Guide
Cloudflare Registrar and multi-provider DNS
A domain registered at Cloudflare Registrar can only use Cloudflare’s nameservers. Here is what that means for redundancy, what you can do today and how to move the registration if you want the apex on two providers.
If your domain is registered at Cloudflare Registrar
-
You cannot change its nameservers at the registrar, so the apex (
example.com) stays on Cloudflare alone while it is there. -
Subdomains such as
api.example.comcan be on two or more providers today, with no transfer: RedundantDNS writes their delegation into your Cloudflare zone. - For the apex, transfer the registration to another registrar (allowed 60 days after registration or a previous transfer), then set the multi-provider NS set there.
- Domains registered anywhere else can use Cloudflare as one of their providers, apex included.
The problem
Multi-provider DNS works because the NS set at your registrar lists the nameservers of every provider. Resolvers follow that list, so when one provider stops answering, another one does.
Cloudflare Registrar does not let you edit that list. Every domain registered there is delegated to Cloudflare’s own two nameservers and nothing else. As long as the domain is registered at Cloudflare, the apex has one provider.
Adding NS records for other providers at the apex of the zone does not change this. Those records live inside the zone; resolvers find your
zone through the delegation that the registrar publishes at the TLD (for .com, the .com nameservers), and that
delegation still lists only Cloudflare.
Why it happens
Cloudflare Registrar is built to register domains that use Cloudflare’s DNS. Its FAQ answers the question “Can I use my own (third-party) nameservers?” with a no: all domains on Cloudflare Registrar use Cloudflare nameservers. The same FAQ points to the two ways around it: delegate subdomains to other providers, or transfer the domain to another registrar. See also the Cloudflare Registrar documentation.
This is a rule of the registrar, not of Cloudflare DNS. Cloudflare DNS itself works well in a multi-provider zone, as the next section shows.
What still works
Cloudflare as one provider, for domains registered elsewhere
If the domain is registered at any other registrar, Cloudflare can be one of the providers of the zone, apex included. Cloudflare DNS has a Multi-provider DNS setting: with it on, Cloudflare honors the NS records at the apex and activates the zone even when the registrar also lists other providers’ nameservers. RedundantDNS turns the setting on when it attaches a Cloudflare zone, then writes the apex NS set with every provider, like it does on the others.
Subdomain redundancy, with no transfer
You can keep the domain at Cloudflare Registrar and make the names that matter most redundant. Create api.example.com or app.example.com as its own zone in RedundantDNS, on two or more providers. When the parent zone example.com is also
in your organization, RedundantDNS writes the NS delegation for api into it (on Cloudflare too) and keeps it up to date as
providers are attached or detached. Resolvers reach the apex through Cloudflare, and the subzone through every provider it is attached to.
Cloudflare documents the same pattern as delegating a subdomain outside Cloudflare.
The limit: if Cloudflare as a whole cannot answer, resolvers that do not have the delegation cached yet cannot find the subzone either, because the delegation itself is served by Cloudflare. Once cached (for the TTL of the NS records), the subzone keeps answering from its providers.
Cloudflare as a single provider
You can also keep things as they are: attach the Cloudflare zone to RedundantDNS for sync, drift detection and probes, knowing that the apex stays single-provider until the registration moves. The delegation check in the dashboard says so next to the zone.
Transfer out, step by step
A registrar transfer moves the registration only. It does not move or delete your DNS zone, and it does not have to change the nameservers. Cloudflare describes the process in Transfer your domain to another registrar.
- Check the 60-day rule. ICANN rules block a transfer within 60 days of the registration, of a previous transfer, or of a change to the registrant’s contact details. Wait until the 60 days are over.
- Pick the new registrar and check that it sells your TLD. Some of their guides are listed below.
- In the Cloudflare dashboard, open Manage Domains, select the domain, then Configuration and Unlock. Copy the authorization code (also called the auth or EPP code) that Cloudflare shows.
- At the new registrar, start a transfer in for the domain and paste the authorization code. Keep the current nameservers during the transfer: if the new registrar offers to switch the domain to its own DNS, say no for now.
- Approve the outgoing transfer in the Cloudflare dashboard when the request arrives, or wait: Cloudflare approves it on the fifth day if you do nothing.
- When the transfer is complete, add the zone to RedundantDNS (or adopt it from Cloudflare), attach a second provider, and set the NS set that the dashboard lists at the new registrar. The delegation check tells you when every provider is live.
Transfer-in guides
The steps at the receiving registrar, from each registrar’s own help pages. Any registrar that lets you edit nameservers works.
During the transfer
DNS answers keep working while the registration moves, as long as the nameservers do not change. The registry keeps publishing the same NS set; only the company you pay for the registration changes. Change the NS set once, after the transfer is complete, to the one RedundantDNS lists.
Assisted transfer (planned)
We plan to offer an assisted transfer: move the registration to a registrar we work with, from the dashboard, with the multi-provider NS set applied on arrival. It is planned, with no date yet. Until then, the steps above are the way to do it.
More on how Cloudflare fits a zone: the Cloudflare permission guide and the pairs on the providers page.
Put your zone on two providers
Start with one zone and two providers you already have. Free, no card.