The Baddie Stack π πΎπ±β¨οΈ
thebaddiestack.tech/dns-checklist
The DNS Migration Checklist
Moving your domain's DNS is the least photogenic process in tech β no before-and-after, no visible progress, just four dashboards that don't know each other exist. Here's the order, so it reads as calm instead of chaos.
DNS migration has main character energy for about ten minutes, and then it's just paperwork β a lot of small, quiet actions spread across four dashboards that don't talk to each other, in an order nobody wrote down for you. Think of it like a skincare routine: the products were never the hard part, the order was. Apply things out of sequence and nothing absorbs right. This checklist comes straight out of a real migration β a domain moved off Squarespace, onto DigitalOcean for DNS, wired up to Netlify for hosting and Proton Mail for email, with the site and the inbox both staying live through the whole thing. Swap in your own registrar, host, and mail provider. The sequence still holds.
1 Before you touch anything
Five minutes here is the difference between a clean switch and a support ticket β the prep step everyone wants to skip and nobody should.
- Screenshot or export your domain's current DNS records at your existing registrar. This is your rollback plan, not a formality.
- Note which records are actually doing something β mail, a subdomain, a verification code β versus leftover defaults nobody set on purpose.
- Confirm you have login access to every dashboard involved before you start: new host, site host, email provider. Getting locked out mid-migration is the one plot twist nobody's asking for.
2 Point your domain at your new DNS host
This is the flag-plant. Everything after this is just waiting for the rest of the internet to get the memo.
- At your new DNS host, add your domain and let it generate its own nameservers β DigitalOcean, for example, hands you three:
ns1,ns2,ns3. - Back at your registrar's nameserver settings, delete the old default nameservers.
- Add the three new ones in their place. Save.
.tech/.com domains lands within 2β4 hours.
3 Wire up hosting and email
The part with the most moving pieces β your site and your inbox are two different notes in the same fragrance, and both need their own dose.
- Site hosting (e.g. Netlify): add a
CNAMEforwwwpointing to your site's default subdomain, plus anArecord on the root (@) pointing to your host's load-balancer IP β pull the exact IP from your host's own domain settings. - Email (e.g. Proton Mail): add the two
MXrecords your provider gives you, in the priority order they specify, plus theTXTrecord for SPF and the verification string from your provider's domain setup screen. - Anything else with a custom domain β form handlers, marketing tools β only needs DNS records if you're sending or receiving from a custom domain with them. Using their default? Skip it, nothing to accessorize here.
4 Verify everything actually resolves
Run these once propagation's had time to finish β call it the mirror check before you walk out the door.
| Command | Expected result |
|---|---|
dig NS | Your new host's three nameservers β |
dig MX | Your mail provider's MX hostnames, in priority order β |
dig TXT | Your SPF string (v=spf1 ...) and your provider's verification string β |
dig CNAME | Your site host's domain (e.g. *.netlify.app) β |
5 Close the loop with your mail provider
- Once MX and TXT resolve correctly, go into your mail provider's domain settings and run its built-in verification.
- Click through every tab it offers β Verify, MX, SPF, DKIM, DMARC. One green check is not the whole fit; check all five.
- Send yourself a test email from an outside address. DNS status and actual delivery are two different receipts.