Skip to content
About DNSMigrator

Built to make DNS cutovers predictable and boring.

DNS is the central nervous system of the modern internet. Yet for decades, moving nameservers has remained a high-anxiety gamble where one forgotten MX record or misconfigured TTL silently takes down production emails, APIs, and customer revenue.

DNSMigrator is a DNS migration tool that previews record changes, checks provider differences, and verifies the destination before nameserver cutover. It replaces hope with a reviewed plan, record-by-record diffs, and a rollback path for the changes it makes.

80+
DNS & Registrar APIs
Normalized into one model
Pre-cutover
Destination Verified
Queried at its own nameservers
7–30 days
Rollback Window
Reverses only our own writes
RFC 1035
Open BIND Standard
Zero vendor lock-in
Engineering Leadership

Meet the Creator

ST

Shubham Takankhar

Creator & Lead Systems Architect

Software Development Engineer · SaaS Security & Cloud Infrastructure

Why I Built DNSMigrator

“I have been in the midnight war rooms when a routine nameserver switch silently dropped SPF and DKIM records, sending transactional emails to spam, or when undocumented ALIAS quirks caused 48-hour outages. DNS operations shouldn't demand nerves of steel. I designed DNSMigrator to give every platform team, sysadmin, and agency the simulation rigor and automated rollback safety they deserve.”

With an engineering background, Shubham envisioned DNSMigrator as a foundational utility for modern internet reliability. The system brings the principles of continuous integration—drift detection, dry-run plans, audit trails, and verified, reversible changes—to the DNS realm.

Technical Focus & Architecture Disciplines

  • Cloud Infrastructure (AWS, Azure, GCP)
  • DNS Protocols (RFC 1035, BIND, DNSSEC)
  • SaaS Security Posture Management
  • Identity Architecture & Zero Trust
  • Distributed State & Background Queues
  • Deterministic Systems Engineering
The Architecture

Our Non-Negotiable Tenets

Every feature and line of code in DNSMigrator is measured against four foundational safety principles.

Preview Before Any Write

Nothing is written until you have reviewed the plan. Apply re-reads the destination first and only starts when the live plan still matches the one you approved; the destination's nameservers are then queried before any delegation change.

Rollback for Our Own Writes

Apply snapshots the destination and records each successful change. Rollback reverses those changes where the destination still matches them; records edited afterwards are left alone and reported, not overwritten.

Not in Your Resolution Path

DNSMigrator is not a proxy and does not host your DNS. Once migrated, your traffic flows straight from your end users to your chosen cloud provider's global anycast network.

Provider Differences Made Visible

Cloudflare CNAME flattening, Route 53 alias targets, Azure alias records and differing minimum TTLs are mapped to the closest equivalent at the destination, or flagged with a reason when there isn't one.

Verification Flow

The Lifecycle of a Safe Migration

How DNSMigrator inspects, translates, verifies and cuts over a domain, and where the remaining risks (resolver caches, DNSSEC timing, provider limits) are handled.

STAGE 01

Deep Ingestion & Normalization

Connect via read-only API or upload standard BIND zone files. DNSMigrator parses all apex, subdomains, and proprietary records into a unified model.

STAGE 02

Semantic Diff & Anomaly Check

Algorithms cross-reference TTLs, conflicting CNAMEs, MX priorities, SPF string syntax, and DNSSEC keys, flagging risks before any mutation.

STAGE 03

Apply & Verification

After you approve the plan, records are written to the destination provider. Probes query its authoritative nameservers to confirm they answer as planned before delegation changes.

STAGE 04

Controlled Delegation & Standby

Switch nameservers at the registrar once verification passes. Public resolvers are checked as caches expire, and you can switch back or roll back DNSMigrator's writes within the rollback window.

Ready to see your zone at the new provider?