An email DNS cutover runbook is the day-of order of operations so a small team does not invent the cut while customers are sending invoices. You verify ownership and create aliases before the window. You publish one MX set during the window. You delete leftovers in the same window. You prove inbound from a mailbox you do not own. You do not keep Google MX “just in case.”
Quick answer for email dns cutover runbook
IETF RFC 5321 — Simple Mail Transfer Protocol delivers to the MX set the public DNS returns. A cutover changes that set. Small businesses fail the change by editing the wrong panel, leaving leftover hosts, testing only from Gmail to Gmail, or announcing the new address before TTL expires. The runbook exists so those four mistakes are scheduled out of the day.
Before the window: authoritative NS known, verification TXT matching in public, named aliases created, unknown held, old MX screenshot from two resolvers, TTL lowered if you can. During: exclusive new MX, leftovers deleted, inbound proof, public lookups looped. After: no phone registrar edits, sending DNS only if you will send, paid SMTP copied from the dashboard—not invented. See troubleshooting, tools, docs, and migration planner.
MailerZ is the receiving host after MX points there. It is not IMAP. Destinations stay Gmail or Outlook. Free cannot send-as. The runbook still applies: inbound can cut on Free; outbound is a later paid step.
Rollback is republishing the screenshot as the only MX set. Adding the old host beside the new one is a new outage with extra steps.
User problem and decision criteria
Cut day without a runbook looks like this: the founder is in a cafe, the contractor is in a registrar app, the designer “helps” by restoring Google email, and the bookkeeper sends a test to themselves. Three people “succeeded.” The vendor on another resolver still hits leftover Microsoft MX. The runbook names one DNS owner, one comms owner, and one proof owner. If you cannot name those three, you are not ready.
Decide the window. Avoid month-end invoicing if billing@ is in scope. Avoid a product launch hour. A Tuesday morning with the DNS owner on a keyboard is better than a Friday evening. Lower TTL the day before if the zone allows it.
Decision criteria: NS panel access live, 2FA on that login, aliases already created, leftover inventory written, customer-facing announcement drafted but not sent, rollback screenshot stored offline, a third mailbox ready for proof.
Criteria that do not belong: dual MX as comfort, changing Gmail MX, buying Workspace seats to “make the cut safer,” or treating a website CNAME as mail cutover.
Agencies should put the runbook in the ticket with checkboxes. Clients will skip steps they do not see. Bill the hour. It is cheaper than the emergency that follows a silent leftover.
Multiple domains in one business get one runbook each. A parked domain that still catch-alls into the founder will not cut just because the primary brand did. List every name that receives mail.
Staff who send as the domain need a second runbook page: paid SMTP after inbound is proven. Do not mix those pages on cut morning. Inbound first.
Technical mail flow
Senders look up MX and connect. During TTL overlap, some caches still have the old set. That is expected. Leftover hosts that remain published after you intended to delete them are not TTL. They are a runbook miss. Distinguish those in the war room: “cache” versus “still in the zone.”
After exclusive MX at MailerZ, named aliases forward to destinations. Envelope SRS only. Headers intact. Unknown held on Free. If aliases were not created before the window, the cut opens a hole. That is why aliases are phase two, not an afterthought.
Sending records do not move inbound. Do not “fix” a quiet inbound queue by editing SPF during the window. Check MX and hop history first.
Open relay remains 550. A panicked WordPress plugin pointed at the new host without a password will not save the cut. It will fail closed. Correct.
Step-by-step setup / decision path
- T-24h or earlier: Confirm NS. Verify TXT in public. Create every printed alias. Hold unknown. Lower TTL if you can. Assign DNS, comms, and proof owners.
- T-1h: Screenshot MX from two public resolvers. Confirm nobody else has the registrar app open. Draft the customer note but do not send it.
- T-0: Publish only the MailerZ MX set from the dashboard. Delete leftover Google, Microsoft, and registrar hosts in the same change.
- T+5m: Public lookup. If leftovers remain, you did not save. Fix the zone, do not add more hosts.
- T+15m: Third-mailbox unique inbound to a named alias. Confirm Header From and hop row. Self-send is forbidden in the runbook.
- Until old TTL: Loop public MX. Do not announce “fully cut” while a public view still shows the old company.
- After proof: Send the customer note if the printed address changed. If only the host changed, most customers need no note.
- T+1d: Lookup again. Check hop history for gaps. Disable phone registrar apps. If send-as is in scope, copy dashboard SMTP on a paid plan as a separate change.
- Rollback trigger: If inbound proof fails and public MX is exclusive to MailerZ, the bug is aliases or destinations—not a reason to dual-publish. If you published the wrong hosts, restore the screenshot exclusively.
Print this list. Digital-only runbooks vanish when the DNS login is on the same laptop that froze. A paper copy is not nostalgia. It is the fallback.
If the DNS owner is on holiday, delay the window. A deputy without 2FA is not a deputy.
Failure modes and proof
Dual MX “safety”: random loss. Proof: two companies in the public set.
Wrong panel: zone unchanged. Proof: public MX equals the screenshot after you “saved.”
Aliases missing: hole. Proof: hop history empty, MX already new.
Self-send: false green. Proof: no third mailbox.
Phone restore Google: leftovers return. Proof: morning lookup.
Announcing during TTL: customers mail a host some resolvers have not learned. Proof: split public views.
SPF panic-edit: inbound still the issue. Proof: you never looked at MX.
Apex CNAME “cut”: mail never moved. Proof: MX lookup unchanged.
Parked domain forgotten: cannon remains. Proof: that name’s MX still old or catch-all.
Free send-as during cut: fails. Proof: plan. Inbound-only is enough for day one.
MailerZ workflow and product boundary
MailerZ is custom-domain aliasing and forwarding with optional paid send-as. Secuno LLC operates mailerz.net. The app is mail.mailerz.net. Not Workspace, not IMAP, not an open relay.
Cutover means exclusive MX to the set the dashboard shows. Envelope SRS inbound. Headers intact. Free: one domain, ten aliases, fourteen-day store, send-as disabled, hold unknown. Solo: forty dollars a year, twenty-five aliases, ninety-day store, 2,500 outgoing, 20 send-as per hour. Starter eight or eighty. Business nineteen or one hundred ninety. Agency thirty-nine or three hundred ninety. Quote pricing.
Copy SMTP host, port, and TLS or STARTTLS only after inbound is stable and the plan is paid. This page does not invent SOC 2, ISO, HIPAA, SLAs, or inboxing rates.
Cost, alternatives, and trade-offs
A two-hour runbook costs less than a week of missing invoices. Consultants who skip public lookups sell theater. Workspace seats do not cut MX for you.
Lowering TTL early is cheap. Dual MX as insurance is expensive in silent loss. Choose the screenshot rollback.
Doing an unscheduled cut during a sale is the expensive version of the same steps. Schedule it.
Agencies should refuse a cut without the three owners named. That refusal is a service.
If you cannot lower TTL, lengthen the watch window. Time is the substitute. Do not skip the loop.
After the cut, leftover registrar “email forwarding” products may still bill you. Cancel them so nobody republishes their MX to “fix billing.”
Shared calendars and Slack huddles are not a status page. Put the runbook phase in a single written channel so the bookkeeper does not start a parallel cut in a second registrar login. One window, one zone, one writer.
If a customer insists they sent mail during TTL overlap, ask for the UTC time and their resolver if they know it. Compare to your public lookup log. You may owe a resend, not a dual-MX panic. Document that difference so the next cut does not regress.
Night-of monitoring is a person, not a hope. Assign who looks at hop history at T+3h. An unowned watch is how a leftover returns at 11pm and nobody sees it until Monday invoices bounce.
T-minus calendar a three-person shop can run
T-minus seven: write the printed aliases, the destination Gmails, and the human who can edit the real nameservers. Query two public resolvers and paste both MX answers into the ticket. If they already disagree, you do not have a cutover problem yet. You have a zone you do not understand. Fix NS ownership before you pick a Friday window.
T-minus five: add the MailerZ domain, publish verification TXT, create every named local-part you still print. Free is ten aliases. Solo is twenty-five. Starter is fifty. A cutover that “includes catch-all FORWARD so we do not forget names” is not a runbook. It is a missing map. HOLD on Free will show the names you skipped. Create them before MX moves.
T-minus three: lower MX TTL if the current TTL is a day or more and you can wait out the old value. Lowering TTL after you already published leftovers does not help. You still wait the old clock. Screenshot the old exclusive set — or the leftover set you are about to delete — so rollback is paste, not memory.
T-minus one: freeze website CNAME edits, SPF experiments, and registrar “free professional email” wizards. One object tomorrow. Tell the bookkeeper the registrar app stays closed. A parallel cut from a phone is how aspmx returns at 4 p.m.
Cut hour: publish exclusive MailerZ MX from the dashboard. Delete leftover Google, Microsoft, ImprovMX, registrar, and lone-dot null MX if you intend to receive. Same window. Dual MX is leftover MX. Priority 20 “backup” is leftover MX. Two public resolvers should show one owner as soon as they agree.
T-plus fifteen minutes: probe from another mailbox. Unique subject per critical alias. Open hop history. Empty is leftover or a name that never arrived. HOLD is a missing alias on Free. 250 then destination 5xx is Gmail or Outlook. Copy the SMTP line. Do not restore Google MX because one phone is slow.
T-plus one old TTL: loop the two resolvers until they match the exclusive set. Then tell customers the cut happened. Announcing during disagreement trains people to restore leftovers when a single sender is still cached.
Rollback is the screenshot of the previous exclusive owner, not a hybrid. If you must roll back, you republish that set and delete MailerZ MX. You do not run both. Probe again from another mailbox. Self-send still lies after rollback.
Send-as waits. Free cannot send. Paid SMTP 550 is plan and identity, not a failed cut. Do not rotate SPF in the cut hour. One include for the hop that will send, swapped after inbound is green.
Night watch: one named human reads history at T+3h. Unowned watch is how a leftover returns after dinner. Put the phase in one channel. Slack huddles are not the runbook.
Small-business failure stories that are really leftover MX
A bakery published MailerZ MX and left aspmx “until we are sure.” Half of catering requests hit a Google Group nobody opened. History looked random. They deleted leftovers. The next Friday was boring. Sure comes from probes, not from two owners.
A dentist used Gmail-to-Gmail as the go-live test. It “worked.” Patients on Outlook never arrived. Exclusive MX was never exclusive. A Proton probe would have shown empty history the same hour.
An agency cut four client zones in one window. One zone still had registrar MX. That client’s invoices vanished from MailerZ. One domain per window. Agency caps (100 domains, 500 aliases, 50 seats) do not make a blended cut safer.
A founder enabled paid FORWARD on cut day to “match the old catch-all.” They could not tell HOLD misses from real misses. Named aliases first. FORWARD is a later paid choice.
Finance cancelled the old forwarder the same morning as MX. Logs died. Keep the old login a week. Delete its MX at cut. Cancel after probes. That keep is a library card, not a second post office.
Someone edited SPF and MX together. Permerror plus leftover. They undid SPF, finished exclusive MX, then swapped the include when send-as actually moved. Causality returned.
Calendar was the excuse for leftover aspmx. Consumer Google Calendar never needed Workspace MX. They deleted aspmx. Invites still worked. Drive still worked if they paid Google for Drive without mail MX.
TTL theater: they waited 48 hours while two resolvers already agreed on leftovers. Waiting is not a runbook step when the zone is wrong. Edit. Then wait only remaining TTL after a correct exclusive publish.
Start free on a spare domain if the team has never cut MX. Practice TXT, three aliases, exclusive publish, stranger probe. Then run the same card on the invoice domain. Night CTA: start free — one domain. Sign in when the hop already exists.
Product facts stay on the card: Secuno LLC, envelope SRS only, Header From intact, not IMAP, not an open relay, no SOC 2, no inbox SLA. /pricing for caps. /security for controls. The runbook does not grow Vault.
Who speaks, who edits, and who stays off the registrar
A cutover fails more often from two writers than from a wrong priority number. Name three seats before the window: the person who can publish MX on the real nameservers, the person who owns MailerZ aliases, and the person who talks to customers if a probe fails. If two of those seats are the same human, write that down. If they are three different people, they need one ticket, not three Slack threads that diverge at 3 p.m.
The registrar phone app is the fourth writer you forgot to fire. Apple Wallet, saved passwords, and “free professional email” banners will republish aspmx while you are proving inbound. The runbook is not complete until the bookkeeper’s phone is in a drawer for the window. That is not drama. That is how leftover MX returns after you already deleted it at a desktop.
Customer language during a cut is not “we are migrating email.” That phrase makes people restore Google MX from a five-year-old screenshot. Say: the brand domain now answers at one hop. Invoices still land in the same Gmail. If you sent something in the last hour and it is missing, resend. Do not ask them to change their address book. Do not ask them to wait two days for “DNS to settle” if two public resolvers already agree. Waiting after agreement is superstition.
Vendor tickets are a trap. Google Workspace support will tell you to add aspmx because that is their runbook. Microsoft will tell you to add outlook MX. The old forwarder will tell you to keep their MX as backup. None of those tickets own your printed aliases. File them after exclusive MX is green if you need to cancel a seat. Do not file them at T-minus one as a “just in case.” Just in case is leftover MX with a ticket number.
After-hours is a named human with hop history open, not a hope that nobody invoices on Friday night. If the shop closes at six, the watch still exists at nine. Empty history after a stranger probe is leftover or a name that never existed. HOLD is a missing alias on Free. Destination 5xx is Gmail or Outlook rejecting. Those three are different restores. Mixing them is how people republish Google MX because a mailbox is full.
Print the alias map the night before. Local-part, destination mailbox, who answers the phone if that inbox is quiet. Free allows three named aliases. If you still print six names, you do not have a cutover problem. You have a plan problem. Create the three that invoices use, or upgrade before MX moves. Catch-all FORWARD on cut day hides the map. HOLD on Free shows the map. Prefer the map.
Website and mail share a zone more often than founders admit. A marketing intern who “fixes the www CNAME” during the window can open a registrar wizard that also offers mail. Freeze non-mail records for the hour. If the site must change, change it tomorrow. One object in the zone is how you keep causality. Two objects is how you get a CNAME at the apex and a vanished MX.
Proof is a mailbox you do not own. A Proton, Outlook.com, or a colleague’s personal Gmail that is not the destination. Unique subject per alias. Timestamp in UTC. Screenshot the hop. Self-send from the destination Gmail to the alias that forwards back to the same Gmail is not proof. It never was. It will not become proof after you add a third section to this article.
Rollback language belongs on the same card as cut language. Rollback is the exclusive screenshot from T-minus three, republished, MailerZ MX deleted. It is not dual MX. It is not “leave both until Monday.” If you roll back, you probe again from the stranger mailbox. Then you schedule a second window. Two exclusive owners in sequence is a runbook. Two owners at once is leftover MX with better lighting.
Send-as is not a cutover step. Free cannot send. Paid SMTP 550 is identity and plan, not inbound failure. SPF rotation waits until exclusive MX is green and probes land. One v=spf1. One include for the hop that will send. Do not add a second v=spf1 because a blog said Google needs its own record. That blog is why this site has a duplicate-SPF article.
Agency seats do not change the physics. One hundred domains and five hundred aliases do not make a blended Friday safer. One client zone per window. One leftover scan per zone. One stranger probe per printed alias that invoices use. The Agency card is a cap, not a permission to parallel-cut four bakeries.
Product facts stay boring on purpose. Secuno LLC. Envelope SRS only. Header From never rewritten. Not IMAP. Not an open relay. No SOC 2 claimed here. No inbox SLA. Fourteen-day store on Free, ninety on paid. Start free is one domain and ten aliases. Sign in when the hop already exists. The runbook does not grow Vault into a mailbox host.
If the team has never cut MX, spend a week on a spare domain. Practice verification TXT, three aliases, exclusive publish, stranger probe, leftover delete. Then run the same card on the invoice domain. Practice is cheaper than a dual-MX Friday and a bookkeeper who learned the registrar app.
FAQ
- What is the safest way to handle email dns cutover runbook?
- Verify TXT and create named aliases before cut day. Lower TTL if you can. On the day: screenshot old MX from two public resolvers, publish one new set, delete leftovers immediately, prove inbound from a third mailbox, loop lookups until public views agree. Rollback is the old exclusive screenshot, not dual MX. Phone registrar apps stay off.
- Does this require a new mailbox?
- No. A cutover moves which host answers MX. Destinations stay Gmail or Outlook. MailerZ is not IMAP. Buying seats does not replace exclusive MX.
- Will it work with Gmail or Outlook?
- Yes as destination inboxes after the brand domain’s MX points at the alias service. You do not change Gmail or Outlook MX. You change the custom domain only.
- What DNS records are involved?
- NS to know the real panel, verification TXT before cut day, exclusive MX on cut day, leftover host deletion, and sending SPF/DKIM/DMARC if you also send. CNAME at the apex is not a mail cut.
- What should I test before production?
- Before cut day: public TXT match and aliases created. After MX: unique inbound from a third mailbox plus two public MX lookups with no leftover company names. Self-send from Gmail to Gmail is not the test. Watch one old TTL before you announce the cut to customers.
Key takeaways
- An email DNS cutover runbook is verify and aliases first, exclusive MX second, proof third, TTL watch fourth.
- Name DNS, comms, and proof owners. No phone registrar apps.
- Screenshot old MX from two public resolvers. Rollback is exclusive restore.
- Do not dual-publish old and new providers.
- Self-send is not in the runbook. Use a third mailbox.
- Do not announce while public views still disagree.
- Inbound cut is separate from paid send-as.
- MailerZ receives only after MX actually points there.
Conclusion
Write the order before the window. Verify, name aliases, publish one MX set, delete leftovers, prove inbound, watch TTL. Comfort dual-MX is how small businesses lose mail and still think they were careful.
Complete TXT and aliases on MailerZ first, then run this cutover when the DNS owner is at a keyboard.