Migrate nameservers to Azion
Move the DNS of a domain to Edge DNS, test the zone, delegate the domain to Azion's nameservers, and point its hostnames at a workload.
You can migrate the nameservers of a domain to Edge DNS from Azion Console, the Azion CLI, or the Azion API. Afterward, Azion’s nameservers answer every DNS query for the domain, and you manage its records at Azion instead of at your current provider.
The order of the work matters. Resolvers ask Azion only after your registrar delegates the domain, and they get NXDOMAIN for every name the zone does not hold. So you rebuild and test the zone first, and change the registrar last. Edge DNS hosts the zone, and a workload serves your application on the hostnames whose records point at it.
To point one hostname at a workload while your current provider keeps the DNS of the domain, refer to Point a domain to a workload instead.
Select your interface once. The prerequisites and the stages below show only that path.
Prerequisites
- A domain you control, access to its registrar, and the list of records your current DNS provider serves for it.
- The Edit Edge DNS permission, which requires View Edge DNS. Refer to Teams permissions.
- A workload that serves your application. To create one, refer to the Workloads quickstart.
digon your machine, for stages 3 and 6. To install it, refer to Query a zone with dig.
- Access to Azion Console. To sign in, refer to Access Azion Console.
1. Create the zone of the domain
Edge DNS keeps the records of one domain in a zone. Use your domain in place of example.com throughout this guide.
To create the zone with the Azion CLI, run:
The CLI returns the ID of the zone:
Keep the ID. Stage 4 uses it as <zone-id>.
The domain of a zone cannot change, and only one zone in Azion can host a domain. For every zone setting, refer to Create, edit, or delete a zone.
2. Copy the records of the domain
The zone answers only for the records you add to it. Export or list the records at your current DNS provider, then recreate them in Edge DNS before the registrar changes.
To copy the records:
- Leave out the NS and SOA records of the root domain. Edge DNS answers both for the zone itself, and the API refuses an NS record at
@with19021. - Add every other record to the zone with the same name, type, and value. For the steps in each interface, refer to Add, edit, or delete a record.
- Enter each name relative to the zone:
wwwforwww.example.com, and@forexample.comitself. Edge DNS adds the domain, so a name typed with the domain is served with the domain twice.
The zone now holds every name your domain answers for. For the value format of each record type, refer to Record types.
A CNAME record is refused at @ with 19005. If your current provider points the root domain at another hostname, use an ANAME record, as Point an apex domain with ANAME shows.
3. Test the zone at Azion’s nameservers
Query Azion’s nameserver directly before you touch the registrar. The query skips your resolver’s cache, so it shows what Edge DNS answers for the zone today.
To test a record, query ns1.aziondns.net for one of the names you added:
The nameserver returns the value of the record:
Run the same query for each name and type you copied, and compare each answer with your current provider. Without +short, the output header shows status: NOERROR and the aa flag, which marks an authoritative answer.
The first record of a zone can take a few minutes to be answered. If a query prints nothing, refer to A new record returns NXDOMAIN.
To see the nameservers the zone declares for itself, query its NS set:
The zone lists the three Edge DNS nameservers:
The zone answers as your current provider does. The domain is ready to move.
4. Delegate the domain to Azion’s nameservers
Your registrar tells resolvers which nameservers answer for the domain. Replacing the current nameservers with Azion’s moves every query for the domain to Edge DNS.
Get the three nameservers from the interface you used in stage 1:
On the Zones page of Edge DNS, select Copy Nameserver Values. It copies the three names, joined by semicolons.
To delegate the domain at your registrar:
- Open the nameserver settings of the domain at your registrar.
- Replace the current nameservers with all three Edge DNS nameservers:
ns1.aziondns.net,ns2.aziondns.com, andns3.aziondns.org. - Save the change.
The registrar lists the three Edge DNS nameservers for the domain. Stage 6 checks when resolvers follow them.
If your registrar holds a DS record for the domain from your current provider, validating resolvers can reject the answers of Edge DNS. To fix it, refer to Validation fails after turning on DNSSEC.
5. Point the hostnames to the workload
A workload serves your application on the hostnames you add to it. You add each hostname of your domain to the workload, then create a CNAME record in the zone that points the hostname at the Azion domain of the workload.
Workloads replaces Domains. If your account still serves applications through Domains, follow the Domains steps in the Console panel or the API v3 steps in the API panel. For how a workload takes a hostname, refer to Workloads settings and Point a domain to a workload.
To point a hostname at a workload with API v4, first list your workloads:
The response lists each workload with its hostnames in domains and its Azion domain in workload_domain:
Keep the id of the workload and its workload_domain. If domains lists none of your hostnames, send them in a PATCH request. Replace <workload-id> with the id:
The domains field takes the list of hostnames the workload serves.
To create the CNAME record, send a POST request to the records of the zone. Replace <zone-id> with the id from stage 1:
The API answers 201 with the record. The name is relative to the zone, rdata holds the workload domain, and ttl sets the time to live in seconds. Repeat the request for each hostname the workload serves.
If your account uses Domains with API v3, list your domains:
The response lists each domain with its hostnames in cnames and its Azion domain in domain_name:
Keep the id of the domain and its domain_name. If cnames lists none of your hostnames, send them in a PATCH request. Replace <domain-id> with the id:
To create the CNAME record with API v3, send a POST request to the records of the zone. Replace <zone-id> with the id from stage 1:
In API v3, record_type is the type, entry is the name relative to the zone, and answers_list holds the values. The response returns the record:
A record named * answers every name the zone does not list, so one record can send both www and blog to the workload. For the names a wildcard matches, refer to Match subdomains with a wildcard record.
A record whose name nobody queried before it existed answers within seconds. A change to an existing record can take a few minutes to reach every nameserver. For the reason, refer to How Edge DNS works.
6. Check the domain through a public resolver
A public resolver reaches Azion only through the delegation your registrar publishes. Querying one shows whether the internet already follows the change from stage 4.
To query a public resolver, run:
While the resolver does not follow the delegation yet, the header can read NXDOMAIN with no answer:
The resolver may also return the records of your previous provider. Once it follows the delegation, it returns the same value that ns1.aziondns.net returned in stage 3. If it does not, refer to Public resolvers return NXDOMAIN while Azion’s nameservers answer.
Edge DNS now answers for your domain. From here on, you add and change its records in Edge DNS, not at your previous provider.