Build a comparison point

Record the current DNS zone, TLS names, runtime versions, scheduled jobs, writable paths, database size, mail routes, and external callbacks. Save representative requests and expected responses before copying anything. A backup is useful only after a restore test proves what it contains.

Create the new environment under a temporary hostname or hosts-file entry. Keep production unchanged while files, data, certificates, and background work are tested against the comparison set.

  • Export DNS with TTL values
  • Restore data into an empty destination
  • Replay critical requests
  • Confirm outbound mail and callbacks

Change routing last

Lower TTL only when the migration window is known. Freeze or reconcile writes, take the final data delta, then change the smallest necessary records. Monitor both origins because cached resolvers can send traffic to the old address after the authoritative zone changes.

Rollback means restoring the previous routing while the old origin is still healthy. Do not dismantle it until access logs, application logs, transactions, certificates, and scheduled work show the new path is stable.

Verification checkpoint

Resolve the domain through multiple public resolvers, complete one real transaction, trigger every scheduled job once, and restore the prior route in a rehearsal before closing the rollback window.