The Baddie Stack πŸ’…πŸΎπŸ“±βŒ¨οΈ

thebaddiestack.tech/dns-checklist

← Back to the portfolio

A routine, not a crisis

The DNS Migration Checklist

Moving your domain's DNS is the least photogenic process in tech β€” no before-and-after, no visible progress, just four dashboards that don't know each other exist. Here's the order, so it reads as calm instead of chaos.

Overview

DNS migration has main character energy for about ten minutes, and then it's just paperwork β€” a lot of small, quiet actions spread across four dashboards that don't talk to each other, in an order nobody wrote down for you. Think of it like a skincare routine: the products were never the hard part, the order was. Apply things out of sequence and nothing absorbs right. This checklist comes straight out of a real migration β€” a domain moved off Squarespace, onto DigitalOcean for DNS, wired up to Netlify for hosting and Proton Mail for email, with the site and the inbox both staying live through the whole thing. Swap in your own registrar, host, and mail provider. The sequence still holds.

1 Before you touch anything

Five minutes here is the difference between a clean switch and a support ticket β€” the prep step everyone wants to skip and nobody should.

  1. Screenshot or export your domain's current DNS records at your existing registrar. This is your rollback plan, not a formality.
  2. Note which records are actually doing something β€” mail, a subdomain, a verification code β€” versus leftover defaults nobody set on purpose.
  3. Confirm you have login access to every dashboard involved before you start: new host, site host, email provider. Getting locked out mid-migration is the one plot twist nobody's asking for.

2 Point your domain at your new DNS host

This is the flag-plant. Everything after this is just waiting for the rest of the internet to get the memo.

  1. At your new DNS host, add your domain and let it generate its own nameservers β€” DigitalOcean, for example, hands you three: ns1, ns2, ns3.
  2. Back at your registrar's nameserver settings, delete the old default nameservers.
  3. Add the three new ones in their place. Save.
The catch Nameserver changes don't take root on your schedule. Give it at least 30 minutes before you check anything β€” full propagation for most .tech/.com domains lands within 2–4 hours.

3 Wire up hosting and email

The part with the most moving pieces β€” your site and your inbox are two different notes in the same fragrance, and both need their own dose.

  1. Site hosting (e.g. Netlify): add a CNAME for www pointing to your site's default subdomain, plus an A record on the root (@) pointing to your host's load-balancer IP β€” pull the exact IP from your host's own domain settings.
  2. Email (e.g. Proton Mail): add the two MX records your provider gives you, in the priority order they specify, plus the TXT record for SPF and the verification string from your provider's domain setup screen.
  3. Anything else with a custom domain β€” form handlers, marketing tools β€” only needs DNS records if you're sending or receiving from a custom domain with them. Using their default? Skip it, nothing to accessorize here.
The catch that breaks most migrations Your site host may still think it owns your DNS. Left unchecked, it'll quietly fight your new host for control β€” no error message, no drama, just records that never resolve right. Go into your site host's domain settings and switch it to "external DNS" before you add a single record anywhere else. Main character energy is for you. Not your hosting dashboard.

4 Verify everything actually resolves

Run these once propagation's had time to finish β€” call it the mirror check before you walk out the door.

# 1. Confirm your new nameservers are live
dig NS yourdomain.com +short
 
# 2. Confirm mail records resolve
dig MX yourdomain.com +short
dig TXT yourdomain.com +short
 
# 3. Confirm your site subdomains resolve to your host
dig CNAME www.yourdomain.com +short
CommandExpected result
dig NSYour new host's three nameservers βœ“
dig MXYour mail provider's MX hostnames, in priority order βœ“
dig TXTYour SPF string (v=spf1 ...) and your provider's verification string βœ“
dig CNAMEYour site host's domain (e.g. *.netlify.app) βœ“

5 Close the loop with your mail provider

  1. Once MX and TXT resolve correctly, go into your mail provider's domain settings and run its built-in verification.
  2. Click through every tab it offers β€” Verify, MX, SPF, DKIM, DMARC. One green check is not the whole fit; check all five.
  3. Send yourself a test email from an outside address. DNS status and actual delivery are two different receipts.