Managed DNS

DNS you don’t have to be afraid of.

One wrong record takes down a website, a mail flow, or both — usually at the worst possible moment. We hold your zone, plan every change against what already depends on it, and verify the result instead of hoping.

  • A, AAAA, CNAME, MX, TXT, SPF, DKIM, and DMARC records managed for you
  • Every change checked before it is made and verified after it is live
  • Your own DNS management area in the client portal, whenever you want it
  • The same team holds your domain, website, and mailboxes — no vendor standoffs

Talk to us about your DNS Mistakes we prevent

Hand your DNS to someone who checks

Tell us what your domain is doing today and we’ll reply with the right next step and a written quote within 24 hours.

What managed DNS means with us

Not a control panel login and good luck. Someone owns the correctness of your zone, and that someone is us.

Records created and maintained

A and AAAA records pointing at your site, CNAMEs for the tools that need them, MX records for mail, and TXT records for the platforms that ask you to prove ownership. Written correctly the first time, and kept accurate as your stack changes.

Checked before

Before anything is edited we read the current zone and work out what depends on it — the website, the mailboxes, the analytics tool, the payment provider, the thing somebody set up in 2021 and forgot. Changes are planned against reality, not a template.

Verified after

Once a change is live we query it back, confirm mail still flows, and confirm authentication still passes. Propagation typically completes within hours; we check rather than assume, and we tell you when it is confirmed.

Who this is for

Nobody buys managed DNS because they find DNS interesting. They buy it because of what happened last time.

It broke once already

A developer swapped a record, a platform asked for a change, and the site or the email went down with it. You want the next change made by someone who knows what else is in the zone before they touch it.

Agencies juggling client zones

A dozen client domains, each with different hosting, mail, and sending tools behind them. Managed DNS gives you one place to ask and a documented record set per zone, so nobody reverse-engineers a client’s setup mid-incident.

Anyone mid-migration

New host, new mail platform, new sending tool — migrations are where DNS mistakes get expensive, because the change window is short and several records move at once. We sequence it and hold the pre-change state.

See email migration →

Email authentication, done properly

Most DNS problems that cost real money are mail problems. Deliverability is our specialty, so authentication records get treated as engineering, not paperwork.

One valid SPF record

A domain may publish exactly one SPF record. We consolidate every service that legitimately sends as you into that single record, and keep it inside the lookup limits that quietly break it once you exceed them.

DKIM per sending platform

Every platform that sends on your behalf gets its own signing key published on its own selector. Add a new tool later and it gets its own key too, rather than being quietly unauthenticated.

DMARC that matches reality

A policy set to what you actually send, with reporting turned on so you can see who else is using your domain. We move the policy up as the evidence supports it, not on day one because it looks strict.

See email deliverability

Your own DNS management area

Clients get a login at portal.tkwebhosts.com with their own DNS management area alongside invoices, services, and support tickets. Look at your records whenever you like, edit them if you want to, or leave the whole thing to us.

Self-serve when you want it, done-for-you when you don’t. What you never get is a zone held hostage by an agency that will not give you access to your own domain.

Written record of every change

You get the fix and the paperwork: what was changed, why it was changed, and what to watch afterwards. Changes are confirmed in writing rather than mentioned in passing on a call.

If you ever replace us, your next provider inherits documentation instead of archaeology — which is the same standard we would want inheriting somebody else’s domain.

Common DNS mistakes we prevent

None of these are exotic. All of them are things we have been called in to undo.

TTL left long before a cutover

A record with a long time-to-live is cached by resolvers around the world for that long. Change it on the day and some visitors keep hitting the old server for hours. Lowering the TTL days ahead of a planned move costs nothing and shortens the switch dramatically.

Orphaned records left behind

Subdomains pointing at servers that no longer exist, CNAMEs for tools that were cancelled, verification strings from trials nobody finished. At best clutter; at worst traffic or mail directed somewhere you no longer control.

Conflicting SPF strings

Two SPF records on one domain is not twice the protection — it is an invalid configuration that receivers may fail outright. It happens whenever a new platform tells you to “add this record” and nobody merges it into the existing one.

Nameservers changed without the zone

Pointing a domain at a new provider without recreating the records first empties the zone in one step. The website disappears and mail stops, and the fix is rebuilding from memory unless someone kept a copy.

MX records edited by a web developer

A website move that rewrites the whole zone often takes the mail records with it. Site and mail are separate systems that share one namespace, and the person changing one rarely knows what the other depends on.

Records nobody documented

The most expensive DNS problem is not a wrong record, it is an undocumented one. When nobody knows why an entry exists, it survives cleanups it should not and gets deleted in cleanups it should have survived.

Managed DNS FAQs

What is managed DNS?

Managed DNS means someone else owns the correctness of your zone. We hold the current record set for your domain, plan every change against what already depends on it, make the change, and verify the result. You get a named contact for DNS instead of a control panel you open twice a year and hope you remember.

Do I have to move my domain to you?

Usually not. DNS management can often be delivered without changing registrar, as long as the current account gives us the access we need. If the existing setup makes that impractical we will tell you why, and what moving would involve, before anything changes. See domains and DNS.

How long does a DNS change take to take effect?

Propagation typically completes within hours, and often much faster when the record’s TTL has been lowered in advance. It is not instant everywhere at once, because resolvers around the world hold cached copies for different lengths of time. We verify each change once it is live rather than assuming it worked.

Can I still make my own changes?

Yes. Clients get their own DNS management area in the client portal at portal.tkwebhosts.com, so you can look at your records or edit them whenever you want. Self-serve when you want it, done-for-you when you don’t — and you are never locked out of your own zone.

My website is hosted elsewhere. Does that matter?

No. DNS is a separate layer from where your site or mail is actually hosted, and we routinely manage records that point at other people’s infrastructure. Your website, mailboxes, and third-party tools can each live wherever they live — the zone just has to point at them correctly.

Will my email break while you change DNS?

That is exactly what the process is designed to avoid. Existing mail routing and authentication records are recorded and validated before anything is edited, mail-affecting changes are sequenced deliberately, and we verify delivery after the change rather than waiting for someone to report a bounce.

Do you handle SPF, DKIM, and DMARC?

Yes — email authentication is our specialty, not a side effect. We publish a single valid SPF record covering every service that legitimately sends as you, add DKIM keys for each sending platform, and set a DMARC policy that matches how you actually send rather than a copied default.

What is an orphaned record and why does it matter?

An orphaned record points at something that no longer exists — an old server, a cancelled tool, a subdomain from a project that ended. At best it is clutter. At worst it sends traffic or mail somewhere you no longer control, or contributes to an SPF record that quietly stops working. We find them and remove them deliberately, with a record of what was removed.

Can you manage DNS across several domains or client accounts?

Yes. Agencies and multi-brand businesses are a common fit — several zones, different hosting and mail arrangements behind each, and one place to ask. Each zone keeps its own documented record set so nobody has to reverse-engineer a client’s setup during an incident.

What happens if something goes wrong after a change?

We hold the pre-change state, so reverting is a known operation rather than a reconstruction. Because we make the change we also own the diagnosis, which is the practical difference between one fix and a conference call between three vendors.

Do I get a record of what changed?

Yes. You get written confirmation of what was changed, why, and what to watch. If you ever replace us, your next provider inherits documentation instead of archaeology.

Stop editing your zone with your fingers crossed.

Tell us what your domain is doing today — you’ll get the right next step and a written quote within 24 hours.

Request a Written Quote