Blog
Writing on billing, provisioning and hosting.
- DNS4 min read
Turning DNSSEC off is the dangerous direction
Switching DNSSEC off feels like the safe, cautious move. Done in the obvious order, it takes the whole domain down for everyone whose resolver checks signatures.
Kostalbreeze · 10 October 2026 - DNS5 min read
Your domain's transfer code is a password
The auth code that moves a domain between registrars is a credential, not a reference number. Keep it out of links and chats, and get the DNS ready before you use it.
Kostalbreeze · 10 October 2026 - DNS4 min read
Lower the TTL the day before the move, not on the day
A DNS change reaches the nameservers instantly. What you actually wait for is the old record expiring from other people's caches — and by the time you are cutting over, it is too late to shorten that wait.
Kostalbreeze · 20 September 2026 - DNS4 min read
Publishing a DS record before the zone is signed takes the whole domain down
DNSSEC fails closed. Get the order wrong and the domain does not degrade or slow down — it stops resolving entirely, for everyone using a validating resolver, and you cannot take it back quickly.
Kostalbreeze · 20 September 2026





