Stay updated with the latest news, insights, and tutorials from the ZoneWatcher team. Learn about DNS monitoring, best practices, and industry developments.
If your service desk lives in HaloPSA, your DNS alerts should too.
In March 2026, the maximum lifetime of a public TLS certificate dropped from 398 days to 200.
If you've ever bounced between AWS Route 53 and Cloudflare and wondered why the same conceptual change — "update the A records for api.example.com" — feels like a totally different operation in each, you've bumped into one of the oldest schisms in DNS tooling: records vs. RRSets.
This sounds simple.
It's tedious and error-prone; it provides a snapshot of a single moment in time.
March is already delivering new integrations and advanced DNS record type support.
Every DNS record has a TTL value, measured in seconds.
Cloudflare published a detailed post-mortem.
The consequences are immediate, escalating, and in the worst case, irreversible.
When something breaks (email stops delivering, a website goes down, a subdomain starts serving the wrong content), the client calls you.
## Step 1: Connect Your DNS Provider After creating your ZoneWatcher account, the first thing you'll do is connect a DNS provider.
Here's how to do it cleanly.
This is a subdomain takeover.
DNS changes are infrastructure changes.
DNS hijacking is the act of redirecting a domain's traffic by modifying its DNS records without authorization.
This guide covers the record types you'll actually encounter: from the basics everyone should know to the newer types that are increasingly relevant.
DNSSEC (Domain Name System Security Extensions) adds cryptographic signatures to DNS responses.
If you manage a domain that sends email, these three records are not optional.
Think of it as a phone book, except it's distributed across thousands of servers worldwide and responds in milliseconds.
Start your free trial today and get full access to all monitoring features.