Domains & DNS
Change DNS anywhere, from one place
Move a domain’s DNS, change a record, or turn on DNSSEC without touching two control panels. InfraNest connects to your registrar and your DNS provider at the same time — so it can copy your existing records across, point the nameservers at the new zone, and tell you the moment anything changes behind your back.
Free plan · No credit card · Connect a provider in 2 minutes
- All your providers, one editor
- Move DNS without the copy-paste
- Told the moment something changes
- Email security in one click
Works with your DNS providers
Move your DNS without the scary part
Switching DNS provider normally means copying every record by hand into a new panel, then changing the nameservers and hoping you didn’t miss one — because a record left behind takes your website or your email down. InfraNest does both halves. It reads the records your domain is answering with right now, creates the zone at the new provider with all of them already in place, and points the nameservers there for you. You never retype a record.
- Records found automatically from your live DNS, or copied from a connected provider
- Or upload a zone file from anywhere — it shows what will import, and every line it had to skip, before it writes anything
- Nameservers updated at your registrar in the same step, because InfraNest holds both accounts
- Do it once by hand, or let a rule do all of it every time a domain arrives
- Nothing is overwritten, and you can stop before the switch
Which domain do you want to manage DNS for?
Domain name
northwind.org
Found in your account
How do you want to set up DNS for northwind.org?
Where should the new DNS zone be created for northwind.org?
8 connected accounts can’t host a new zone
We will scan the DNS records for northwind.org and import them into your new zone. You can review and edit records after this step.
Linked to northwind.org in your account.
Zone will be added to:Hetzner
Nameservers that will be set:
hydrogen.ns.hetzner.comhelium.ns.hetzner.deoxygen.ns.hetzner.comOne editor, every provider
Twelve providers, one way of working. The form knows what each record type needs and fills in what it can from your own servers and the mail providers you already use. It checks as you type, so a private IP on a public record or a malformed SPF line gets caught here — rather than three days later, when someone mentions the email stopped arriving.
- The right fields for the record type, validated as you type
- Suggestions drawn from your own servers and common mail providers
- Point an A or AAAA record at a Dynamic IP and it follows a changing address
- A note on any record explaining why it exists — visible only to you, never published
7 records at Cloudflare · read from the provider 15m ago
The website5 record(s)
Email1 record(s)
Verification1 record(s)
A2 record(s)
AAAA1 record(s)
CNAME2 record(s)
TXT2 record(s)
Know when something changes behind your back
Most DNS problems start with a change nobody remembers making — a colleague in the provider’s panel, a plugin, an old script. InfraNest keeps asking the public internet what your domain answers, and compares it to what it has on file. When those stop matching you are told straight away — by email, Slack, Teams, Discord, Telegram or PagerDuty — with the exact record that changed and a button to put it back. Or skip the button: an automation can put it back for you, open a ticket and post to your status page, while you are still asleep.
- Checked against public resolvers, not just your provider’s API
- The record that differs, what it says now, and what you had
- Keep the new value or restore yours — one record at a time, not all or nothing
- Or let an automation react for you, the moment it happens
- Every change recorded in your audit log, with who did it and when
Email security and DNSSEC, without the guesswork
SPF, DKIM, DMARC, CAA and DNSSEC decide whether your email arrives and whether anyone can pretend to be you. All five are normally hand-typed text that fails silently. InfraNest checks every zone, says in plain words what is missing, and writes the record for you. DNSSEC is the clearest case: it means generating a key at your DNS provider and publishing a fingerprint at your registrar, in that order — the wrong order takes the domain off the internet. InfraNest holds both, so it is one button.
- SPF, DKIM, DMARC and CAA generated correctly, not typed by hand
- DNSSEC switched on across provider and registrar in the only safe order
- Where a provider’s API will not allow it, the exact values and where to paste them
- Only the fixes that will actually work at your provider
Showing your stored records
Verify liveNothing tells receiving servers what to do with mail that fails your checks, so anyone can send as you and it will still land. Based on the records stored here.
What’s working
Your approved senders are listed. Your mail is signed.
What to fix next
- No DMARC record — nothing tells receivers what to do with failures. Add DMARC, monitor first
- Your SPF ends in ~all, a soft fail most servers deliver anyway. Make it strict
Show 4 passedHide passed
Everything else it handles
The parts that are only interesting when you need them.
Templates, built-in and your own
Apply Google Workspace, Microsoft 365 or a security baseline in one click — or save any zone as a template and reuse it. A diff preview shows every record that will be written first.
Zone files in and out
Download any zone as a standard BIND file, or import one. It lists what will be added, what already exists and every line it had to skip — and only ever adds.
Audit log
Every record change recorded with who made it and when, including the ones InfraNest made on your behalf.
Dynamic IP tracking
Tick “Track with a Dynamic IP” and an A or AAAA record follows a changing address. Your router reports it once; InfraNest updates every record that depends on it.
Delegation check
Tells you whether the internet is actually asking this provider for your domain, or whether your registrar still points somewhere else.
Zone cost tracking
Most zones are free; set a price on the ones that are not, like Route 53, and they appear in your running infrastructure cost.
See your own zones in about two minutes
Connect one provider with an API key. Nothing changes at the provider until you edit a record.
Managing DNS by hand vs InfraNest
The difference between DNS that merely works and DNS you can actually trust.
By hand
- A different control panel for every provider
- Retype every record by hand when you move a domain
- Nobody finds out when a record changes until something breaks
- Hand-type SPF and DMARC and hope you got it right
- DNSSEC means copying a key between two panels in the right order
With InfraNest
- Every provider in one editor that checks what you type
- Records copied across and nameservers switched in one step
- An alert the moment the internet answers differently
- Email records written for you, and re-checked on every zone
- DNSSEC is a button, because InfraNest holds both accounts
One login, ten modules
Every module is in every plan, Free included — what changes is how much of each you get.
The cost of doing it separately
Buy each piece from a different tool and it adds up fast:
- Domain & DNS
- ~€30
- Uptime monitoring
- ~€29
- SSL tracking
- ~€15
- Status page
- ~€29
- Server panel
- ~€15
- Across 4–5 separate tools
- €100–150/mo
Frequently asked
Which DNS providers work with InfraNest?
Cloudflare, AWS Route 53, Hetzner, DigitalOcean, IONOS, TransIP, GoDaddy, Namecheap, OVH, Porkbun, Dynadot and Openprovider, with more added regularly. The integrations page lists exactly what each provider’s API supports.
Do I have to move my DNS to InfraNest?
No. InfraNest edits your zones where they already are — nameservers stay with your provider and nothing is migrated. You just get one editor over all of them instead of a panel each.
Will connecting InfraNest break my site?
No. Connecting a provider only reads your zones, and nothing at the provider changes until you edit a record. Imports only ever add records, nothing is overwritten, and you can disconnect the key at any time.
What happens if a record changes outside InfraNest?
InfraNest keeps checking what public resolvers answer for your domain against what it holds. When they disagree it alerts you — by email, Slack, Teams, Discord, Telegram or PagerDuty — shows the exact record and what each side says, and lets you keep the new value or restore yours.
Can I move a domain’s DNS to another provider?
Yes, and it is the case InfraNest is built for. It reads the records your domain answers with today, creates the zone at the new provider with those records already in place, and — because it is connected to your registrar too — points the nameservers at it in the same step.
Can any of this run automatically?
Yes. DNS is wired into InfraNest’s automations, so a rule can create the zone, point the nameservers at it and apply a template the moment a domain is added — and react on its own when a record changes out of band, by restoring it, opening a ticket or posting to your status page. You set it up once and stop thinking about it.
Can I apply DNS templates?
Yes — built-in presets for Google Workspace, Microsoft 365 and security baselines, plus any template you save from a zone of your own. A diff preview shows every record that will be written, and flags anything it would replace, before anything changes.
Every record, in sync
Connect a provider and edit the zones you already have.
Free plan · No credit card required · Set up in minutes