Identify what is actually moving
A hosting move can leave authoritative DNS unchanged. A DNS-provider move changes which servers answer for the domain. A registrar transfer changes registration management and may have its own nameserver behavior. Write down which of these changes you intend; DNSSEC coordination becomes relevant when the signing and delegation relationship changes.
Cloudflare's full-setup instructions describe changing nameservers and handling existing DNSSEC before that move. Those instructions apply to that onboarding path. A coordinated DNSSEC migration or a different provider can require a different procedure, so do not turn one provider's steps into a universal cutover command. [1]
Inventory delegation and ownership
Record the current authoritative nameservers, the target provider, the current DNSSEC state and the DS record observed at the parent. Identify who can change the registrar's delegation settings and who controls signing at the DNS provider. Keep access and recovery arrangements available before the maintenance window.
Ask both providers how their transition handles the existing DS record, what must be verified before the nameserver change and when the new DNSSEC chain can be enabled. Preserve the documented procedure and relevant timing conditions. Do not assume a dashboard toggle immediately removes cached delegation data everywhere.
Worked example: the web server works but the domain fails
Imagine a fictional site that responds correctly when its new server is tested directly with the intended hostname. After the authoritative nameservers change, a validating resolver returns SERVFAIL for the domain. A stale parent DS record tied to the previous provider is one possible cause; the successful server test does not rule it out.
Cloudflare's troubleshooting guidance describes comparing a normal DNSSEC-validating query with a diagnostic query using checking disabled. A response that succeeds only with checking disabled is evidence to investigate the DNSSEC chain. It is not a reason to disable validation on visitors' devices or declare the domain repaired. [2]
Collect evidence before changing more settings
Record the query name, record type, resolver and observation time for each result. Compare authoritative and recursive responses with help from the DNS operator. Other DNS failures can also produce SERVFAIL, so preserve the actual result rather than labeling every such response a stale DS problem.
If the evidence identifies a delegation or signing mismatch, use the responsible provider's documented correction and verification sequence. Avoid simultaneously changing nameservers, DNS records and hosting configuration without a recorded reason. Multiple untracked changes make it harder to distinguish recovery from a different accidental outcome.
Finish the transition with validation enabled
Cloudflare's onboarding guidance includes re-enabling DNSSEC after the domain becomes active when it was disabled for that transition. Follow the current documented activation and registrar steps, then check the resulting chain. A successful non-validating lookup is not the completion criterion for a signed production domain. [1]
Use the worksheet to retain the DS observation, approved procedure, owner, timestamps and application checks. Verify the website and mail-related records relevant to the move after DNS succeeds. This is a documentation-based coordination guide, not a live DNS incident report. It does not supply universal propagation times or authorize removal of production DS records. If provider instructions conflict or parent-state evidence is incomplete, defer the cutover and resolve the sequence with the responsible operators.
Sources & verification
Product details and prices can change. Check the linked provider before buying.
- Cloudflare DNS documentation: Change your nameservers: Full setup Accessed 2026-09-14
- Cloudflare DNS documentation: Troubleshooting DNSSEC Accessed 2026-09-14
Sources link directly to providers. Product buttons may use separately labeled affiliate links. Read our disclosure.