InfraNestInfraNest

Domains & DNS

Change DNS anywhere, from one place

Move a domain’s DNS, change a record, or turn on DNSSEC without touching two control panels. InfraNest connects to your registrar and your DNS provider at the same time — so it can copy your existing records across, point the nameservers at the new zone, and tell you the moment anything changes behind your back.

Free plan · No credit card · Connect a provider in 2 minutes

  • All your providers, one editor
  • Move DNS without the copy-paste
  • Told the moment something changes
  • Email security in one click
DNSManage DNS records across all your zones and provider accounts.+ Add zone
ZoneSecurityRecords
northwind-api.devPendingOpenprovider · 7 records · synced 2h ago7
northwind-app.devCloudflare · 7 records · synced 15m ago7
northwind-docs.comCloudflare · 7 records · synced 37m ago7
northwind-mail.comTransIP · 8 records · synced 10m ago8
northwind.cloudHetzner · 4 records · synced 54m ago4
northwind.comCloudflare · 7 records · synced 15m ago7
Showing 6 of 13 zones
northwind-app.devCloudflare · 7 records · synced 15m ago7
northwind-docs.comCloudflare · 7 records · synced 37m ago7
northwind.comCloudflare · 7 records · synced 15m ago7
northwind.ioCloudflare · 7 records · synced 15m ago7
nwcloud.coCloudflare · 4 records · synced 15m ago4
nwcloud.ioDynadot · 4 records · synced 4h ago4
northwind.cloudHetzner · 4 records · synced 54m ago4
northwind.deHetzner · 7 records · synced 54m ago7
northwind-api.devPendingOpenprovider · 7 records · synced 2h ago7
northwind.euOpenprovider · 7 records · synced 2h ago7
northwind.shopPorkbun · 7 records · synced 2h ago7
northwind-mail.comTransIP · 8 records · synced 10m ago8
northwind.nlTransIP · 7 records · synced 10m ago7

Works with your DNS providers

HetznerCloudflareTransIPGoDaddyIONOSNamecheapAmazon AWSDynadotDigitalOceanOVHcloudPorkbunOpenProvider

See all 30 integrations →

Move your DNS without the scary part

Switching DNS provider normally means copying every record by hand into a new panel, then changing the nameservers and hoping you didn’t miss one — because a record left behind takes your website or your email down. InfraNest does both halves. It reads the records your domain is answering with right now, creates the zone at the new provider with all of them already in place, and points the nameservers there for you. You never retype a record.

  • Records found automatically from your live DNS, or copied from a connected provider
  • Or upload a zone file from anywhere — it shows what will import, and every line it had to skip, before it writes anything
  • Nameservers updated at your registrar in the same step, because InfraNest holds both accounts
  • Do it once by hand, or let a rule do all of it every time a domain arrives
  • Nothing is overwritten, and you can stop before the switch
Add a DNS zone

Which domain do you want to manage DNS for?

Domain name

northwind.org

Found in your account

Cancel

How do you want to set up DNS for northwind.org?

Copy from a connected providerRecommendedCopy the current DNS records from Cloudflare. Records will be imported automatically.
Scan DNS records automaticallyQuery the domain’s live DNS servers to discover and import all current records.
Manually enter DNS recordsAdvancedYou can add DNS records manually after setup.
Upload a DNS zone fileImport records from a BIND format zone file.
Add DNS Record based on a TemplateStart with a pre-built template of common DNS records.

Where should the new DNS zone be created for northwind.org?

HetznerHetzner — Production
CloudflareCloudflare
DigitalOceanDigitalOcean

8 connected accounts can’t host a new zone

We will scan the DNS records for northwind.org and import them into your new zone. You can review and edit records after this step.

Linked to northwind.org in your account.

Zone will be added to:Hetzner

Also update nameservers at your registrarInfraNest will update the nameservers for northwind.org to point to Hetzner DNS.

Nameservers that will be set:

hydrogen.ns.hetzner.comhelium.ns.hetzner.deoxygen.ns.hetzner.com
Add zone

One editor, every provider

Twelve providers, one way of working. The form knows what each record type needs and fills in what it can from your own servers and the mail providers you already use. It checks as you type, so a private IP on a public record or a malformed SPF line gets caught here — rather than three days later, when someone mentions the email stopped arriving.

  • The right fields for the record type, validated as you type
  • Suggestions drawn from your own servers and common mail providers
  • Point an A or AAAA record at a Dynamic IP and it follows a changing address
  • A note on any record explaining why it exists — visible only to you, never published
northwind.io

7 records at Cloudflare · read from the provider 15m ago

RecordsMail & securityActivitySettings
+ Add record
TypeNameTTL
The website5 record(s)
A@5.75.140.205 min
Awww5.75.140.205 min
AAAA@2a01:4f8:1c1e:9a10::15 min
CNAMEapinorthwind.io5 min
CNAMEappnorthwind.io5 min
Email1 record(s)
TXT@v=spf1 -all1 hour
Verification1 record(s)
TXT_acme-challengenorthwind-demo-validation-token2 min
A2 record(s)
A@5.75.140.205 min
Awww5.75.140.205 min
AAAA1 record(s)
AAAA@2a01:4f8:1c1e:9a10::15 min
CNAME2 record(s)
CNAMEapinorthwind.io5 min
CNAMEappnorthwind.io5 min
TXT2 record(s)
TXT@v=spf1 -all1 hour
TXT_acme-challengenorthwind-demo-validation-token2 min

Know when something changes behind your back

Most DNS problems start with a change nobody remembers making — a colleague in the provider’s panel, a plugin, an old script. InfraNest keeps asking the public internet what your domain answers, and compares it to what it has on file. When those stop matching you are told straight away — by email, Slack, Teams, Discord, Telegram or PagerDuty — with the exact record that changed and a button to put it back. Or skip the button: an automation can put it back for you, open a ticket and post to your status page, while you are still asleep.

  • Checked against public resolvers, not just your provider’s API
  • The record that differs, what it says now, and what you had
  • Keep the new value or restore yours — one record at a time, not all or nothing
  • Or let an automation react for you, the moment it happens
  • Every change recorded in your audit log, with who did it and when

All 13 zones match what the internet answers

Checked continuously against public resolvers. You hear from us when one stops matching — not when you next think to look.

northwind-app.dev

7 records at Cloudflare · read from the provider 15m ago

Email security and DNSSEC, without the guesswork

SPF, DKIM, DMARC, CAA and DNSSEC decide whether your email arrives and whether anyone can pretend to be you. All five are normally hand-typed text that fails silently. InfraNest checks every zone, says in plain words what is missing, and writes the record for you. DNSSEC is the clearest case: it means generating a key at your DNS provider and publishing a fingerprint at your registrar, in that order — the wrong order takes the domain off the internet. InfraNest holds both, so it is one button.

  • SPF, DKIM, DMARC and CAA generated correctly, not typed by hand
  • DNSSEC switched on across provider and registrar in the only safe order
  • Where a provider’s API will not allow it, the exact values and where to paste them
  • Only the fixes that will actually work at your provider

Showing your stored records

Verify live
Email deliverability
Spoofable

Nothing tells receiving servers what to do with mail that fails your checks, so anyone can send as you and it will still land. Based on the records stored here.

What’s working

Your approved senders are listed. Your mail is signed.

What to fix next

2 optional hardening record(s)CAA limits who can issue certificates for you; MTA-STS forces encrypted mail delivery. Neither affects whether someone can send as you.Review
DNSSECDNSSEC is off
Show 4 passed
NSNameservers match provider
Root domainRoot domain resolves
HTTPS redirectHTTP is redirected to HTTPS
TLS versionOnly modern TLS is accepted

Everything else it handles

The parts that are only interesting when you need them.

Templates, built-in and your own

Apply Google Workspace, Microsoft 365 or a security baseline in one click — or save any zone as a template and reuse it. A diff preview shows every record that will be written first.

Zone files in and out

Download any zone as a standard BIND file, or import one. It lists what will be added, what already exists and every line it had to skip — and only ever adds.

Audit log

Every record change recorded with who made it and when, including the ones InfraNest made on your behalf.

Dynamic IP tracking

Tick “Track with a Dynamic IP” and an A or AAAA record follows a changing address. Your router reports it once; InfraNest updates every record that depends on it.

Delegation check

Tells you whether the internet is actually asking this provider for your domain, or whether your registrar still points somewhere else.

Zone cost tracking

Most zones are free; set a price on the ones that are not, like Route 53, and they appear in your running infrastructure cost.

See your own zones in about two minutes

Connect one provider with an API key. Nothing changes at the provider until you edit a record.

Managing DNS by hand vs InfraNest

The difference between DNS that merely works and DNS you can actually trust.

By hand

  • A different control panel for every provider
  • Retype every record by hand when you move a domain
  • Nobody finds out when a record changes until something breaks
  • Hand-type SPF and DMARC and hope you got it right
  • DNSSEC means copying a key between two panels in the right order

With InfraNest

  • Every provider in one editor that checks what you type
  • Records copied across and nameservers switched in one step
  • An alert the moment the internet answers differently
  • Email records written for you, and re-checked on every zone
  • DNSSEC is a button, because InfraNest holds both accounts

One login, ten modules

Every module is in every plan, Free included — what changes is how much of each you get.

The cost of doing it separately

Buy each piece from a different tool and it adds up fast:

Domain & DNS
~€30
Uptime monitoring
~€29
SSL tracking
~€15
Status page
~€29
Server panel
~€15
Across 4–5 separate tools
€100–150/mo
InfraNest Business — all of it, one login€49/mo

Compare all features →

Frequently asked

Which DNS providers work with InfraNest?

Cloudflare, AWS Route 53, Hetzner, DigitalOcean, IONOS, TransIP, GoDaddy, Namecheap, OVH, Porkbun, Dynadot and Openprovider, with more added regularly. The integrations page lists exactly what each provider’s API supports.

Do I have to move my DNS to InfraNest?

No. InfraNest edits your zones where they already are — nameservers stay with your provider and nothing is migrated. You just get one editor over all of them instead of a panel each.

Will connecting InfraNest break my site?

No. Connecting a provider only reads your zones, and nothing at the provider changes until you edit a record. Imports only ever add records, nothing is overwritten, and you can disconnect the key at any time.

What happens if a record changes outside InfraNest?

InfraNest keeps checking what public resolvers answer for your domain against what it holds. When they disagree it alerts you — by email, Slack, Teams, Discord, Telegram or PagerDuty — shows the exact record and what each side says, and lets you keep the new value or restore yours.

Can I move a domain’s DNS to another provider?

Yes, and it is the case InfraNest is built for. It reads the records your domain answers with today, creates the zone at the new provider with those records already in place, and — because it is connected to your registrar too — points the nameservers at it in the same step.

Can any of this run automatically?

Yes. DNS is wired into InfraNest’s automations, so a rule can create the zone, point the nameservers at it and apply a template the moment a domain is added — and react on its own when a record changes out of band, by restoring it, opening a ticket or posting to your status page. You set it up once and stop thinking about it.

Can I apply DNS templates?

Yes — built-in presets for Google Workspace, Microsoft 365 and security baselines, plus any template you save from a zone of your own. A diff preview shows every record that will be written, and flags anything it would replace, before anything changes.

Every record, in sync

Connect a provider and edit the zones you already have.

Free plan · No credit card required · Set up in minutes