Skip to content

Reference

DNSControl parity

Compare DNSControl features with DNSMigrator, including providers, commands, JavaScript functions, record builders, modifiers, export behavior, and gaps.

14 min read

On this page

DNSControl feature parity in DNSMigrator maps dnscontrol get-zones, dnscontrol preview, and dnscontrol push to provider imports, live managed-zone plans, and typed-confirmation pushes. The tables below identify the exact UI, CLI command, implementation, or documented gap for each DNSControl surface.

DNSControl feature parity scope and implementation map#

Only paths reachable from the current web app or dnsmigrator CLI are marked supported here.

AreaDNSMigrator surfaceImplementation
JavaScript importZone → Config as code → Load from dnsconfig.js; Add zone → dnsconfig.jspackages/core/src/features/dnsconfig/runtime.ts
JavaScript exportZone → Config as code; CLI export --format dnsconfigpackages/core/src/features/dnsconfig/export.ts
Record constructionImporter and managed-zone editorpackages/core/src/features/records.ts
Ignore rulesZone → Settings → Ignore rulespackages/core/src/features/ignore.ts
BuildersZone → Records → Use a builderpackages/core/src/features/builders/
Transforms and reverse zonesImporter; zone settings; generated planspackages/core/src/features/transform.ts
Provider plans and pushZone → Preview changes → Changespackages/core/src/features/plan.ts, packages/services/src/zones.ts
One-time migrationNew migrationpackages/services/src/migrations.ts, packages/services/src/handlers/

Status terms: Supported means the construct changes the imported canonical model or a reachable plan. Import-only means script logic runs while converting but has no independent UI control. Preserved-only means metadata round-trips but does not cause a provider operation. Unavailable means the browser runtime rejects it or there is no matching operation.

Providers#

The generated table is the catalog source of truth for DNS and registrar roles, status and capabilities. Provider-specific setup pages use the catalog slug.

72 providers

ProviderDNSRegistrarDNSControl idAuthentication
Akamai Cloud (Linode) DNScloudbeta—LINODEPersonal access token
Akamai Edge DNScdnbeta—AKAMAIEDGEDNSEdgeGrid API client (host, client token, client secret, access token)
Amazon Route 53cloudstablebetaROUTE53Cross-account IAM role with an external ID
Azure DNScloudstable—AZURE_DNSService principal (client ID + secret)
BIND zone filefilestable—BINDUpload or paste an RFC 1035 zone file
Bunny DNScdnbeta—BUNNY_DNSAccount API key
Cloudflare DNScloudstable—CLOUDFLAREAPIScoped API token
ClouDNShostingbetabetaCLOUDNSAPI user auth ID (or sub-user ID/name) + password
deSEChostingbeta—DESECAPI token
DigitalOcean DNScloudbeta—DIGITALOCEANPersonal access token (custom scopes)
DNS Made Easyhostingbeta—DNSMADEEASYAPI key + secret key (HMAC-SHA1 signed requests)
DNSimpleregistrarbetabetaDNSIMPLEAccount API access token
Gandi LiveDNSregistrarbetabetaGANDI_V5Personal access token (legacy API key also accepted)
GoDaddy DNSregistrarstablebeta—Production API key + secret
Google Cloud DNScloudstable—GCLOUDService account key (JSON)
Hetzner DNScloudbeta—HETZNER_V2Hetzner Cloud API token (per project)
Hurricane Electric DNShostingplanned—HEDNSAccount username + password (+ TOTP)
IBM NS1 Connecthostingbeta—NS1API key
Name.comregistrarbetabetaNAMEDOTCOMUsername + API token (Core API, HTTP Basic)
Namecheap BasicDNSregistrarstablebetaNAMECHEAPAPI user + API key, with our egress IP allow-listed
Netlify DNScdnbeta—NETLIFYPersonal access token
Oracle Cloud DNScloudbeta—ORACLEAPI signing key (tenancy, user, fingerprint, key)
OVHcloud DNSregistrarbetabetaOVHApplication key + application secret + consumer key (EU, CA or US API)
PorkbunregistrarbetabetaPORKBUNAPI key + secret API key
PowerDNS Authoritativeself hostedbeta—POWERDNSAPI URL + API key (X-API-Key) + server ID
Vercel DNScdnbeta—VERCELAccess token (+ team ID)
Vultr DNScloudbeta—VULTRAPI key (personal access token)
AdGuard Homeself hostedbeta—ADGUARDHOMEServer URL + web interface username + password (HTTP Basic)
Alibaba Cloud DNScloudbeta—ALIDNSRAM user AccessKey
AutoDNS (InterNetX)registrarbetabetaAUTODNSAPI user + password + context (Basic auth), optional TOTP 2FA secret
Azure Private DNScloudbeta—AZURE_PRIVATE_DNSService principal (client ID + secret)
CentralNic ResellerregistrarbetabetaCNRReseller (or sub-user) login + password over the HTTPS gateway
CSC Global Domain ManagerregistrarbetabetaCSCGLOBALAPI key + bearer (user) token
DNS over HTTPS (read-only)registrar—betaDNSOVERHTTPSNone: reads nameservers through public DNS
DNScalehostingbeta—DNSCALEZone-scopable API key (Bearer)
Domeneshopregistrarbeta—DOMAINNAMESHOPAPI token + secret (HTTP Basic)
Dynadotregistrar—betaDYNADOTAPI key
Dynuhostingbeta—DYNUAPI key (API-Key header)
easynameregistrar—betaEASYNAMEUser ID + email + API key + signing salt
Exoscale DNScloudbeta—EXOSCALEIAM API key + secret
FortiGate DNSself hostedbeta—FORTIGATEManagement URL + REST API admin token (Bearer) + VDOM
Gcore DNScdnbeta—GCOREPermanent API token
GidiNETregistrarbetabetaGIDINETUsername + dedicated API password (SOAP)
Gigahosthostingbeta—GIGAHOSTPersonal API key (Bearer flux_live_…)
hosting.deregistrarbetabetaHOSTINGDEAPI key (authToken), optional sub-account ID
Huawei Cloud DNScloudbeta—HUAWEICLOUDIAM access key (AK) + secret key (SK)
IBM Cloud Classic (SoftLayer) DNScloudbeta—SOFTLAYERClassic infrastructure username + API key
Infomaniak DNShostingbeta—INFOMANIAKAPI token (OAuth2 Bearer) with scopes
Internet.bsregistrar—betaINTERNETBSAPI key + password
INWXregistrarbetabetaINWXUsername + password session login, with optional TOTP 2FA secret
Joker.comregistrarbeta—JOKERDMAPI API key (or username + password), session-based
LoopiaregistrarbetabetaLOOPIALoopiaAPI username + password
LuaDNShostingbeta—LUADNSAccount email + API key (HTTP Basic)
MikroTik RouterOSself hostedbeta—MIKROTIKRouterOS REST API URL + username + password (HTTP Basic, RouterOS v7.1+)
Mythic Beastshostingbeta—MYTHICBEASTSAPI key ID + secret (DNS API v2)
NetBirdself hostedbeta—NETBIRDPersonal access token (Authorization: Token) + optional self-hosted management URL
netcuphostingbeta—NETCUPCustomer number + API key + API password (CCP API session)
Netnod Primary DNShostingbeta—NETNODAPI token (Authorization: Token)
NexDNShostingbeta—NEXDNSAPI key (Bearer, nxd_ prefix)
NextDNS rewriteshostingbeta——API key + profile ID
OpenSRSregistrar—betaOPENSRSReseller username + API key
OpenWrtself hostedbeta—OPENWRTLuCI URL + username + password (LuCI JSON-RPC, luci-mod-rpc)
Packetframehostingbeta—PACKETFRAMEAccount session token (Authorization: Token)
Realtime RegisterregistrarbetabetaREALTIMEREGISTERAPI key (Authorization: ApiKey)
RFC 2136 dynamic DNS (AXFR + DDNS)self hostedbeta—AXFRDDNSPrimary server + TSIG key (HMAC-SHA256/512; SHA1/MD5 for legacy servers)
RWTH Aachen DNS-Adminhostingbeta—RWTHDNS-Admin API token (PRIVATE-TOKEN header)
Sakura Cloud DNScloudbeta—SAKURACLOUDAPI key (access token + access token secret)
Scaleway Domains and DNScloudbeta—SCALEWAYIAM API secret key (+ optional project ID)
Tencent Cloud DNSPodcloudbetabetaTENCENTDNSCAM SecretId + SecretKey
TransIPregistrarbeta—TRANSIPUsername + API private key (signed JWT), or an access token
UniFi Networkself hostedbeta—UNIFIAPI key (X-API-Key) + controller URL or UniFi console ID (via api.ui.com)
Websupporthostingbeta—WEBSUPPORTAPI key + secret (HMAC-SHA1 signed requests)

Hurricane Electric is cataloged but planned because DNSControl automates its web UI with account credentials and a TOTP seed rather than an official API. GoDaddy remains available even though current DNSControl no longer includes it. DNSMigrator also has providers beyond DNSControl, including NextDNS rewrites.

DNSControl get-zones, preview, and push#

DNSControl command or fileStatusDNSMigrator equivalent
previewSupportedManaged zone: Preview changes → Changes. Migration: Create preview. Both read live state and produce a plan without record writes.
pushSupportedManaged zone: type the zone name, then Push to N providers. Migration: Apply N changes. Both re-read live destination state and calculate the operations used for the write.
check-credsSupportedCreating a connection runs verification; Connections → Check access runs it again and records read or write scope.
get-zonesSupported in UIZones → Add zone → Import from a provider, or select a connected source under New migration. BIND and dnsconfig.js output are available after import or through CLI export; the credential-free CLI does not fetch provider zones.
initUI equivalentConnect a provider, then Add zone. The app does not write local creds.json or dnsconfig.js files.
fmtPartial equivalentZone file validator and CLI export --format bind normalize BIND. DNSMigrator does not reformat arbitrary JavaScript.
checkSupportedManaged-zone Zone checks and CLI dnsmigrator lint.
print-irSupportedCLI dnsmigrator export --format json emits the canonical zone model.
creds.jsonDeliberately replacedCreate encrypted workspace Connections. Credential files are not imported or exported.
--domains / --providers selectionUI equivalentOpen one managed zone and attach its providers under Settings → Providers.
--variable / CLI_DEFAULTSPartialCLI_DEFAULTS is parsed, but the current import screen has no variable input; missing variables produce a warning.
--notifyUI equivalentConfigure workspace Notifications; pushes, drift, cutover and failures dispatch through those channels.
--expect-no-changesUI and CLI equivalentsCheck for drift for managed zones, or dnsmigrator diff --strict for files.
--no-populateNo direct switchManaged preview does not create zones; push/apply can create a missing destination zone.
--reportSupported by related surfacesMigration Report pages, CLI JSON, and translate --report.
--help, --version, color flagsCLI equivalentdnsmigrator --help, --version, --no-color, and NO_COLOR.

DNSControl’s removed ppreview and ppush aliases do not need equivalents. DNSMigrator does not expose DNSControl’s --cmode modes; managed-zone provider writes run sequentially.

Top-level JavaScript functions#

FunctionStatusBehavior in DNSMigrator
DSupportedDeclares one desired zone; tags after ! are retained.
D_EXTENDSupported, import-onlyAdds modifiers to the closest previously declared parent zone and handles subdomain context.
DEFAULTSSupported, import-onlyApplies default domain modifiers to later D declarations until replaced.
DOMAIN_ELSEWHERESupportedCreates a no-purge zone with explicit nameservers.
DOMAIN_ELSEWHERE_AUTOSupportedCreates a no-purge zone and attaches declared DNS providers.
NewDnsProviderSupportedDeclares a key and resolves its DNSControl type, catalog ID, slug, or inferred name for later connection mapping. No secrets are read.
NewRegistrarPartialParses and retains registrar identity, but the importer has no registrar-connection mapping control. Select Registrar account in the imported zone’s settings; no secrets are read.
IPSupported, import-onlyConverts a valid dotted IPv4 address to its integer form for transform tables.
REVSupportedGenerates IPv4 or IPv6 reverse-zone names, including classless forms.
REVCOMPATSupported, import-onlySelects RFC 2317 or RFC 4183 reverse naming once per evaluation.
PANICSupported, import-onlyAborts import with the supplied message.
getConfiguredDomainsSupported, import-onlyReturns declarations seen so far for script logic.
INCLUDESupported, import-onlyCopies records from a previously declared zone.
CLI_DEFAULTSPartialWarns for variable names not supplied to the runtime; the web screen does not collect values.
requireUnavailableRejected because the browser worker cannot read modules or files.
require_globUnavailableRejected because the browser worker cannot enumerate files.
globUnavailableRejected in the browser runtime.
FETCHUnavailableRejected because importer evaluation has no network access.
fetchUnavailableLowercase compatibility alias is also rejected.
HASHUnavailableRejected in the browser runtime.

Standard record functions#

All rows below are accepted by the browser importer and represented in the canonical zone model. The managed record editor uses structured forms for provider-supported types. A later provider plan can still mark a record unsupported.

FunctionCanonical resultPlanning note
AAIPv4 is validated and canonicalized.
AAAAAAAAIPv6 is validated and canonicalized.
ALIASALIASRetained as a canonical ALIAS for managed-zone planning. The one-time migration translator can convert it to a destination-native alias, apex CNAME, or supplied static addresses.
CAACAAValid tags are checked; CAA_CRITICAL sets flag 128.
CNAMECNAMETargets are fully qualified; coexistence is linted.
DHCIDDHCIDOne value is retained.
DNAMEDNAMETarget is normalized as a hostname.
DNSKEYDNSKEYAccepted on import but provider-managed DNSKEY sets are omitted from normal plans.
DSDSChild-delegation DS data remains a normal record set. Registrar apex DS changes belong to cutover.
FRAMEFRAMEProvider redirect feature; blocked when the destination has no equivalent.
HTTPSHTTPSPriority and target are normalized; alias mode omits parameters, while other parameter text is retained.
LOCLOCCoordinates and precision fields become canonical LOC presentation text.
MXMXPriority is range-checked and target is fully qualified.
NAPTRNAPTROrder, preference, flags, service, regexp and replacement are retained.
NSNSNon-apex delegation records are planned normally; apex NS is managed through nameserver settings.
OPENPGPKEYOPENPGPKEYValid hexadecimal input is converted to base64; valid base64 is retained.
PTRPTRReverse-zone label handling honors REVCOMPAT.
RPRPMailbox and TXT-domain targets are normalized.
SMIMEASMIMEANumeric fields are checked and association data is canonicalized.
SOASOAAccepted and exportable, but normal provider plans treat SOA as provider-managed.
SRVSRVPriority, weight and port are checked; target is fully qualified or ..
SSHFPSSHFPAlgorithm and fingerprint type are checked; fingerprint is uppercased.
SVCBSVCBPriority and target are normalized; alias mode omits parameters, while other parameter text is retained.
TLSATLSAUsage, selector and matching type are checked; association data is canonicalized.
TXTTXTMultiple JavaScript arguments are concatenated into one logical TXT value.
URLURLProvider redirect feature; blocked where no equivalent exists.
URL301URL301Permanent provider redirect feature; blocked where no equivalent exists.

The canonical model also understands obsolete SPF record sets from BIND/provider input. The importer’s DNSControl-style DSL creates SPF policy data through TXT or SPF_BUILDER, and exports obsolete SPF as TXT with a warning.

Provider-specific record functions#

FunctionStatus and location
ADGUARDHOME_A_PASSTHROUGHSupported for AdGuard Home rewrite semantics.
ADGUARDHOME_AAAA_PASSTHROUGHSupported for AdGuard Home IPv6 passthrough semantics.
AKAMAICDNSupported Akamai Edge DNS provider feature.
AKAMAITLCSupported Akamai traffic-management target with DUAL, A, or AAAA answer mode.
R53_ALIASSupported Route 53 resource/hostname alias; stores DNS name, hosted-zone ID and evaluate-target-health metadata.
AZURE_ALIASSupported Azure resource alias for A, AAAA, or CNAME.
CF_REDIRECTSupported Cloudflare bulk redirect feature; canonical owner is the zone apex.
CF_TEMP_REDIRECTSupported Cloudflare temporary redirect feature.
CF_SINGLE_REDIRECTSupported Cloudflare single redirect with accepted HTTP redirect codes.
CF_WORKER_ROUTESupported Cloudflare Worker route feature.
CLOUDNS_WRSupported ClouDNS web redirect feature.
MIKROTIK_FORWARDERSupported MikroTik forwarder feature.
MIKROTIK_FWDSupported MikroTik forwarding entry.
MIKROTIK_NXDOMAINSupported MikroTik NXDOMAIN entry.
LUASupported PowerDNS LUA record with emitted record type and expression.
BUNNY_DNS_PZAccepted for compatibility, then skipped during import with a warning; it has no release canonical record type or exporter case.
BUNNY_DNS_RDRAccepted for compatibility, then skipped during import with a warning; it has no release canonical record type or exporter case.
PORKBUN_URLFWDAccepted for compatibility, then skipped during import with a warning; it has no release canonical record type or exporter case.

Supported provider features are not portable DNS. During migration, translateZone blocks one when the destination catalog does not advertise the same type and explains that it must be recreated manually. The Bunny and Porkbun compatibility-only functions above are skipped before they reach translation.

Domain modifiers and nameservers#

ModifierStatusDNSMigrator mapping
DnsProviderSupportedAttaches a declared provider and optional nameserver count; map its key to a Connection during import.
DefaultTTLSupportedSaves the zone default used for records without an explicit positive TTL.
NAMESERVERSupportedAdds explicit apex nameservers alongside attached providers’ nameservers.
NAMESERVER_TTLSupportedSaves the TTL used for the planned apex NS set.
NO_PURGESupportedNever delete records at the provider on; provider-only records remain.
PURGESupportedNever delete records at the provider off; exact desired-state planning may delete extras.
AUTODNSSEC_ONSupported where the adapter can toggle DNSSECDNSSEC → Sign; lint warns for attached providers without automatic DNSSEC.
AUTODNSSEC_OFFSupported where the adapter can toggle DNSSECDNSSEC → Unsign. Registrar DS handling is still a separate cutover concern.
AUTODNSSECDeprecated no-opImported with a warning; use the explicit forms.
IGNORESupportedAdds name, type and target glob matching.
IGNORE_NAMESupportedConvenience form for name and optional type matching.
IGNORE_TARGETSupportedConvenience form for target and optional type matching.
IGNORE_EXTERNAL_DNSSupportedPreserves records identified by external-dns ownership TXT data; optional prefix is retained.
DISABLE_IGNORE_SAFETY_CHECKSupportedAllows a configured record to also match an ignore rule, with a warning.
IGNORE_NAME_DISABLE_SAFETY_CHECKUnavailableRejected with instructions to use the domain-wide replacement.
IMPORT_TRANSFORMSupportedAt plan time, derives A and CNAME records from another managed zone and applies IPv4 mappings.
IMPORT_TRANSFORM_STRIPSupportedSame, with source suffix removal.
GIDINET_PREMIUM_NSSupported, import-onlyExpands to the five GidiNET premium nameserver declarations.

Managed-zone planning combines explicit nameservers with provider nameservers returned when a destination zone is created, honoring each configured nameserver count. Existing provider-managed apex NS records are otherwise excluded from ordinary plans. See Multi-provider DNS and Import transforms.

Builders#

Each builder is available under Records → Use a builder and through dnsconfig.js import.

BuilderResult
SPF_BUILDERBuilds an SPF TXT policy, can flatten selected includes when a resolver is available, can split overflow into a %d chain, and warns over the SPF lookup limit.
DMARC_BUILDERBuilds _dmarc TXT with validated policies, alignments, report URIs, failure options and supported extension tags.
CAA_BUILDERBuilds CAA sets for issue, issuewild, issuevmc, issuemail and optional iodef, including critical flags.
DKIM_BUILDERBuilds selector _domainkey TXT for RSA or Ed25519 with validated hash, service and flag values.
M365_BUILDERBuilds selected Microsoft 365 MX, Autodiscover, DKIM, Teams/Skype and enrollment records; SPF is a DNSMigrator extension.
LOC_BUILDER_DDBuilds LOC from decimal latitude and longitude.
LOC_BUILDER_DMM_STRBuilds LOC from degrees and decimal-minutes text.
LOC_BUILDER_DMS_STRBuilds LOC from degrees, minutes and seconds text.
LOC_BUILDER_STRAccepts either supported coordinate text form.

Browser config import has no DNS resolver, so imported SPF flattening remains unflattened with a warning. The managed-zone SPF builder calls the app’s TXT resolver and can flatten there.

Record modifiers and compatibility constants#

Modifier or constantStatusBehavior
TTLSupportedParses seconds or s, m, h, d, w, n, and y duration suffixes.
CAA_CRITICALSupportedSets CAA flag 128.
ENSURE_ABSENT_RECSupportedRemoves a matching value or record even when NO_PURGE is active.
R53_ZONESupported on aliases; preserved at domain levelSupplies an alias hosted-zone ID. Domain use becomes metadata without a provider operation.
R53_EVALUATE_TARGET_HEALTHSupportedStores Route 53 alias health-evaluation intent.
R53_WEIGHTSupportedStores weighted routing, set identifier and validated weight.
R53_HEALTH_CHECK_IDSupportedAdds the Route 53 health-check ID to weighted routing metadata.
HEDNS_DYNAMIC_ONImport/export compatibilityStores canonical dynamic metadata. The live Hurricane Electric provider is planned, so this is not currently a web push target.
HEDNS_DYNAMIC_OFFImport/export compatibilityStores canonical non-dynamic metadata; no live HE web push is available.
HEDNS_DDNS_KEYImport/export compatibility; secret export redactedStores canonical DDNS-key metadata. Normal web export replaces it with HEDNS_DYNAMIC_ON and warns; no live HE web push is available.
CF_PROXY_ONSupportedSets canonical proxied: true.
CF_PROXY_OFFSupportedSets canonical proxied: false.
CF_PROXY_FULLPartialImports as proxied: true; the distinct “full” value is not retained.
CF_PROXY_DEFAULT_ONSupported on importApplies proxied-by-default to A, AAAA and CNAME records without an explicit setting.
CF_PROXY_DEFAULT_OFFSupported as the default stateRetains explicit non-default metadata but does not alter records already marked proxied.
CF_COMMENTPartialStores canonical comment metadata and includes it when a Cloudflare record is otherwise created or updated; a comment-only difference does not create a plan operation.
CF_TAGSNot applied by importerThe current metadata converter reports it as having no equivalent and drops it.
CF_CNAME_FLATTEN_ON, CF_CNAME_FLATTEN_OFFPreserved-only at domain levelKept as zone metadata but do not trigger a Cloudflare operation.
CF_UNIVERSALSSL_ON, CF_UNIVERSALSSL_OFFPreserved-only at domain levelKept as zone metadata but do not trigger a Cloudflare operation.
CF_MANAGE_COMMENTS, CF_MANAGE_TAGSPreserved-only at domain levelKept as zone metadata; provider comparison is capability-driven instead.
DISABLE_REPEATED_DOMAIN_CHECKSupportedAllows an intentionally repeated zone suffix on that record.
AUTOSPLITAccepted no-opCompatibility sentinel; current records are already canonical logical values.
ENDAccepted no-opCompatibility sentinel.
DKIMSupported, import-onlyIdentity wrapper used around generated record modifiers.

Arbitrary metadata objects are accepted, but unrecognized record metadata produces a warning and is dropped from the canonical record. Unrecognized domain metadata is retained as strings and re-exported as a JavaScript object.

Export behavior#

The Config as code tab exports the saved zone, not unsaved edits. It generates provider and registrar declarations, domain modifiers, records, ignores, transforms and supported metadata. CLI export --format dnsconfig uses the same generator for one BIND file.

Export deliberately warns about lossy cases:

  • non-weighted routing has no emitted DNSControl modifier and is dropped;
  • Hurricane Electric DDNS keys are redacted by default;
  • obsolete SPF record types become TXT;
  • unsupported record types become comments;
  • records outside the zone are skipped;
  • SOA serial is provider-managed and is dropped;

Generated JavaScript should be reviewed before dnscontrol push. See dnsconfig.js import and export.

Known deviations#

  • Glob matching follows DNSControl’s implementation where older documentation differs.
  • DMARC and CAA builders reject invalid policy, URI, tag, range and flag input instead of retaining it.
  • Names are lowercased but are not converted to IDNA; use ASCII or already-punycode names.
  • Provider declarations resolve known DNSControl IDs, catalog IDs, slugs and recognizable key names. An inferred type is reported as a warning so you can verify the mapping.
  • D_EXTEND and INCLUDE require the source declaration to appear earlier in the script.
  • The browser importer preserves JavaScript-generated desired state, not arbitrary JavaScript source formatting or comments.
  • Provider capability checks happen after import. A valid DSL function can still be unsupported by an attached provider and will appear in Changes rather than being sent silently.

Features beyond DNSControl#

DNSMigrator adds a separate migration lifecycle with destination snapshots, live destination re-planning, authoritative record verification, operation-scoped rollback, guided or automatic registrar cutover, DNSSEC sequencing, bulk CSV migrations and shareable reports. Managed zones add scheduled backups, restore, drift monitoring, workspace roles and signed notification webhooks. These features are documented by their app workflows rather than represented as extra dnsconfig.js functions.