Your IP address:
Provider:
...

What are domain nameservers?

Nameservers host a DNS zone and provide authoritative answers for it. Delegation tells the DNS hierarchy where to direct queries for a domain. The nameserver setting at a registrar and the NS records inside the zone are related but not identical control points.

How delegation works

For example.org, the org parent zone points to servers responsible for example.org. A recursive resolver learns this referral and asks an authoritative server for the requested A, AAAA, MX or other record. The authoritative answer comes from the zone, while the recursive resolver may cache it. RFC 1034 describes the hierarchical design.

A DNS provider’s panel may also show NS records inside the child zone. Editing those records alone does not necessarily alter the parent zone’s delegation. During a move, identify both the nameservers configured through the registrar and the ones published by the parent. A mismatch can lead to confusing results.

When to change nameservers

A move to another DNS provider or to self-managed authoritative servers commonly requires an NS change. Before switching, copy the records still needed: website addresses, MX and mail host addresses, TXT used for domain verification, and service-specific records. Query each new authoritative server directly to confirm the zone is complete.

Old delegation data may remain cached during a change. Where possible, keep critical answers consistent between old and new providers through the transition. With DNSSEC enabled, check the DS record in the parent zone separately. An old DS pointing to keys no longer used by the child zone can cause validation failures.

Check the current state

Use the DNS configuration checker to inspect NS and key records, then compare answers from individual servers. Record the time, server name and query type. If one authoritative server gives a different zone version, fix that inconsistency before changing more settings. An answer being present is not enough; its content must be correct.

If a site fails after an NS move, separate three possibilities: a resolver still follows the previous delegation, the new zone lacks A or AAAA, or the web server itself is unavailable. They require different remedies. A domain availability search is not a delegation test.

Reliability and access control

A zone normally has multiple authoritative servers so that one failure does not stop all resolution. They need consistent data and maintained configurations. Protect registrar and DNS-provider accounts with multifactor authentication: anyone able to edit delegation or records could redirect both mail and web traffic.