Taking the whole DNS zone to Cloudflare without losing records

When you add a domain to Cloudflare, it reads your current DNS and brings across what it finds. That gives the impression everything is copied. It is not. It can only bring what is published and what it thinks to ask for, and whatever is missing only announces itself days later, when somebody notices the e-mail stopped.

The automatic read is a best effort, not a copy. Do not treat it as an export. The only reliable list of what your domain has today is in the cPanel Zone Editor, and that is what you check against.

Step zero: get the real list

1 Open cPanel and the Zone Editor tool. See how to access cPanel.
2 Pick the domain and ask it to show all records, not just one family.
3 Save the list. A file, a screenshot, a printed sheet. You need it open beside you while you check.
4 Count the lines. You are about to compare them one by one, and knowing the total stops you skipping any.

If you cannot read what is there, every record type is explained in DNS records explained.

The families that usually go missing, worst first

Family What happens if it is missing
Mail records E-mail stops the minute propagation lands. The worst and the most common.
SPF The mail you send starts landing in recipients spam. See SPF, DKIM and DMARC.
DKIM The same, and even harder to diagnose. These are very long text records: check the value came across complete, not cut halfway.
DMARC Reports stop and, depending on the policy, messages may start being refused.
Service verifications Google, social networks and tools stop recognising the domain as yours. See TXT verification records.
Administrative names Mail, webmail, cPanel, FTP. The site still opens and everything else stops, which confuses everybody.
Subdomains Each is a record of its own. Any that do not come across simply vanish.
Other services records Shops, newsletter tools, booking systems, ticketing systems. They usually ask for a record with a name you have not looked at since.
Long text records are the special case. Mail signing keys are enormous strings, and they are sometimes stored in pieces. Copy the whole value from this side, paste the whole value on the other, then compare the beginning and the end. Half a key produces no error at all: it produces mail that lands in spam.

The check, field by field

For every line on your list, confirm four things on the Cloudflare side. It is dull, and it is what avoids the Monday phone call.

1 The type is the same. A mail record imported as a text record is worth nothing.
2 The name is the same. Watch which ones are short names and which carry the whole domain.
3 The value is the same, down to the last character, with no stray spaces.
4 The priority, where there is one, is the same. Swapped priorities on mail records deliver everything to the wrong server.

On record lifetimes: Cloudflare forces the automatic value on anything it proxies. That is normal and not a mistake of yours.

The proof you can run before risking anything

This is the best part, and almost nobody uses it: Cloudflare nameservers already answer for your domain before they are at the registrar. You can question them directly and see exactly what they will tell the world on the day of the swap.

1 Ask them for the domain and see whether they return the right address.
2 Ask them for the mail records. If they return nothing, aren’t you glad you asked.
3 Ask them for the text records. Compare SPF and the verifications with what you have today.
4 Ask them for the subdomains you actually use.
5 Only if everything matches do you go to the registrar and swap the nameservers.

How to run a lookup like that is in how to check a domain DNS. If you prefer, send us the list and we will check it with you.

The zone that stays here

It is not deleted: it stays on the server exactly as it was, and nobody reads it. That has two practical consequences.

Consequence What to do
Editing here stops having any effect After the move, you edit at Cloudflare. It is the confusion that reaches us most often.
The zone here quietly ages After a year, what is here no longer represents your domain. That is why leaving Cloudflare means copying the zone back, not simply swapping nameservers.
If the hosting is ever closed, the zone here goes with it One more reason to keep your own copy of the record list, in a file of your own.

The return journey is in switching the CDN off and confirming it is off. To create new things after the move, creating a subdomain on Cloudflare.

Send us the Zone Editor list and the Cloudflare list, and we will tell you what is missing.

Open a support ticket

SEE ALSO

WHOIS lookup

Professional e-mail

Support Policy

RECOMMENDED PRODUCT

Register your .co.mz domain

Secure your company name before someone else registers it. from $41.68/yr

Search a domain
  • 0 Users Found This Useful
Was this answer helpful?