A domain is more than its website address
Inventory the existing DNS zone and the services using it. Website A, AAAA and CNAME records are only part of it: email needs MX and authentication records, while other systems may use verification, service-discovery or delegation records. An automated scan or a list of visible hostnames is not a complete inventory.
- Ask the authorised account holder for an export and review its sensitivity before sharing.
- Include SPF, DKIM selectors, DMARC, relevant TXT, CAA and service records.
- Record current nameservers, TTLs and DNSSEC/registrar state.
Import is a starting point, not verification
Cloudflare supports BIND-format export and import, with fully qualified domain targets. Review the resulting records and any provider-specific proxy or flattening settings; importing equivalent-looking values can still change behaviour. Compare the destination against the authorised inventory before changing delegation.
- Check MX priorities and targets explicitly.
- Separate DNS hosting from the actual mailbox host.
- Plan website and mail tests using customer-authorised synthetic messages.
DNSSEC requires its own migration sequence
Cloudflare's documented move warns that an old registrar DS record can cause validation failure if delegation changes too soon. Its procedure removes the old DS record, waits the record TTL and then changes nameservers. Follow the current provider-specific instructions with the registrar account holder; do not treat that sequence as universal for every provider migration.
- Do not delete security or delegation records casually.
- Cached results can persist; define checks over the agreed transition window.
- A DNS rollback does not undo mail delivered or application data written elsewhere.
A credible outcome
Ask for a reviewed record inventory, cutover plan, website and mail checks and an explicit recovery route. No absolute zero-downtime promise follows from copying records. Send the domain and intended providers initially, not registrar credentials; account changes require approved authority.
Sources and limits
- Cloudflare: DNS import and export Checked 2026-10-10.
- Zone records can be exported and imported in BIND format.
- Domain-name targets must use fully qualified names; proxy metadata needs review.
- Cloudflare: DNSSEC Checked 2026-10-10.
- For the documented move to Cloudflare, remove the old DS record and wait its TTL before changing nameservers to avoid DNSSEC validation failures.