DNS TTL Planner
Plan the TTL reductions before a DNS change and the timeline for a migration cutover, including how long stale answers persist and what ignores your TTL entirely.
Last reviewed by the Radiatus Cloud team
Need this monitored 24/7?
Radiatus delivers managed cloud & network operations.
Lower the TTL before the change, not during it
A resolver that has cached a record keeps it for the full TTL regardless of what you do afterwards. Lowering the TTL from a day to five minutes does not take effect for a day, because every resolver holding the old record also holds the old TTL. The reduction therefore has to happen at least one full old TTL before the cutover, and preferably two, which for a 24 hour TTL means starting two days ahead.
The propagation window is the sum of two TTLs
After the change, resolvers holding the record continue serving the old answer until their copy expires. With a five minute TTL that window is five minutes; with the original 24 hour TTL it is 24 hours. This is why the whole procedure exists: the temporary low TTL turns a day long cutover during which some users reach the old server into a five minute one, at the cost of higher query volume for a few days.
Some resolvers ignore your TTL
Public resolvers, corporate caches and some ISP resolvers apply their own minimum and maximum, and a handful cap TTLs at their own value regardless of what the zone says. Browsers and operating systems cache separately with their own timers, and Java applications historically cached DNS answers for the lifetime of the process. Planning for a clean expiry at exactly the TTL is optimistic; keeping the old destination serving for a period afterwards is what actually makes a migration safe.
Related tools
- Port Scanner — Check which common ports respond on a host and understand what each exposed service means. Scan only systems you are authorised to test.
- DNS Misconfiguration — Analyze DNS records (TXT, SPF) for security gaps.
- TLS Compat Tester — Check client-server compatibility for TLS versions.
- Firewall Rule Risk — Evaluate firewall rules for over-permissive exposure.
Frequently Asked Questions
How far ahead should I lower the TTL?
At least one full current TTL before the change and preferably two, because every resolver holding the record also holds the old TTL and will not see the new one until its copy expires. For a 24 hour TTL that means starting two days ahead.
What TTL should I use during a cutover?
Sixty to three hundred seconds. Below sixty the query volume rises sharply for little benefit, and some resolvers enforce a minimum anyway. Restore the normal value a day or two after the change is confirmed good.
Why do some users still reach the old server?
Resolvers that cached before the TTL was lowered, resolvers enforcing their own minimum, and browsers or applications caching independently of the operating system. Keep the old destination serving for at least a day after the cutover rather than assuming a clean expiry.
What is negative caching?
The SOA minimum field controls how long a resolver remembers that a name does not exist. A high value means a newly created record stays invisible for that long to anyone who happened to query it before it was created, which is a common cause of "it works for me" during a launch.
Does a low TTL hurt performance?
It increases query volume to your authoritative servers and adds a lookup to some requests, which is a few milliseconds. For a migration window that is a fair trade; as a permanent setting on a busy domain it is a meaningful cost for no benefit.
Privacy & Security
Everything runs in your browser; nothing is uploaded.
How to Use
Enter your current TTL and cutover date to get the schedule for lowering and restoring it.
Disclaimer: This tool is provided "as is" without warranty of any kind. Results are for educational and utility purposes.
Related Tools
Port Scanner
NetworkCheck which common ports respond on a host and understand what each exposed service means. Scan only systems you are authorised to test.
DNS Misconfiguration
NetworkAnalyze DNS records (TXT, SPF) for security gaps.
TLS Compat Tester
NetworkCheck client-server compatibility for TLS versions.