Migration runbook
1
Inventory the source zone
Export the zone when possible and capture dynamic or provider-managed records separately. Record DNSSEC, ALIAS/flattening, traffic policies, and health checks that may not transfer as plain records.
2
Reduce application TTLs
Several TTL periods before the cutover, lower records that may need rollback. Do not reduce them so far that query load becomes unacceptable.
3
Create and populate the Aptranet zone
Recreate record sets and convert provider-specific routing into Aptranet picker and metadata structures.
4
Validate directly
Query every important name and type against both Aptranet nameservers. Check negative answers and wildcard behavior as well as successful records.
5
Handle DNSSEC deliberately
Coordinate DS records with the signing state of the new provider. A mismatched DS record can make the entire zone appear unavailable to validating resolvers.
6
Change parent delegation
Update registrar nameservers and monitor public resolvers, application health, mail, certificate issuance, and query analytics.
7
Retire the old provider
Keep the old zone consistent until its delegation is no longer observed. Raise lowered TTLs after the system is stable.