What does this mean?
Changing nameservers moves authority for DNS; it does not automatically copy your old mail settings. The website may load from the new host while missing MX, authentication or provider-verification records interrupt email. Waiting for propagation does not restore records that were never recreated.
What should I check first?
Locate the previous zone export or screenshots and your email provider’s current instructions. Identify whether the domain moved DNS providers only or email providers as well. Keep the original mailboxes and service active until migration and test delivery are complete.
How can I diagnose the cause?
Compare active nameservers, MX and mail-related TXT records with the intended configuration. Query _dmarc and the exact DKIM selector, including any provider CNAME delegation. Check for a stale DNSSEC DS entry at the registrar and ask the DNS provider about validation if public queries return SERVFAIL.
How do I fix it safely?
Recreate confirmed missing records in the newly authoritative zone, preserving unrelated records. Check whether the new web host incorrectly treats your mail as local. Do not invent an MX value from a server’s marketing name, and do not publish two SPF policies: consolidate the authorized senders with your mail provider.
Verify the fix and know when to contact your provider
Make a zone copy before each change. Test incoming mail, outgoing webmail and a delivered message’s authentication results. If public DNS now matches instructions but failures continue, give the mail provider the change time, observed records and full redacted bounce. Ask the registrar for help if delegation or DNSSEC remains inconsistent.
Work through these checks in order
- Compare the old-zone backup with the active new zone, starting with MX. Then check the single SPF policy, provider DKIM selector or CNAME and _dmarc TXT record; they have separate purposes.
- Restore only provider-confirmed missing or wrong values and check remote mail routing at the web host. If queries return SERVFAIL, ask about DNSSEC instead of repeatedly recreating records.
- Test both incoming and outgoing external mail and a website notification. If DNS matches but delivery fails, provide the mail provider with the full redacted bounce and migration time for a message trace.
Which tool can help?
MX record checker · DNS lookup · Nameserver checker · SPF DNS record checker · DKIM public record checker · DMARC DNS record checker
DNS tools show one resolver’s public answers. Record explainers do not authenticate a message, and calculators do not monitor a server. Use the evidence alongside your provider’s logs.