Skip to main content

Security essentials

DNS Explained

DNS tells visitors and email systems where to find services for a domain. A mistaken or unauthorised change can redirect traffic or stop important services.

Plain-English guidance · Last reviewed 24 July 2026

On this page

The business case

Why it matters

The same DNS zone may control the website, email routing, certificate validation and third-party verification. Replacing nameservers or copying only web records can silently break mail and security policies.

Account protection and change discipline are often more important than individual record syntax. A protected registrar account, recorded zone and tested rollback reduce both compromise and accidental outage risk.

Know the exposure

Common risks

01

Registrar takeover

Control of the registrar account can allow nameserver, contact or transfer changes that affect the entire domain.

02

Incomplete migrations

Changing nameservers without recreating MX, TXT, CAA or subdomain records can disrupt email and integrations.

03

Uncontrolled change

Unrecorded edits, broad access and low-quality rollback notes make outages longer and attribution harder.

Investigate, do not ignore

Warning signs

  • The domain or DNS account belongs to a former employee, agency or unknown email address
  • Several people share one registrar login without MFA
  • No current zone export or list of website and email dependencies exists
  • Unexpected nameservers, mail records, verification records or certificate issuances appear
  • A provider asks to replace all nameservers for a change that needs only one record

Reduce likelihood and impact

Practical steps

  1. 01

    Confirm ownership and recovery

    Use a business-controlled registrar account, current recovery details, MFA and restricted access for authorised people.

  2. 02

    Document the live zone

    Export records and identify which provider owns each website, email, verification and certificate-related value.

  3. 03

    Plan the smallest change

    Change only the required record, lower TTL in advance when useful, record previous values and agree a rollback trigger.

  4. 04

    Verify dependent services

    After a change, check authoritative answers and test the website, email authentication, inbound mail and important subdomains.

  5. 05

    Review advanced protections

    Consider registry lock, DNSSEC and CAA with providers that support them, understanding that incorrect setup can also cause outages.

Defined website support

How AHANIX can help

AHANIX can plan and carry out authorised website-related DNS changes while preserving known email and service dependencies.

  • Map the records used by the website and document existing values
  • Prepare a controlled website migration or certificate-related DNS change
  • Coordinate validation with the registrar, DNS, hosting and email providers

Clear limits

What this cannot guarantee

  • DNS changes cannot be made risk-free, and cached answers or third-party provider behaviour may delay a visible result.
  • AHANIX cannot guarantee registrar, registry, resolver or provider availability and does not take control without explicit authorised access.

Continue with existing resources

Relevant tools and guides

These links use existing AHANIX tools and guides for the next useful check or deeper explanation.

Common questions

DNS explained questions

What does DNS propagation mean?

Resolvers cache answers for their stated lifetime, so old and new values may be seen at different times after a change. It is not one global switch.

Will changing nameservers affect email?

It can. Nameservers delegate the whole DNS zone. Mail and verification records must be recreated correctly at the new provider before or during the change.

Does DNSSEC encrypt DNS?

No. DNSSEC helps clients validate the authenticity and integrity of signed DNS answers. It does not encrypt ordinary DNS queries or secure the website application.

A scoped next step

Plan DNS changes without guessing

AHANIX can map the website records, preserve known dependencies and coordinate a controlled change with your providers.

Discuss a DNS change

Continue in the Security Centre