Some of the most embarrassing outages have nothing to do with code. A website goes down because a certificate expired at midnight. Email stops working after someone edited a DNS record. A domain lapses because the credit card on file expired and the renewal notices went to a former employee. These failures are entirely preventable, yet they happen to organisations of every size, often because DNS and certificates fall between teams and nobody owns them. This guide explains how the pieces work and how to manage them so they stay boring.

How DNS works, briefly
The Domain Name System translates human-friendly names like example.com into the addresses computers use. Your domain is registered with a registrar, and it points to name servers that hold the DNS records for the domain. Those records say where your website lives, where email should be delivered, and which services are authorised to send mail on your behalf. When someone types your address, resolvers look up the records, caching answers for a period called the time to live (TTL). Because of caching, changes are not instantaneous, and mistakes can persist for hours.

How certificates work, briefly
An SSL/TLS certificate, the padlock in the browser, proves that a server is who it claims to be and enables encrypted connections. Certificates are issued by certificate authorities for specific domain names and are valid for a limited period, which has been getting shorter across the industry to improve security. If a certificate expires, browsers show alarming warnings and many customers will leave; APIs and integrations that connect to your server may fail outright. Certificates must also cover every name in use, including subdomains and the bare domain, and intermediate certificates must be installed correctly.
The common causes of outages
- Expired certificates. A manually installed certificate and a forgotten renewal date. Especially common for internal tools, API endpoints, staging environments and load balancers that nobody remembers.
- Domain expiry. The registration lapses because of an expired card, an unmonitored email address or misplaced ownership. Recovery can be slow, and in the worst case someone else buys the domain.
- Wrong or missing DNS records after a migration, such as pointing the website at the new host but forgetting email records, or deleting a record that something still depends on.
- Long TTLs that make it impossible to switch quickly during an incident.
- Dangling records that point to services you no longer use, which can allow subdomain takeover by attackers who claim the abandoned resource.
- Registrar or DNS account compromise. Someone with access changes name servers and redirects your traffic or intercepts email.
- Single points of failure, such as a single DNS provider without redundancy for a critical business.
Own the domain properly
Register domains in the organisation's name, not an employee's or agency's personal account. Use a role-based email address for contacts that reaches several people, so renewal and transfer notices are never lost. Enable auto-renewal with a valid payment method, and consider renewing critical domains for multiple years. Turn on registrar lock and, where available, registry lock for the most important domains to prevent unauthorised transfers. Protect the registrar and DNS accounts with strong unique passwords, multi-factor authentication and limited access. Keep credentials and recovery information in your password manager. These same principles apply to any vendor that manages your domains for you; you should always have the ability to prove ownership and access it directly. See our note on protecting intellectual property and accounts.
Manage DNS records deliberately
Treat DNS as configuration that deserves the same care as code. Keep an inventory of every record with its purpose and owner. Use a reputable DNS provider with high availability and an API, and consider managing records as code so changes are reviewed and reproducible, as we describe in our infrastructure as code guide. Before migrations and cutovers, lower the TTL a day or two ahead so the change propagates quickly and can be rolled back, then raise it again afterwards. Remove records for services you have retired, both to reduce clutter and to close subdomain takeover risks. Consider adding CAA records so only your chosen certificate authorities can issue certificates for your domain.
Email authentication records
DNS is also how you prove your email is legitimate. Publish an SPF record listing the servers allowed to send mail for your domain, DKIM records so recipients can verify messages were not altered, and a DMARC policy that tells receivers what to do with mail that fails checks and sends you reports. Start DMARC in monitoring mode, review the reports to discover all legitimate senders, then move toward stricter enforcement. Correct configuration protects your brand from spoofing and improves deliverability of transactional and marketing messages; see our notification systems article. Whenever you add a service that sends email on your behalf, update these records.

Automate certificates
The single best improvement is automation. Modern certificate authorities and tools support automated issuance and renewal using standard protocols; your web server, load balancer, CDN or hosting platform can obtain and renew certificates without human intervention, typically well before expiry. With automation, a shorter validity period is a security benefit rather than a burden. Make sure the automation covers every place a certificate is used: public sites, APIs, admin panels, staging, mail servers, VPNs and third-party endpoints. Where automation is not possible, such as some appliances, use calendar reminders and monitoring.

Monitor everything that can expire
Add monitoring for certificate expiry on every public endpoint, with alerts at thirty, fourteen and seven days, and escalation if unresolved. Monitor domain expiry using registrar tools or external services. Check DNS resolution and record changes: alert if key records such as A, MX and NS change unexpectedly, which can also indicate a compromise. Include TLS configuration checks, such as supported protocol versions and certificate chain completeness, in your regular scans. These checks belong in the broader monitoring setup described in our monitoring guide, and a simple external uptime check that visits your site with full certificate validation will catch expiry the moment it happens.
Handle changes safely
- Plan. Document the current records, the target records and the order of changes.
- Lower TTLs ahead of time.
- Change in stages, verifying each step: web, then email, then verification records.
- Check from multiple locations and resolvers, and test real user journeys, including email sending and receiving.
- Keep the old service running until traffic has fully moved.
- Restore normal TTLs and record what changed.
Site moves and migrations are where most DNS mistakes happen; see the checklists in our store migration guide.
Security hardening
Enable DNSSEC where your registrar and DNS provider support it, to protect against forged DNS responses, understanding that it adds operational complexity and must be managed carefully. Enforce HTTPS across the site with redirects and the HSTS header, after confirming that certificates are reliable. Use modern TLS versions and disable outdated protocols. Restrict who can modify DNS and require review for changes to critical records. Keep audit logs.
Prepare for the bad day
Write a short runbook: how to renew or replace a certificate urgently, how to regain control of a domain, how to switch DNS providers, and who to call at the registrar and hosting provider. Record account recovery details. Include DNS zone exports in your backups so records can be restored quickly; see our backup and recovery guide.
A quick audit you can do today
- List every domain your business owns, its registrar, expiry date and contact.
- Confirm auto-renew and registrar lock are on, and that notices go to a monitored shared address.
- Check certificate expiry dates for every public hostname.
- Review DNS records for anything unexplained or pointing to retired services.
- Verify SPF, DKIM and DMARC.
- Turn on multi-factor authentication for registrar and DNS accounts.
An hour spent on this checklist can save a very bad day. If you would rather not manage it yourself, our hosting team handles DNS, certificates and renewals for the domains we host, and our maintenance plans include monitoring so expiry warnings reach a person long before they reach your customers.
Put this into practice with CodeLuma
CodeLuma manages DNS, certificates and domain renewals for the sites we host and maintain, with automation and monitoring, so a forgotten renewal never takes your business offline.
- Managed hosting - monitored, backed-up, Canadian-friendly hosting.
- Maintenance and support plans - updates, monitoring and ongoing improvement.
- Website and web application development - fast, accessible, search-friendly builds.
Start a conversation. Tell us about your project and we will reply with practical next steps, or browse all CodeLuma services. CodeLuma Development Inc. is based in Nova Scotia and works with teams across Canada and remotely.


