Turn a DNS edit into a controlled change plan

Name the owners, evidence, smallest action, stop condition, verification, and rollback before touching a control plane. The planner identifies missing decisions; it never approves execution.

1. Outcome and risk
Affected service surfaces
2. Owners and window

Approval, window, interruption, and rollback ownership are required for state-changing plans.

3. Preflight evidence

Clear any statement that is not yet proven. An unchecked item becomes a stop condition for state-changing plans.

4. Action, stop, verification, and rollback

Draft assessment

Move www.example.com to a prepared web origin

Ready for human review

Every required planner field and preflight confirmation is present. The draft is ready for human review, not approved for execution.

Risk
reversible
Affected surfaces
3
Preflight confirmed
7/7

No required planner item is missing. Human approval and evidence review still remain.

Ownership and window

  • Change owner: Change owner
  • Approver: Approver
  • Independent verifier: Independent verifier
  • Window: Approved window and communication channel
  • Maximum acceptable interruption: 15 minutes

Preflight and affected surfaces

  • Review: authoritative DNS records and cache overlap; TLS, redirects, CDN, origin, and representative web journeys; issuance policy, validation, hostname coverage, and renewal
  • Complete current state and rollback evidence are captured.
  • Every intended authoritative server agrees.
  • Affected destinations and consuming services are ready.
  • Parent DS and child signing state are understood.
  • Required provider, registrar, and recovery access is verified.
  • Exact prior values and the rollback procedure are complete.
  • Monitoring can distinguish DNS from application failure.

One coherent action and stop

  • Replace the approved www A RRset once; do not change mail or delegation.
  • Stop when: Stop before submission if authorities disagree, the destination fails TLS or HTTP checks, or the rollback owner is unavailable.
  • After the first unexplained result, stop adding changes.

Verification

  • Confirm every authority serves the intended RRset and TTL, then check named resolvers, TLS coverage, redirects, HTTP behavior, monitoring, and the user journey.
  • Record the exact query or check, observer, answer or result, TTL where relevant, and time.
  • Do not report a global propagation percentage.

Rollback

  • Owner: Rollback owner
  • Restore the captured prior www A RRset once if authoritative publication is wrong or application errors exceed the approved threshold; keep both origins available through cache overlap.
  • After restoration, verify authority, delegation and DNSSEC where applicable, named resolvers over time, and every affected application layer.

Planner cautions

  • This planner checks whether a draft contains required evidence and decisions. It cannot approve a change or prove the entered facts are correct.
  • A rollback is another DNS change. Restoring authoritative data cannot erase values already held by caches.

Planner boundaries

Read the complete safe DNS-change checklist and the cache-aware rollback playbook before executing a risky change.