Built to make DNS cutovers predictable and boring.
DNS is the central nervous system of the modern internet. Yet for decades, moving nameservers has remained a high-anxiety gamble where one forgotten MX record or misconfigured TTL silently takes down production emails, APIs, and customer revenue.
DNSMigrator is a DNS migration tool that previews record changes, checks provider differences, and verifies the destination before nameserver cutover. It replaces hope with a reviewed plan, record-by-record diffs, and a rollback path for the changes it makes.
Meet the Creator
Shubham Takankhar
Creator & Lead Systems Architect
Software Development Engineer · SaaS Security & Cloud Infrastructure
Why I Built DNSMigrator
“I have been in the midnight war rooms when a routine nameserver switch silently dropped SPF and DKIM records, sending transactional emails to spam, or when undocumented ALIAS quirks caused 48-hour outages. DNS operations shouldn't demand nerves of steel. I designed DNSMigrator to give every platform team, sysadmin, and agency the simulation rigor and automated rollback safety they deserve.”
With an engineering background, Shubham envisioned DNSMigrator as a foundational utility for modern internet reliability. The system brings the principles of continuous integration—drift detection, dry-run plans, audit trails, and verified, reversible changes—to the DNS realm.
Technical Focus & Architecture Disciplines
- Cloud Infrastructure (AWS, Azure, GCP)
- DNS Protocols (RFC 1035, BIND, DNSSEC)
- SaaS Security Posture Management
- Identity Architecture & Zero Trust
- Distributed State & Background Queues
- Deterministic Systems Engineering
Our Non-Negotiable Tenets
Every feature and line of code in DNSMigrator is measured against four foundational safety principles.
Preview Before Any Write
Nothing is written until you have reviewed the plan. Apply re-reads the destination first and only starts when the live plan still matches the one you approved; the destination's nameservers are then queried before any delegation change.
Rollback for Our Own Writes
Apply snapshots the destination and records each successful change. Rollback reverses those changes where the destination still matches them; records edited afterwards are left alone and reported, not overwritten.
Not in Your Resolution Path
DNSMigrator is not a proxy and does not host your DNS. Once migrated, your traffic flows straight from your end users to your chosen cloud provider's global anycast network.
Provider Differences Made Visible
Cloudflare CNAME flattening, Route 53 alias targets, Azure alias records and differing minimum TTLs are mapped to the closest equivalent at the destination, or flagged with a reason when there isn't one.
The Lifecycle of a Safe Migration
How DNSMigrator inspects, translates, verifies and cuts over a domain, and where the remaining risks (resolver caches, DNSSEC timing, provider limits) are handled.
Deep Ingestion & Normalization
Connect via read-only API or upload standard BIND zone files. DNSMigrator parses all apex, subdomains, and proprietary records into a unified model.
Semantic Diff & Anomaly Check
Algorithms cross-reference TTLs, conflicting CNAMEs, MX priorities, SPF string syntax, and DNSSEC keys, flagging risks before any mutation.
Apply & Verification
After you approve the plan, records are written to the destination provider. Probes query its authoritative nameservers to confirm they answer as planned before delegation changes.
Controlled Delegation & Standby
Switch nameservers at the registrar once verification passes. Public resolvers are checked as caches expire, and you can switch back or roll back DNSMigrator's writes within the rollback window.
Ready to see your zone at the new provider?