Cloud & Server Management

DNS Management

We set up and manage DNS records correctly the first time, verify mail records against real delivery, and document the full zone so future changes are safe for whoever makes them.

What DNS management covers

DNS is the directory that tells the internet where your website, email and services live. Each record type has a job: A and AAAA point names to IPv4 and IPv6 addresses, CNAME aliases one name to another, MX says where email should go, TXT holds verification and email authentication data, and SRV points to specific services. A single wrong record can stop email arriving or take a site offline.

DNS management means keeping that zone accurate, tidy and documented as your business adds tools, domains and servers over time.

Signs your DNS needs attention

  • Emails from your domain land in spam, or some customers never receive them.
  • The zone has dozens of records nobody can explain, including for tools you no longer use.
  • You have several SPF records, or a DMARC record that was copied from somewhere without being understood.
  • A new subdomain works for you but not for colleagues or customers.
  • Your DNS was imported automatically when moving providers and some records never came across.

What’s included

  • Full zone audit, with every record explained or flagged for removal.
  • Web records (A, AAAA, CNAME) pointing to the right servers or platforms.
  • Mail records: MX, SPF, DKIM and DMARC set up and checked with real test messages.
  • Verification TXT records for services such as search consoles and SaaS tools.
  • SRV and CAA records where your services need them.
  • Sensible TTLs: short during changes, longer once stable.
  • A documented zone file you keep, with notes on what each record is for.

How we work

  1. Export and back up the current zone before any change.
  2. Map each record to a service and identify stale, duplicate or conflicting entries.
  3. Plan changes, lowering TTLs first where traffic or mail flow is affected.
  4. Apply changes and verify from multiple public resolvers.
  5. Test mail by sending to external mailboxes and checking authentication results.
  6. Hand over the documented zone and restore normal TTLs.

DNS providers and tools

We manage zones on Cloudflare, AWS Route 53, Google Cloud DNS, Azure DNS, DigitalOcean and registrar or hosting DNS panels. Verification uses standard tools like dig and public resolver checks. When moving to a new DNS provider, we check that every record came across, because automatic imports frequently miss records or bring in nothing at all.

For deeper mail work, such as dedicated sending domains and deliverability monitoring, see our Email Infrastructure & Deliverability services.

What affects timeline and cost

A small, tidy zone takes little time. Larger jobs involve many domains, provider migrations, mail authentication for several sending services, IPv6 rollout or zones with years of undocumented records.

When zones are managed in several places, such as a registrar panel for one domain and Cloudflare for another, we can consolidate them into one provider so changes happen in a single, well-documented place.

Record types at a glance

Understanding what each record does makes it much easier to spot mistakes. Here is a plain-language reference we include in every zone handover:

RecordPurposeTypical example
A / AAAAPoints a name to an IPv4 or IPv6 addressexample.com to your web server
CNAMEMakes one name an alias of anotherwww.example.com to example.com, or a subdomain to a SaaS tool
MXSays which servers accept email for the domainYour email provider’s mail servers
TXTHolds text used for verification and email policiesSPF, DKIM, DMARC and site verification
SRVPoints to a specific service and portCalendar, chat or VoIP services
CAALimits which authorities may issue certificatesAllow only your chosen certificate issuer

Each record in your zone is annotated with the service it belongs to. When you stop using a tool, you can remove its records with confidence; when you add one, you know exactly where its records fit and whether they conflict with anything already there.

Common mistakes

  • Publishing two SPF records instead of one merged record, which causes SPF to fail.
  • Setting DMARC to reject before confirming all legitimate senders pass authentication.
  • Putting a CNAME at the root domain where the provider does not support flattening.
  • Copying mail records from a provider’s instructions without adapting them to your domain.
  • Leaving records pointing at deleted cloud resources, which can allow subdomain takeover.

Related: Domain Configuration and Cloudflare Setup. Browse Cloud & Server Management, the cloud and server guide, or contact us.

Frequently asked questions

Why do DNS changes take time to show?

Resolvers cache answers for the record’s TTL. Lowering TTLs before a change shortens that window.

Can you fix our emails going to spam?

DNS is often part of it. We check SPF, DKIM and DMARC first; if the issue is reputation or content, we cover that through our email infrastructure services.

Which DNS provider should we use?

Cloudflare suits most businesses and is simple to manage. If your infrastructure lives in AWS, Google Cloud or Azure, their DNS can make automation easier.

Do you manage DNS on an ongoing basis?

Yes. We can handle change requests and keep the zone documentation current as you add services.

What is subdomain takeover?

It happens when a DNS record still points at a cloud resource or SaaS account you have deleted. Someone else can claim that resource and serve content on your subdomain. Regular zone reviews remove these dangling records.

Talk to us about dns management

A, CNAME, MX, TXT and SRV records set up correctly the first time.

Let's talk

Have something you need built, hosted or fixed?

Tell us what you are trying to do. If we are not the right people for it, we will say so.