On Page Navigation

Managed DNS Services for Records Redirects Migrations

Your DNS is the switchboard for your entire online presence, and one wrong record takes down your website or your email. Our managed DNS service runs every zone inside Cloudflare, where changes propagate in seconds instead of hours. You send the request, we make the edit, and we confirm it resolved correctly. Every change is included at no extra charge, so nobody on your team has to hesitate before asking.

Network rack carrying the DNS infrastructure behind a managed Cloudflare zone.

DNS handled by people, not tickets

What makes our managed DNS service different

Most hosts treat DNS as a form buried three menus deep in a control panel you rarely open. Registrars charge for a support ticket to change one record. We do it differently. Your zones live in Cloudflare under our management, you ask for what you need in plain language, and a person who understands DNS makes the change and verifies it. No panels to learn, no per-change fees, no waiting on a queue.

What that buys you is mostly the absence of incidents. Records are documented, so nobody has to guess what an old TXT entry was for before deleting it. Changes go out with a short TTL first and are confirmed as propagated rather than assumed. Mail authentication is rechecked as part of every change, because that is what breaks most often when a record moves. And your zones stay portable. They are your domains, and you can take them with you whenever you want.

Managed DNS vs your registrar

A managed DNS service compared to registrar DNS

Most businesses leave DNS wherever the domain was registered, because it works until the day it does not. The difference shows up when something needs to change quickly, when email starts failing, or when nobody can remember who has the login.

Who makes the change

Ask us and it is done. A typical registrar hands you a control panel and a help article, then charges for a support ticket if you get stuck. DNS mistakes are easy to make and hard to spot before they cause damage.

How fast records propagate

Cloudflare pushes edits across its anycast network in seconds. Older registrar DNS often carries long default TTLs and slow refresh cycles, so a change you made this morning may still be invisible to some of your visitors tonight, and you have no way to tell.

Cost of a small edit

Every change is included, no matter how many you send. Registrars and hosts frequently bill per request or bundle DNS help into a paid support tier, which quietly discourages teams from fixing small problems while they are still small.

Email record expertise

SPF, DKIM, and DMARC get built and validated by someone who does it regularly. Registrar support will paste a record for you but will not tell you that your third sending service is missing from SPF and is failing silently.

A record of what changed

We keep an export of each zone and note what we changed and why. Registrar panels rarely log anything useful, so when something breaks six months later nobody can say what moved or when it moved.

Domains under one roof

Every domain you own sits in one managed account with one point of contact. Spreading zones across three registrars means three logins, three renewal dates, and a real chance that the one nobody watches expires.

Built for domains that matter

Who our managed DNS service fits best

DNS management pays off when downtime is expensive, when email has to land reliably, or when nobody left on the team remembers how the records were set up. If any of that sounds familiar, having a person responsible for your zones is worth more than the monthly cost.

Transparent pricing for managed DNS

Pricing

Managed
DNS

Standalone Service

$50.00
/per month, per domain
Unlimited DNS changes included

SERVICES INCLUDED

DETAILS

Full DNS management for one domain, hosted on Cloudflare. We handle records, email authentication, redirects, subdomains, and the initial migration from your current provider. Send as many change requests as you need and none of them cost extra. Responses land within one business day, and every zone is backed up before we touch it.

Managed
DNS - Priority

Standalone Service

$130.00
/per month, per domain
Priority response and traffic routing

SERVICES INCLUDED

DETAILS

Everything in the standard plan, with a one-hour response target during business hours and emergency changes covered after hours. Adds load balancing with health checks, geographic routing, and ongoing DMARC report monitoring. Built for domains where an outage costs real money and where a delayed record change is not an acceptable outcome.

Everything we manage in your DNS

Complete managed DNS coverage

Icon representing a feature included in this managed service.Cascadia Web Services logo

Unlimited DNS Record Changes

Send as many change requests as you need. A new subdomain, a repointed host, a record for a tool you started using yesterday. The price is the same either way. We charge per domain because metering edits teaches people to sit on small problems until they turn into outages.
Icon representing a feature included in this managed service.Cascadia Web Services logo

Full Zone Setup and Cleanup

We build your zone from scratch, or we take the one you have and work out what is still load-bearing. Most zones we inherit hold records for a mail provider the client left years ago, a verification TXT nobody can identify, and at least one A record pointing at an IP that stopped answering. Whatever survives the audit gets documented.
Icon representing a feature included in this managed service.Cascadia Web Services logo

A, CNAME, and Alias Records

The records that point your domain and its subdomains at the right places. Picking the type matters. A CNAME follows its target when that target's IP changes, an A record does not, and Cloudflare flattens proxied CNAMEs so you can still use one at the apex.
Icon representing a feature included in this managed service.Cascadia Web Services logo

TTL Tuning and Propagation Control

On Cloudflare, proxied records sit at a fixed 300 second TTL that cannot be edited. Unproxied records are yours to set, anywhere from 60 seconds up to a day, and we bring them down before a planned move so a mistake costs minutes. Knowing which of your records you can actually control is most of this job.
Icon representing a feature included in this managed service.Cascadia Web Services logo

SPF Record Management

One valid SPF record listing every service that sends on your behalf. Not two, which fails automatically, and not a chain of includes long enough to blow past the lookup limit.
Icon representing a feature included in this managed service.Cascadia Web Services logo

DKIM Signing Setup

Keys published for each sending platform, then verified from outside your network. One quirk worth knowing: Cloudflare warns you, or refuses outright, when you try to proxy a CNAME used for DKIM validation. That refusal is correct. People override it anyway.
Icon representing a feature included in this managed service.Cascadia Web Services logo

DMARC Policy Rollout

Monitoring first. Then quarantine, then reject, and only once the reports show your legitimate mail authenticating on every path it travels. Jumping straight to enforcement is how a business discovers in public that its invoicing system was never signing.
Icon representing a feature included in this managed service.Cascadia Web Services logo

MX and Mail Host Cutover

Mail is where DNS goes wrong most often, usually for one reason: somebody proxied the A record the MX points at. Cloudflare cannot proxy MX or TXT records at all, and it does not carry SMTP on port 25 without Spectrum in front of it. We sequence the cutover so nothing bounces.
Icon representing a feature included in this managed service.Cascadia Web Services logo

Redirects and URL Forwarding

Old domains, dead campaign URLs, and the www variant, all forwarded where they belong. Visitors land on the page. Search engines keep the equity.
Icon representing a feature included in this managed service.Cascadia Web Services logo

Subdomain and Service Routing

Point a subdomain at your help desk, your status page, your booking tool, or whatever you adopt next. You describe the outcome you want. We work out the record type and wire it up.
Icon representing a feature included in this managed service.Cascadia Web Services logo

Cloudflare Proxy Configuration

Proxying hides your origin IP and puts Cloudflare between your site and whatever is knocking on it. That is the right default for web traffic and the wrong one for mail, domain verification, and a few SaaS hosts. Worth knowing: if two A records share a name and either one is proxied, Cloudflare treats both as proxied.
Icon representing a feature included in this managed service.Cascadia Web Services logo

Domain and Host Migrations

Planned, not improvised. Records recreated and checked against the live zone first, TTLs lowered where they can be, then the cutover, then website and mail verified from several networks before anyone calls it done.
Icon representing a feature included in this managed service.Cascadia Web Services logo

DNSSEC Signing

We sign the zone and place the DS record at your registrar, which is the half people forget. The real trap is on the way in. If your domain already has DNSSEC switched on at the old provider and the nameservers move before the parent DS record has aged out, validating resolvers return SERVFAIL and the domain goes dark for everyone behind them. Parent TTLs commonly run 24 to 48 hours. We check that clock first.
Icon representing a feature included in this managed service.Cascadia Web Services logo

SSL and Certificate Records

CAA records published so only the certificate authorities you name can issue for your domain, and validation records kept current so renewals happen quietly.
Icon representing a feature included in this managed service.Cascadia Web Services logo

DNS Uptime Monitoring

Resolution checked continuously from several locations. If a record starts returning something unexpected, or stops answering altogether, we hear about it before your customers do.
Icon representing a feature included in this managed service.Cascadia Web Services logo

Zone Backups and Rollback

Every zone gets exported before we touch it. When a change has a consequence nobody predicted, the old state goes back in about a minute, and we work out what happened with the pressure off.
Icon representing a feature included in this managed service.Cascadia Web Services logo

One-Hour Change Response

Requests sent during business hours are actioned within the hour. That is a commitment, not an average.
Icon representing a feature included in this managed service.Cascadia Web Services logo

After-Hours Emergency Changes

Something breaks at nine on a Friday. You reach a person, it gets fixed that evening, and no separate invoice arrives for the inconvenience.
Icon representing a feature included in this managed service.Cascadia Web Services logo

Multi-Domain Portfolio Management

Portfolios get run as one set: consistent records across every zone, shared documentation, one renewal calendar. The domain that expires is always the one nobody was watching.
Icon representing a feature included in this managed service.Cascadia Web Services logo

Load Balancing and Failover

Traffic spread across several origins with health checks running behind it. When one stops answering, visitors reach a healthy origin automatically and nobody files a ticket.
Icon representing a feature included in this managed service.Cascadia Web Services logo

Geographic Traffic Routing

Visitors routed to the nearest or most appropriate origin. Useful if you run regional sites, or need traffic from particular countries handled on its own path.
Icon representing a feature included in this managed service.Cascadia Web Services logo

DMARC Report Monitoring

DMARC aggregate reports arrive daily, in XML, and almost nobody opens them. We read yours. New sending sources, forwarding that quietly breaks SPF, and the tool somebody connected without telling you all surface there first.

Answers to common managed DNS questions

Frequently asked questions
What is managed DNS?
A provider runs your domain records for you. Your zones sit in Cloudflare, you ask for changes in plain language, and we make the edit, verify it resolves, and keep an export of the zone from before. You never have to learn record syntax, or find out at two in the morning that a typo took the site down.
What is DNS management, in practical terms?
Keeping your records accurate while the business changes underneath them. Pointing the site at a new host. Adding records so a new tool can send mail as you. Subdomains, redirects, SPF and DKIM and DMARC. None of it is hard. All of it is easy to get subtly wrong, and the bill arrives as downtime, or as mail that quietly stopped being delivered.
Are DNS changes really unlimited and free?
Yes. The fee covers the domain, not the edits. One request a year or ten in a week, the price does not move. We set it up that way on purpose: charging per change teaches a team to batch up small problems and sit on them, and small DNS problems do not stay small.
How long do DNS records take to update?
Cloudflare publishes an edit across its anycast network in seconds. What you actually wait on is TTL, the cache lifetime attached to the record. If a resolver picked up the old value with an hour still to run, it will keep serving that value for the hour. Proxied records are pinned at 300 seconds and cannot be changed, which works in your favour here. Unproxied records we lower ahead of a planned cutover, down to 60 seconds when it matters. Your own laptop may hold a stale answer a little longer than any of that.
What is TTL in DNS records?
Time to live: how long a resolver may cache a record before it asks again. Long TTLs mean fewer lookups and slower changes. Short TTLs mean the opposite. On Cloudflare you can set anything from 60 seconds to a day on an unproxied record, and nothing at all on a proxied one, where it is fixed at 300 seconds.
Where are DNS records stored?
On authoritative nameservers, which hold the definitive copy for your domain. In our case those are Cloudflare's. Resolvers on your visitors' networks then cache copies for as long as the TTL allows. We also keep a dated export of every zone, so there is always a known good state to put back.
Do you take ownership of my domain?
No. The domain stays registered in your name, at your registrar. The Cloudflare account holding the zones is yours as well. DNS management and domain ownership are separate things and we keep them separate. If you leave, you keep all of it, and none of it has to be prised out of our hands first.
Can you fix our email deliverability problems?
Usually. When legitimate mail lands in spam the cause is nearly always one of four things: SPF that does not cover every sender, a platform signing with no DKIM key published, two SPF records where the standard allows one, or a DMARC policy set to reject while something legitimate was still failing. We find every service that sends as you, rebuild the records, and walk DMARC up in stages while actually reading the reports.
Will moving DNS to you cause downtime?
It should not. We recreate every record in Cloudflare and check it against your live zone before anything switches, lower TTLs where they can be lowered, and watch resolution from several networks until it is consistent. The one case that needs real care is a domain with DNSSEC already enabled at the old provider. Move the nameservers before the parent DS record has expired and validating resolvers return SERVFAIL, which to a customer looks exactly like the domain has vanished. Those TTLs commonly run 24 to 48 hours, so that migration gets scheduled around the clock, not squeezed into an afternoon.
How do I request a DNS change?
Email, call, or text. Describe what you want to happen. You do not need to know whether that is an A record or a CNAME, and there is no form to fill in. We work out the record, make the change, and tell you when it is live and verified.
What is the difference between the standard and priority plans?
Standard covers what most businesses need: unlimited changes, email authentication, redirects, subdomains, migrations, zone backups, and responses within one business day. Priority adds an hour response target during business hours, emergency changes outside them, load balancing with health checks, geographic routing, and someone actually reading your DMARC reports. Take priority if an hour of downtime costs you money. If it does not, standard is the honest answer and we will say so.
Can you manage DNS for more than one domain?
Yes, and most clients do. Pricing is per domain, so five domains is five subscriptions, but they sit in one account with one point of contact and one renewal calendar. Consolidating is usually the first job we do, and it usually turns up two or three domains the client had forgotten they owned.
Do we need to use Cloudflare?
For this service, yes. Running every client zone on one platform is what makes the work fast and consistent, and Cloudflare's anycast network is genuinely good at a price that does not need passing on to you. The free tier covers what most businesses need from DNS. We handle the account setup during onboarding, and the account is in your name.
How do I change DNS records if I want to do it myself?
You can. We give you access to the Cloudflare account and you are never locked out of your own zone. In practice most clients stop after a few weeks, because a two line message is faster than logging in and remembering which record type does what. If you do make a change yourself, tell us, so the zone documentation does not drift out of date.
What happens if something goes wrong after a change?
We roll back first and diagnose second. There is an export of the zone from immediately before every change, so putting the old state back takes about a minute. Then we work out the cause with nothing on fire. Most DNS faults look catastrophic and turn out to be one character in the wrong place.
​Contact

Ask Us Anything

We’d love to hear from you!