Planned migration from Time4VPS to Contabo. Reduced TTL to 300s 48 hours before. Or so I thought.
The registrar lock. Not the domain lock — the registrar-level change lock I didn't know my old registrar had added in 2023. "Security feature." No notification. Transfer went through. DNS changes published. Global propagation: 4 hours.
But the old registrar's nameservers kept serving stale records for 44 additional hours. Authoritative for our zone somehow? Glue records? Still unclear. Their support: "cache will clear."
It didn't "clear." It aged out. 48 hours total. Revenue impact: measurable. Reputation impact: worse.
Lessons:
- Verify TTL reduction at every level, not just zone apex
- Check for hidden registrar locks beyond standard transfer lock
- Have monitoring on DNS resolution from multiple vantage points, not just propagation checkers
- Document your registrar's "security features" annually — they add them silently
The 7-day story in replies below made me feel slightly better. Slightly.
— Jane @ Contabo