DNS safety checklist before making changes
Protect email and other connected services before changing nameservers or adding a Pages CNAME.
Complete this checklist before changing nameservers or adding a DNS record. If you cannot complete an item, tell AlphaBlue. That is a reason to pause, not a reason to guess.
Safety rule: Never use
Reset DNS,Restore defaults,Delete all recordsor a similar action while following this course.
Account and ownership
- I can sign in to the account that manages the domain.
- The account email and phone number are current.
- I can complete its two-factor authentication.
- I know who is responsible for renewing the domain.
- I have not sent my password or one-time code to AlphaBlue.
Changing nameservers does not transfer domain ownership. The domain remains in the customer’s registrar account, and the customer remains responsible for renewal and registrant details.
Save the current state
- I captured every current nameserver in one screenshot.
- I captured the full DNS record list, including records below the first screen.
- If the provider offers DNS export, I exported a copy without replacing anything.
- I sent the screenshots or export to AlphaBlue for review.
Cloudflare may scan common records when a zone is added, but its scan is not guaranteed to find custom hostnames or records such as a less common DKIM selector. AlphaBlue must compare the imported records with the saved source before nameservers are changed.
Protect email and connected services
- I told AlphaBlue whether I use email addresses on this domain.
- I told AlphaBlue about Google Workspace, Microsoft 365, email forwarding or hosting mailboxes.
- I told AlphaBlue about existing shops, booking systems, forms or verification records.
- I will not edit
MX,TXT,SPF,DKIM,DMARC,CAAorSRVrecords unless AlphaBlue gives a specific instruction.
Do not delete a record simply because its purpose is unclear. Unknown records may protect email, verify ownership or operate another business service.
Check for DNSSEC
Look for a setting called DNSSEC, DNS Security, DS record or DNS Security Extensions. Report its current state to AlphaBlue.
Do not disable it immediately unless AlphaBlue has confirmed that the replacement Cloudflare zone and copied records are ready. An old DS record left active during a normal nameserver change can make the domain return SERVFAIL. Cloudflare documents an advanced multi-signer migration, but that is an operator procedure rather than a customer self-service step.
Before pressing Save
- AlphaBlue confirmed whether I am changing nameservers or adding one CNAME.
- AlphaBlue gave me the exact values for this domain.
- The values are not copied from another customer, domain or online example.
- My provider screen matches the provider-specific guide.
- I know which screenshot to take after saving.
Stop and contact AlphaBlue if
- the screen asks you to delete or reset all DNS records;
- you see an existing record with the same
NameorHost; - you see a DNSSEC or DS warning;
- the provider asks you to disconnect email or another service;
- the guide’s menu, field or button is missing;
- you are unsure whether
@, a blank field orwwwis correct; - the website or email stops working.
Take a screenshot before closing the page. Include the full error message, but hide passwords, one-time codes, payment details and recovery codes.
Official references
Technical requirements last verified: 7 September 2026.