Check an unexpected DNS change
What to do when a domain's NS, MX, A or TXT records change: how to tell an expected change from a mistake or a compromise, and how to lock DNS down.
By the Domain Health Hub team · Updated
- We take a daily snapshot of a domain's main DNS records and tell you when any of them change.
- Most changes are expected: a new email tool, a site move. Some are mistakes, and a few are attacks.
- Find out who made the change. If nobody did, secure the registrar and DNS accounts first, then put the records back.
What this means
Once a day we record the domain's NS, A, AAAA, MX and TXT records and the CNAME for www, and compare them with the previous snapshot. Something differs: a record was added, removed or changed. The alert names which records changed.
Why it matters
DNS decides where the website and email go. A changed MX record can send a company's incoming email to someone else; a changed A record can put a different website on the domain; changed name servers hand control of everything to whoever runs them. Most changes are routine, but an agency is usually the last to hear about them unless something watches.
How to check the change
- NS
- The most serious. Expected only if the domain moved DNS provider. If not, treat it as urgent.
- MX
- Expected when the client changes email provider. Otherwise incoming mail may be going elsewhere.
- A / AAAA / www
- Expected with a site move, new host or CDN. Otherwise check the site.
- TXT
- Often a new verification record or an SPF edit for a new sending tool. Check SPF still passes.
- Ask the client and your own team whether anyone made the change.
- Look at the DNS provider's audit log, if it has one (Cloudflare does), for who changed what and when.
- If it was intended, check nothing broke: run the domain through the checker and send a test email with the email test.
- If nobody made it, secure the accounts (below) before changing anything back, or whoever made the change can simply do it again.
Securing DNS
Two accounts control a domain: the registrar (which sets the name servers) and the DNS provider (which holds the records). For both, turn on two-factor sign-in, remove old staff and suppliers, and use a shared contact address the client controls. Turn on the registrar lock so the domain can't be transferred without unlocking it first.
Domain Health Hub sends DNS change alerts by email or signed webhook, straight away or in a daily digest, and lists the month's changes on the client's report card.
Questions
Which records do you watch?
The domain's NS, A, AAAA, MX and TXT records, and the CNAME for www. TXT covers SPF and most verification records.
Does a DNS change lower the grade?
No. The change itself is information. If it breaks something, such as SPF or the website certificate, the check for that thing reports it.
Hear about it the day it breaks.
Daily checks on every client domain, alerts when something changes, and a monthly report card your clients will understand.