Written from operating and development evidence. Adapt the principles to the risk, authority and scale of your own system.

Record the current authority

Capture nameservers, A and CNAME records, MX routes, SPF, DKIM, DMARC, verification records and application dependencies before any edit.

Move only the intended layer

If the website is changing servers, preserve mail records unless email migration is explicitly in scope. A new web IP should not silently replace the whole DNS zone.

Lower risk before cutover

Prepare SSL, application configuration, database state and host-based testing first. Reduce TTL early enough to matter and keep the previous service available during convergence.

Verify from outside

Check the public website, form delivery, inbound and outbound mail, DNS propagation and important third-party callbacks from more than one network before closing the rollback window.

Apply this to a real system.

Bring the context and we will identify the useful first decision.

Discuss the related system