ClueDNS knowledge path

Learn DNS from ownership to answer

Start with the systems and people involved, then follow the protocol evidence without collapsing distinct responsibilities into one provider.

beginner · read-only

Who controls each part of a domain

Separate the registrant, registrar, registry, DNS host, authoritative server, resolver, web host, CDN, and email provider.

intermediate · read-only

DNSSEC and the chain of trust

Understand how DNSKEY, DS, RRSIG, NSEC, and NSEC3 let validating resolvers authenticate DNS data and where a broken chain becomes bogus.

intermediate · availability-impacting

Safe DNS-change checklist

Plan, approve, execute, verify, and roll back DNS changes with explicit owners, evidence, stop conditions, and application-layer checks.

Provider-specific · verified 2026-07-28

Cloudflare nameserver onboarding

Apply the neutral migration and DNSSEC model to Cloudflare's current full-setup workflow.