DNS cutover without downtime
Lower TTLs early, dual-publish critical records, and verify from multiple resolvers before decommissioning the old stack.
TTL hygiene
Lower authoritative TTLs to 300s at least 48 hours before cutover. Confirm recursive caches have drained for your highest-traffic regions.
Dual publish
Serve identical MX, SPF, and DKIM on both old and new providers during the overlap window. Email failures are the most expensive cutover bugs.
Verification checklist
Probe with dig +trace, public DNS checkers, and synthetic monitors from CN / US / EU. Keep the old zone for one full TTL cycle after traffic flips.