Domain Registration & DNS Management.
DNS breaks quietly and loudly — a TTL nobody remembered to lower before a cutover, an SPF record that silently drifted, a registrar whose panel nobody can log into. We audit what you have, document every record, and move providers without the 24-hour outage most migrations ship with. Cleanly done, then handed back to you.
A short list of
real things.
Not deliverables in the consultant sense. Actual files, pages, docs, access. Listed here so there's no surprise.
- 01DNS audit — every active record documented, orphaned records flagged, TTLs reviewed
- 02DNSSEC setup where the registrar and resolver chain support it, with key-rotation plan
- 03Zero-downtime cutover plan — TTLs lowered a week ahead, dual-running where the protocol allows, verified at every resolver
- 04Full zone-file documentation handed over as a committed text file, not a screenshot of a panel
- 05DMARC / SPF / DKIM alignment check if email runs on the domain — including sub-domains
- 06Registrar consolidation — fold scattered domains onto one account if ownership is spread across ex-employees or agencies
- 07Transfer authentication + EPP codes handled end-to-end; registry lock re-enabled after cutover
- 08Post-cutover propagation monitoring across major resolvers for 48 hours, with a written all-clear
Four principles.
No slogans.
Zero-downtime is a plan, not a hope
A clean DNS cutover is the product of a low TTL set a week in advance, a dual-run window where both providers answer, and a verified propagation check before the old record is turned off. Skip any of those and you're gambling with email and traffic on launch day.
Stage before you flip
Every non-trivial change runs against a staging zone first — either on a test sub-domain, or a mirror zone on a second provider. We never edit live records and wait to see what breaks; we edit a copy, verify, then cut over.
Monitor after, not just during
Most DNS failures surface 12–48 hours after the change — a resolver that cached stale, an SPF that didn't realign, a CAA record that now blocks renewal. We watch for 48 hours after any cutover, and catch the drift before your users file a ticket.
The zone file is the source of truth
We hand back a plain-text zone file with every record annotated — what it does, why it exists, what depends on it. If the registrar's UI disappears tomorrow, you still have the truth. A panel screenshot is not documentation.
How we work, start to finish.
- 01Audit & document
We pull every record across every sub-domain, map what each one does, and flag the orphans. You get a plain-language summary of what's live, what's stale, and what's actively risky — before anything moves.
- 02Plan the cutover
Written migration plan with a pre-flight checklist: TTLs lowered, dependencies listed, rollback steps documented, email impact mapped. Nothing touches live records until you've signed off on the plan.
- 03Stage & verify
Records staged on the destination provider, verified against a test resolver and a dual-run window. We confirm every record answers correctly — mail, web, sub-domains, wildcards — before we flip the nameservers.
- 04Cutover & monitor
Nameservers flipped during a low-traffic window, propagation watched across major resolvers for 48 hours. Registry lock re-enabled, DNSSEC keys published, zone file + access credentials handed back to you.
Before you
ask us.
Move DNS without taking the site down.
Send us the domain and whatever you know about the current setup. You'll get a short read on what's live, what's risky, and what a clean migration would look like.
or email hello@genvoid.com