Move my domain's DNS to Cloudflare without breaking anything

The ordinary way to connect a bernard site is smaller than a DNS move: add the records shown on the Custom domain page and leave the nameservers and registration alone. That remains the simplest route for most people. See Connect my own web address (domain) to my site.

Moving DNS is useful when you want the domain's directions in your own Cloudflare account. Your website, email and registration do not move with it. The aim is a controlled change with evidence and a rollback route, not a promise that nothing could ever go wrong.

If the terms are unfamiliar, What do domain names, DNS and nameservers actually mean? explains who does what.

Start with the ready-made task

Open Manage my domain, choose Move my DNS to Cloudflare, and ask:

Check the DNS move for my domain. Change nothing. Tell me the one thing I should do next.

bernard checks public evidence for the current DNS provider, website, email and DNSSEC. The result must lead with:

  1. one plain-English verdict;
  2. confirmation that the check changed nothing;
  3. one next action.

This is an assessment, not a disguised setup button. It does not create a Cloudflare zone, import or edit records, change nameservers, transfer the registration or start a charge.

An account owner can Connect Cloudflare to bernard without giving it control of my DNS with Zone Read when you want bernard to confirm that this exact domain is visible in the Cloudflare account you chose. The later managed inventory step asks separately for DNS Read before comparing the existing Cloudflare record list. Neither permission can make a change, and Cloudflare cannot reveal records that were missed before the zone reached it, so the complete source export or screenshots remain essential.

It will not tell you to change nameservers from public evidence alone. Public DNS cannot list every private record held by the old provider, so a saved copy of the old records is still required.

The move in six small steps

Complete one step, then check before continuing.

  1. Save the old map. Export the DNS zone, or take complete screenshots of every record. Save the old nameserver addresses outside the provider account.
  2. Add the domain to your own Cloudflare account. Use an email address you control and never paste your password into chat.
  3. Compare the records and cloud icons. Cloudflare's scan is a starting point. Cloudflare warns that it may miss records, so match its list against the export or screenshots. Check each record's name, type, value and proxy setting. Leave mail, verification and other service records as DNS only. Turn the orange-cloud proxy on only for website records you have deliberately identified. Cloudflare's setup guidance explains that DNS-only records return their original value and recommends DNS only for third-party verification CNAMEs.
  4. Clear the stop signs. Do not continue while any record is unexplained, DNSSEC's old security link is still present, or the DNSSEC result is unknown.
  5. Change nameservers once. Enter Cloudflare's assigned nameservers at the registrar. Leave the old DNS account and records untouched.
  6. Check every named service. Check the site with and without www, the security certificate, sending and receiving email, and every shop, booking, newsletter, login or unusual subdomain you named. Then complete Cloudflare DNSSEC and verify it publicly.

Cloudflare's official full setup guide explains the nameserver and DNSSEC parts. bernard should guide one current step at a time instead of giving you the whole technical checklist at once.

What can stop the move?

bernard pauses the journey for three reasons:

  • The old record map is incomplete. A missing mail, booking or verification record can break that service even while the website looks fine.
  • DNSSEC is still tied to the old provider. Changing nameservers while its old security link, called a DS record, remains can make the domain disappear.
  • A service is unexplained. Every known email system, shop, booking tool, newsletter, login and non-www address needs a matching record or an explicit decision to retire it.

If evidence is missing, stop at the current step, resolve the named gap and run the check again.

If something stops working

Do not delete records at random. Compare the failing service with the saved old map and restore the missing record in Cloudflare.

If the whole domain fails, check the registrar's nameservers and DNSSEC DS record first. Restoring the old nameservers may provide a manual rollback while the old provider still serves the old zone, but caches mean it is not instant. Keep both accounts accessible until the website, email and every named service have been checked.

Do not cancel the old registrar, hosting or email plan just because DNS works. First name what each subscription still supplies.

I have several domains. Should I move them all?

Usually, yes, for domains you intend to keep. One customer-owned Cloudflare account gives you one place to manage DNS. Moving an eligible registration later may save money, but only after you compare its current renewal and attached services. bernard is intended to manage all the domains you authorise once managed migration support is live.

Move them one at a time, starting with a domain that has the fewest services. Each domain gets its own record map, DNSSEC check, approval, test and rollback evidence. A problem on one domain must never advance or block another.

Today one read-only Cloudflare connection can check the exact domain attached to each bernard site in the selected account. You still make Cloudflare and registrar changes yourself. Moving registration is a separate customer-operated step covered in Move my domain registration to Cloudflare.

The prompt

Check the DNS move for [my domain]. Change nothing. Tell me the one thing I should do next.

Press Copy, then paste it into your AI and fill in the [bracketed] parts. First time? Connect your AI to bernard first - a one-time setup in bernard → your site → Use your own AI.

Questions people ask

Is moving DNS to Cloudflare the same as transferring my domain?
No. Moving DNS changes where the domain's directions are kept. Registration and renewal stay with the current registrar unless you later choose a separate transfer.
Will my email address or mailboxes move?
No. Your email provider, addresses and mailboxes stay where they are. Their DNS records must be copied correctly, so bernard checks email as a named service rather than assuming the website is the whole domain.
Can bernard make the Cloudflare and nameserver changes for me today?
Not yet. An account owner can connect Cloudflare with Zone Read, which lets bernard find this exact domain. When the managed inventory step is available, bernard asks separately for the owner's approval of DNS Read so it can compare the records already there. Neither permission allows edits. Bernard still cannot create a zone, change DNS, change nameservers, transfer registration or start a charge.
Can I undo the move?
Often, by restoring the old nameservers while the old provider still serves the saved zone. That is a manual rollback route, not an instant undo button, so keep the old account, old nameservers and record copy until every service has been checked.
I have several domains. Should I move them all to Cloudflare?
Yes, usually, for domains you intend to keep. One account can reduce complexity and eligible registration transfers may reduce renewal costs. One read-only connection lets bernard check each exact domain today, and bernard is designed to manage them all as the later migration capability arrives. Move one domain at a time because each can carry different email and services.

You might also want to…