Turn a DNS edit into a controlled change plan
Name the owners, evidence, smallest action, stop condition, verification, and rollback before touching a control plane. The planner identifies missing decisions; it never approves execution.
Draft assessment
Untitled change draft
Draft blocked
9 required items must be resolved before this draft is reviewable.
- Risk
- Not selected
- Affected surfaces
- 0
- Preflight confirmed
- 0/7
Resolve before review
- Name the planned operation.
- Define the user-visible outcome.
- Select the highest applicable risk level.
- Select at least one affected service surface.
- Name the change owner.
- Name an independent verifier.
- Define one smallest coherent action.
- Define an explicit stop condition.
- Define verification from authority outward.
No required planner item is missing. Human approval and evidence review still remain.
Ownership and window
- Change owner: Not named.
- Approver: Risk not selected.
- Independent verifier: Not named.
- Window: Risk not selected.
- Maximum acceptable interruption: Risk not selected.
Preflight and affected surfaces
- Review: No affected surface selected.
- Select a risk level before relying on preflight confirmations.
One coherent action and stop
- The action is not defined.
- Stop when: No stop condition is defined.
- After the first unexplained result, stop adding changes.
Verification
- The verification plan is not defined.
- Record the exact query or check, observer, answer or result, TTL where relevant, and time.
- Do not report a global propagation percentage.
Rollback
- Select a risk level before deciding whether rollback is required.
Planner cautions
- This planner checks whether a draft contains required evidence and decisions. It cannot approve a change or prove the entered facts are correct.
- A rollback is another DNS change. Restoring authoritative data cannot erase values already held by caches.
Planner boundaries
- The assessment only checks the structure of what you enter. It cannot verify evidence, authorize an account action, or know whether a destination is healthy.
- Device storage belongs to this browser profile and origin. It is not a backup, approval record, collaboration system, or secure secret store.
- Restoring authoritative data does not erase cached old, failed, or negative answers. Keep relevant destinations available through the overlap window.
- Account ownership, registrar recovery, DNSSEC, and certificate policy decisions still require the responsible humans and providers.
Read the complete safe DNS-change checklist and the cache-aware rollback playbook before executing a risky change.
