Skip to content

Reference

FAQ

Get direct answers about DNS migration safety, previews, credentials, DNSSEC, rollback, provider support, zone files, the CLI, pricing, and cutover.

6 min read

On this page

This FAQ answers common questions about previews, provider access, apply safety, cutover, rollback, managed zones, the CLI, and billing. The key point is that previewing is free and read-only, while provider writes, cutover automation, and ongoing management features depend on the selected one-time offer or workspace plan.

Migration and safety#

Does DNSMigrator change the provider I am leaving?

Not during preview, destination apply, verification, or rollback. Those stages read the source and write only to the destination. If you select Lower TTLs to 5 minutes at the old provider first during cutover, DNSMigrator deliberately updates eligible source TTLs and waits for the old TTL values to expire. That checkbox is off by default.

When does the migration go live?

Applying records does not change public delegation. The destination begins receiving normal traffic only after nameservers are changed at the registrar and resolver caches move to the new delegation. See Nameserver cutover.

Can DNSMigrator guarantee zero downtime?

No migration tool can guarantee availability for every application and DNS setup. DNSMigrator reduces avoidable risk by showing unsupported records and behavior changes, snapshotting the destination, recalculating the plan before record writes, verifying destination authoritative answers, and sequencing DNSSEC cutover. You still need to review application dependencies and keep the old zone available while caches expire.

What happens to a record the destination cannot represent?

It is marked Unsupported with a reason and has no target record. It is not silently changed into an unrelated type. A downloaded translated zone omits unsupported active records and keeps the report as the explanation. Resolve required unsupported rows before cutover. See Previews and record statuses.

What is the difference between Keep extra records and Make an exact copy?

Keep extra records is merge mode: records found only at the destination remain. Make an exact copy is mirror mode: destination-only records enter the delete plan. Changing the mode rebuilds the preview.

What happens if the destination changes after I preview?

Apply reads the destination and recalculates the plan. If it differs from the preview, Activity records the revised create, update, and delete counts, and apply uses that fresh plan rather than replaying the old operations. A missing destination zone may be created before this live read.

How does verification work?

DNSMigrator asks the destination provider’s authoritative nameservers for every planned record set. Literal records must return exactly the planned normalized values. Aliases are checked as A or AAAA answers; different non-empty source and destination address sets can be informational for CDNs and load balancers. Initial failures are retried, and Verify again is available afterward.

Does rollback restore the whole destination snapshot?

No. Rollback is operation-scoped. It inverts only writes that succeeded and checks the current destination first. If a record was changed after the migration, it is skipped rather than overwritten. This protects unrelated and newer work. See Rollback.

Can I migrate between two accounts at the same provider?

Yes. Create two different connections and choose one as source and one as destination. The preview labels this Same provider, different account.

Do I need a registrar connection?

Not for preview, apply, verification, a zone-file download, or guided cutover. Automatic nameserver switching requires an active registrar connection for the account that holds the domain. Some DNS companies also act as registrars, but the roles and checked permissions remain distinct.

What happens when DNSSEC is enabled?

A safe cutover removes the old DS record, waits, changes nameservers, enables destination signing when supported, and publishes the new DS record. If an API cannot perform a step, the cutover pauses with a manual instruction. Do not switch a signed zone while a DS record still points only to the old provider’s keys. See DNSSEC transitions.

Connections and credentials#

Is read-only access enough?

It is enough to list and read a normal source for preview. A destination needs the provider’s write permissions to apply. The connect form names the expected permissions, and the resulting connection row shows Read or Read + write when the provider adapter can determine scope.

How are credentials stored?

Each connection is encrypted with AES-256-GCM under a per-connection data key. In production that data key is wrapped by AWS KMS. Workspace ID and connection ID are bound as encryption context, and credential decryptions are audited. See Credential security.

When are credentials deleted?

The default service window is 24 hours after the most recent credential use. Every checked use extends that deadline, and the purge job does not delete a connection while a preview, apply, verification, or rollback is actively using it. Choosing Remove deletes the stored secret immediately unless a migration is applying, verifying, or rolling back; the manual-remove check does not protect an in-progress preview.

Does Amazon Route 53 require access keys?

Production uses a cross-account IAM role with a workspace-specific external ID. The connect dialog can open the CloudFormation setup and optionally include write access. Long-lived AWS access keys are rejected in production; local development can use key credentials.

Why does a connection say Access failed?

The initial verification could not perform the provider’s access operation. Common causes are a bad credential, missing list/read permission, API restrictions, an IP allow-list, or an unreachable self-hosted endpoint. Correct the provider setting, then choose Check access. See Troubleshooting access.

What does Beta mean for a provider?

The adapter is implemented and covered by provider contract tests, but it has not yet been exercised against a live account. Run a preview and review every row before applying. Stable providers have also been verified live.

Zone files, CLI, and tools#

Can I migrate without provider credentials?

Yes. Use the zone translator to paste a BIND export, choose a destination, and download translated BIND and JSON results. The translator runs in the browser. In the signed-in migration flow, a zone file can also be the source or destination.

Does public DNS discovery find every record?

Usually not. A complete AXFR is possible only when the authoritative server permits it. Otherwise the checker probes common names and types and marks the result partial. Provider API access or a provider export is the reliable source for a complete reviewed plan.

What can the CLI do?

The open-source CLI can check a public domain, translate a zone file, lint it, diff two files, export BIND/JSON/dnsconfig.js, compare public resolvers, check DNSSEC, and inspect the provider catalog. It accepts no provider credentials and cannot apply. See the CLI command reference.

Which web tools keep the zone file in the browser?

The zone translator, zone file validator, and two-file zone diff run in the browser. Live DNS tools require server queries. The DNS record diff sends the domain and pasted zone file to the server because the server must parse it and query authoritative DNS. See Free web tools.

Can I import DNSControl configuration?

Yes. Zones → Add zone → dnsconfig.js runs the supported DSL in a sandboxed Web Worker. Recreate creds.json entries as Connections, then map each imported DnsProvider key. File loading, globbing, fetches and hashes are unavailable in the browser runtime. See Coming from DNSControl.

Pricing and plans#

What is free?

Migration previews are free. The Free workspace plan costs $0, supports up to 3 managed zones and 1 seat, and has no scheduled backups, drift schedule, multi-provider sync, alerts, team feature, bulk migration, reports, or priority support. Applying a one-time migration uses one of the offers below unless another entitlement covers it.

What are the one-time migration offers?
OfferPriceZone sizeIncluded cutoverRollback window
Migrate$9 per zoneUp to 50 record setsNo guided or automatic cutover tier7 days
Migrate + cutover$29 per zoneAny record-set countGuided switch and DNSSEC handling30 days
Automated$49 per zoneAny record-set countRegistrar nameserver switch through its API30 days

The required minimum tier is Migrate at 50 record sets or fewer and Migrate + cutover above that. Automatic cutover always requires Automated. A record set is one owner/type/routing identity with all of its values, not one value line.

Is a subscription required for a one-time migration?

No. One-time migration entitlements are separate from workspace plans. Plans are for zones you keep managing afterward.

What does Pro include?

Pro is $19 per month or $190 per year. It supports up to 25 managed zones and 3 seats, daily backups, hourly drift checks, multi-provider sync, alerts, and team features. It does not include a one-time migration tier.

What does Agency include?

Agency is $99 per month or $990 per year. It supports up to 250 managed zones and 15 seats, hourly backups, drift checks every 15 minutes, multi-provider sync, alerts, team features, bulk CSV migrations, reports, and priority support. The code-defined plan includes the Migrate + cutover migration tier.

Can the Free plan use managed zones?

Yes, up to 3. You can maintain saved drafts and manually preview changes within the product’s permission checks. Scheduled backups, scheduled drift, and multi-provider sync require the plan features listed above.

How many providers can serve one managed zone?

The service accepts up to 4 provider connections per managed zone. More than one provider requires the Pro sync feature, which is also included in Agency. DNSMigrator combines their selected nameservers and builds a separate provider plan for each. See Multi-provider DNS.

Where can I see my current entitlement?

Open Billing in the workspace. A migration’s apply card also shows the required one-time offer when the migration is not yet entitled. See Plans and billing and the public pricing page.