MYTHOSAI

Email and domains / PRACTICAL GUIDE

Review DNS changes for a business domain

Check authoritative settings and important records before blaming a website or mail outage on propagation.

Before you start

A domain you manage, registrar access and access to its authoritative DNS provider.

Identify who is authoritative

A registrar account, a hosting account and a DNS panel can be three separate services. Editing a record in an old panel may have no effect if the domain's active nameservers point elsewhere. Start with the delegation before changing individual records.

This is a read-first exercise. Do not replace nameservers or delete records merely because two dashboards display different information. An existing mail or website service may depend on values that are unfamiliar to you.

Compare the important settings

  1. Check the domain's configured nameservers at the registrar and compare with the intended authoritative DNS provider. Record the current values and recent authorised changes.
  2. Inspect the active zone's website records, mail-routing records and relevant TXT records. Compare them with the documented service configuration rather than guessing from a server name.
  3. Use read-only DNS queries to check what resolvers currently return. Include the queried name, record type and resolver in your notes. Different caches or intentionally different DNS views can produce different responses.
  4. If an unauthorised or incorrect change is identified, preserve the evidence and restore the known-good value through the approved provider. Keep a rollback record and inform the responsible service owner.

Verify service restoration separately

Expected DNS records are only one layer. Test the real website, certificate and email flow through normal authorised clients after the correction. Record a successful external delivery or page response instead of declaring recovery from a DNS screenshot alone.

Check account protection

Unexpected DNS changes can indicate misuse of registrar or DNS credentials. Review account activity, MFA, authorised users and API tokens. A restored record can be changed again if the underlying account access remains compromised.

Protect domain continuity

Document who controls renewal, billing and account recovery. Enable available account safeguards and use an independent recovery route where possible. Expiration and administrative lockout can resemble a technical DNS problem but require different action.

Keep the zone understandable

Give records clear internal ownership in your documentation and retire obsolete entries only after confirming their purpose. A well-maintained zone is not the one with the fewest records; it is the one where an authorised administrator can explain which service each important record supports and how to verify it.

Official references

Consult the current vendor documentation if your version or screen differs.

Documentation-based draft. Commands have not all been executed against the named products in a lab. Validate configuration examples against your installed version before changing a working system.