Skip to content

The DNS propagation I didn't plan for

Reviews by jane_ffm 23 replies 2.5K views
#11

Porkbun's prices are solid but their DNS propagation from panel to actual nameservers can lag 10-15 minutes. Not a migration killer but worth knowing. Namesilo is faster but their panel looks like 2004.

I buy domains at both, DNS at Cloudflare. Separation of concerns.

world record: 4min Arch install
6 #12
JokoNord said:
The registry itself caches nameserver glue for 24 hours minimum

This is the piece most migration guides miss. They focus on recursive resolver caches and forget about registry-level glue and parent zone TTLs. For .com/.net the parent TTL on NS records is 48 hours by default at some registrars. You can request lower but they don't advertise it.

My quarterly audit now includes: parent zone TTL, registry cache policy, registrar locks, and whether the registry supports EPP info commands to check status flags. Took me three years to build the list. Still finding new items.

Honey badger don't care... about downtime
#13
lee_mcr said:
For .com/.net the parent TTL on NS records is 48 hours by default at some registrars.

KnownHost's "premium dns protection" also modified the parent TTL without telling me. Found it in a WHOIS history months later. They'd bumped it to 172800 seconds when I transferred in, presumably for "stability." The lock re-enabled itself, the TTL change did not revert. I had to request manual reset.

Budget registrars. The ones that look cheap until they aren't.

8 #14

Following this thread closely. I'm on Namecheap with TTL stuck at their minimum of 1200s even though the panel says 300s. Tested with dig, confirmed 1200 from their nameservers. Support: "this is expected behavior."

Expected by whom, exactly?

$3/year. 128MB RAM. Pure happiness.
#15
larryjeong said:
Namecheap with TTL stuck at their minimum of 1200s

I can confirm this from Rotterdam. Their "BasicDNS" and "PremiumDNS" have different actual minimums. Premium honors what you set. Basic silently enforces 1200 floor. It's in their docs but buried three clicks deep: https://www.namecheap.com

Straight paths, please. I like straight paths.

Containers before it was cool
#16

I found a server in a dumpster and now I'm here, but even I know to check

dig +trace
before declaring a migration done. The number of times I've seen "propagation complete" from some dashboard while trace shows the old NS set at the parent...

Jane_ffm, did you catch the old registrar still in the delegation path with trace, or only after the stale records started serving?

#17
dancore said:
Did you catch the old registrar still in the delegation path with trace

Only after. The transfer completed, WHOIS showed new nameservers,

dig +trace
looked clean from Frankfurt. But regional resolvers in Asia and US East were still hitting the old NS. Took me 20 hours to realize it wasn't "propagation" at all — the old registrar's servers were still authoritative for some resolvers that had cached the old NS set.

Their support kept saying "cache will clear" because they didn't understand their own infrastructure was still serving the zone. Or they understood and couldn't admit it.

Single mode till I die 💀
#18

This is why I test from at least 6 locations before calling anything done. VPS in Singapore, Mumbai, London, New York, Sao Paulo, Sydney. $5/month insurance policy.

Also:

ellagee91 said:
The lock re-enabled itself after thirty days

This should be illegal. Did you get any notification when it re-enabled?

5 #19
Hosts28 said:
Did you get any notification when it re-enabled?

Nothing. Found it during a routine check because I now check every migration three times. Even then I miss things. The re-enable happened silently, no email, no dashboard badge. I only caught it because I was verifying something unrelated and saw the lock flag in a WHOIS detail I happened to expand.

They added it in 2022 apparently. "Improved security for all customers." Opt-out available if you know to ask. I didn't know to ask until it broke me twice.

#20

Same here. Well, not KnownHost, different registrar, same pattern. "Security feature" added retroactively to all accounts, no notification, breaks your next migration.

This thread is making me anxious about a migration I have scheduled for next week.

Post a reply

You need an account to reply. Log in or register to join the conversation.

Post reply Preview Save draft