Domains and DNS, handled.
The boring records that quietly govern whether your website resolves, your email arrives, and your domain is recognised across every platform that needs to see it. We register, configure, document, and maintain — so the technical layer of your identity stops being someone’s anxious afterthought.
Nine moving parts.
One tidy record set.
DNS is one of those layers everyone touches and almost nobody owns. A record gets added during a marketing launch, a developer points an MX entry the wrong way, a TTL is left at thirty days because nobody felt confident lowering it — and then, one ordinary Tuesday, something quiet breaks.
Our work is to take a complete inventory, fix what is wrong, document everything that remains, and keep the record set clean as your business grows. We do not sell domains, but we help you buy, transfer, and manage them across whichever registrars and DNS providers make sense for you.
A & AAAA Records
Where the site livesThe records that point your domain at the IP address of the server hosting the website. We audit existing A and AAAA records, eliminate stale entries pointing at decommissioned servers, and configure them correctly for your current hosting setup — whether that is a single VPS, a load-balanced cluster, or a managed platform behind a hostname. We also coordinate IPv6 (AAAA) records where the host supports them, because IPv6 reachability is no longer optional for a properly modern domain.
CNAME & Alias Records
AliasingCNAME records map subdomains to other hostnames — pointing www at a CDN, shop at a Shopify storefront, app at a SaaS instance. They are simple in theory and quietly prone to misuse: stacked CNAMEs that increase resolution time, CNAMEs at the apex (which the DNS spec forbids), and CNAMEs that conflict with MX or TXT records on the same host. We audit every alias, replace flat-CNAME-at-root setups with ALIAS or ANAME equivalents where the provider supports them, and keep the chain shallow so resolution stays fast.
MX & Email Routing
Mail deliveryThe MX records that decide which mail server receives email for your domain. Wrong priorities, missing fall-backs, lingering MX entries from a previous provider, or a single typo in a hostname — these are the difference between mail that arrives and mail that bounces silently for a week before anyone notices. We configure MX correctly for Google Workspace, Microsoft 365, Tencent Exmail, Zoho, or self-hosted servers, verify delivery end-to-end, and keep the records aligned with the SPF, DKIM, and DMARC work covered on the email-setup page.
TXT Records
Verification & policyTXT records have quietly become one of the most loaded entries in modern DNS — they carry SPF policies, DKIM keys, DMARC reports, domain-ownership verifications for Google, Microsoft, Apple Business, and Cloudflare, and a long tail of platform attestations. We organise them, remove the dozen orphan verifications nobody remembers, keep SPF under the ten-lookup limit, ensure DKIM selectors stay rotated, and document what every record is for so the next person to inherit the zone is not solving a mystery.
DNSSEC
AuthenticityDNSSEC adds cryptographic signatures to your DNS responses so resolvers can verify the records were not tampered with in transit. It is increasingly recommended — and in some industries, required — but it is also the single most common way to break a domain through a registrar transfer or DS-record mismatch. We turn DNSSEC on correctly, coordinate the DS record between your DNS provider and your registrar, monitor for signature failures, and roll keys without disruption when rotation is due. We also know when DNSSEC is not the right call for a particular setup, and we will say so.
Cloudflare-Hosted DNS
Edge integrationCloudflare is the default DNS provider for many of the businesses we work with — fast, free, audit-friendly, and tightly integrated with the CDN, WAF, and bot-management layers. We configure Cloudflare DNS with proxied versus DNS-only records set correctly per use case, handle the subtle interactions between Cloudflare’s flattened CNAME-at-root and your registrar’s NS records, and tune SSL modes so the certificate chain works whether Cloudflare is in front or your origin is exposed directly. The deeper Cloudflare configuration lives on its own page — the DNS surface lives here.
Registrar & Provider Migration
Carry without breakMoving a domain between registrars, or moving DNS hosting between providers, is the single highest-risk operation in this entire discipline. The wrong sequence drops mail for hours, breaks the website, or — at worst — leaves the domain temporarily unowned. We plan migrations against a written checklist: lower TTLs in advance, replicate the full record set on the destination, validate every entry, switch nameservers, monitor propagation, and only then complete the transfer. We do not sell domains, but we will help you choose a registrar (we use Cloudflare Registrar, Namecheap, and Porkbun most often), buy or transfer the domain, and document who holds the keys.
Subdomain Architecture
Naming disciplineA handful of well-named subdomains is a quiet form of brand discipline; a sprawl of app2., new-shop., old-blog., and test-final-v3. is technical debt accumulating in plain sight. We help you decide what deserves a subdomain, what should live on a path instead, and what should be retired entirely. We also coordinate the SSL coverage that follows — wildcard certificates, multi-SAN certificates, or per-subdomain provisioning — so security never lags behind naming.
TTL Strategy & Propagation
Time-to-liveTTLs control how long DNS resolvers cache a record before checking again. Set them too high and a planned migration takes a day to roll forward; set them too low everywhere and you spend resolver capacity for no benefit. We tune TTLs by record type — long for stable apex records, short for records under active change, lowered well in advance of any planned cut-over — and we know how to check propagation honestly using authoritative resolvers rather than the misleading “DNS checker” sites that often misreport. Once a change has settled, we restore sensible defaults so the zone is not perpetually thrashing.
Audit. Document.
Change carefully.
DNS is the area of infrastructure where confidence has to come from process rather than instinct. A wrong record has a propagation delay before it visibly fails, which means mistakes are discovered hours after they were made, by the people they affect rather than by the person who made them. Our approach is shaped by that reality.
Inventory before any change
The first deliverable on every DNS engagement is a complete record-set inventory — every A, AAAA, CNAME, MX, TXT, NS, CAA, and SRV entry across every zone you own. We annotate what each record is for, who depends on it, and whether it is current or orphaned. Most clients have never seen this artefact before, and the inventory alone often surfaces three or four entries that should have been removed years ago.
Lower TTLs ahead of cut-over
Any change with rollback risk — a hosting move, a mail-provider switch, a registrar transfer — gets a TTL-lowering pass at least twenty-four hours before the change itself. That way, if something goes wrong, the rollback propagates in minutes rather than hours. After the change has settled, we restore TTLs to sensible long-term values. It is a small piece of discipline that saves entire afternoons.
Verify with authoritative tools
Every change is verified against the authoritative nameserver, not against the local resolver, and not against a third-party DNS-checker site. We use dig, kdig, and the registrar’s own propagation report. Mail records are verified by sending and receiving real test messages. We do not call a change done because the dashboard says it saved.
Document everything, hand it back
The final artefact of every DNS engagement is a written record-set document — your authoritative reference for what is configured, why, and where. We update it whenever a change lands, store it in a place you can access without us, and design it so any competent technical person could pick up maintenance without a knowledge-transfer call. The records are yours. The documentation is yours. Both stay yours when the engagement ends.
When the records
need a grown-up.
DNS work is rarely the reason a business calls — it is what they discover they need on the way to fixing something else. A migration, a new mail provider, a launch of a new product subdomain, a brand acquisition, an outage with no obvious cause. These are the moments when a tidy DNS layer becomes the difference between a quiet afternoon and a long evening.
A handful of recurring situations where careful DNS work is the unlock.
- i Businesses preparing a hosting or platform migrationYou’re moving from shared hosting to a VPS, from WordPress to Webflow, from Shopify to a custom build — and you would like the cut-over to happen on a Tuesday morning rather than a Friday night.
- ii Teams whose DNS lives somewhere uncomfortableYour records are still at the registrar that came free with the domain ten years ago. The control panel is awkward, propagation is slow, and you would like to consolidate to Cloudflare or a modern provider without breaking anything in transit.
- iii Organisations with portfolios of domainsPrimary brand, regional variants, redirect domains, defensive registrations, and a long tail of campaign URLs. Each lives in a different account, with different TXT records, and nobody is fully sure which still need to renew.
- iv Founders inheriting an undocumented zoneThe previous developer or agency held the keys, and now the keys are with you. You need somebody to walk through the records, identify what is current, retire what is dead, and document what remains.
- v Companies whose mail keeps landing in spamThe diagnosis is almost always at the DNS layer — missing or broken SPF, DKIM, and DMARC entries that nobody has audited end-to-end. We pair this work tightly with the email-setup discipline so the fix is structural rather than cosmetic.
A note on registration: we do not sell domains. We do, however, help you buy them — researching availability, checking trademark conflicts, choosing a registrar that fits your needs, and walking through the purchase with you. If you already own domains, we will help you transfer them to a registrar that suits the rest of your stack, or leave them where they are and manage the DNS layer separately. The choice is yours; our job is to make it informed.
Curious how Google sees your site?
Send us your URL. We’ll send back a Premium SEO Report, prepared by hand, within 48 hours — domain authority, keyword rankings, backlinks, competitor gap, and the quick wins worth chasing first. We’ll flag any DNS issues we notice along the way.
No sales call required.
DNS is where small mistakes break everything for everyone, hours after the keystroke. The discipline is patience, not cleverness.— The Aureole Practice —
Questions we
get about DNS.
If a question is missing here, the contact link at the foot of the page goes straight to the person who would answer it. No ticket queues, no funnels.
i Do you sell domains, or do we buy them ourselves?
ii Our DNS is at our registrar — should we move it to Cloudflare?
iii How long does a DNS or domain change actually take to take effect?
iv Can you take over a zone someone else configured?
v Is DNSSEC worth turning on?
vi What’s the difference between this and the Cloudflare and SSL pages?
Where DNS fits
in the wider stack.
DNS sits below almost everything else in your web infrastructure — when it is right, the layers above feel effortless. The link below returns to the parent service; the pills extend laterally to the sister IT disciplines that depend on a clean record set.
Parent service
Sister sub-disciplines
Adjacent services
Ready to tidy
the records?
Tell us what is on the zone today — or what you wish were. We’ll respond within one business day with a clear assessment, a record-set inventory plan, and a scope that fits your timeline.