your records, but the &#8220;audit&#8221; itself, the decision to keep or delete a record, requires human judgment. A tool can show you a list; you have to decide if that list is still valid.<\/p>\n\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\"><strong>Latest post:<\/strong><\/p>\n\n\n<ul class=\"wp-block-latest-posts__list wp-block-latest-posts\"><li><a class=\"wp-block-latest-posts__post-title\" href=\"https:\/\/dnsrecordschecker.com\/blog\/dns-lookup-vs-dns-propagation-checker\/\">DNS Lookup vs DNS Propagation Checker (When to Use Each)<\/a><\/li>\n<li><a class=\"wp-block-latest-posts__post-title\" href=\"https:\/\/dnsrecordschecker.com\/blog\/audit-dns-records-before-migration\/\">How to Audit DNS Records Before Website Migration<\/a><\/li>\n<li><a class=\"wp-block-latest-posts__post-title\" href=\"https:\/\/dnsrecordschecker.com\/blog\/what-makes-a-dns-checker-accurate\/\">What Makes a DNS Checker Accurate? (Behind the Tool)<\/a><\/li>\n<li><a class=\"wp-block-latest-posts__post-title\" href=\"https:\/\/dnsrecordschecker.com\/blog\/verify-dns-changes-before-going-live\/\">How to Verify DNS Changes Before Going Live<\/a><\/li>\n<li><a class=\"wp-block-latest-posts__post-title\" href=\"https:\/\/dnsrecordschecker.com\/blog\/dns-health-check-for-your-domain\/\">DNS Health Check: What to Analyze in Your Domain<\/a><\/li>\n<\/ul>","protected":false},"excerpt":{"rendered":"<p>Quick Answer: Before migrating a website, perform a full DNS Records audit by mapping all active records, reducing your TTL (Time-to-Live) to 300 seconds, and documenting TXT records for email. Verify these records against your authoritative nameserver, not just a recursive cache, to ensure the new server will handle all traffic, subdomains, and mail services [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":227,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"pagelayer_contact_templates":[],"_pagelayer_content":"","footnotes":""},"categories":[8],"tags":[],"class_list":["post-107","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-dns-tools-checkers"],"_links":{"self":[{"href":"https:\/\/dnsrecordschecker.com\/blog\/wp-json\/wp\/v2\/posts\/107","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/dnsrecordschecker.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/dnsrecordschecker.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/dnsrecordschecker.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/dnsrecordschecker.com\/blog\/wp-json\/wp\/v2\/comments?post=107"}],"version-history":[{"count":5,"href":"https:\/\/dnsrecordschecker.com\/blog\/wp-json\/wp\/v2\/posts\/107\/revisions"}],"predecessor-version":[{"id":228,"href":"https:\/\/dnsrecordschecker.com\/blog\/wp-json\/wp\/v2\/posts\/107\/revisions\/228"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/dnsrecordschecker.com\/blog\/wp-json\/wp\/v2\/media\/227"}],"wp:attachment":[{"href":"https:\/\/dnsrecordschecker.com\/blog\/wp-json\/wp\/v2\/media?parent=107"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/dnsrecordschecker.com\/blog\/wp-json\/wp\/v2\/categories?post=107"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/dnsrecordschecker.com\/blog\/wp-json\/wp\/v2\/tags?post=107"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}