Preflight Domain
preflight_domainCheck if a planned domain change will break DNS or email before making it. Run this read-only preflight before moving nameservers, transferring out, or enabling DNSSEC.
Instructions
Ask whether a change is about to break a domain, BEFORE making it. Read-only, free, and the right thing to call before changing nameservers, transferring a domain out, or enabling DNSSEC.
Every check comes from a real incident, so these are the failures where a zone looks fine and stops working anyway. Read blockers first — those will break something. warnings will not break outright but are usually what the user notices next. safe is true only when both are empty. Each check names the rule it comes from and carries a next_action, so you can explain the finding rather than just report it.
The two an agent should treat as hard stops:
dnssec-active— DS records are published at the registry, so new nameservers will serve answers that do not match them and validating resolvers will refuse the WHOLE zone. The domain goes dark rather than degrading. DNSSEC has to be removed and the DS TTL waited out BEFORE the nameservers change. Never move delegation past this one.spf-duplicate/spf-lookups— RFC 7208 permerrors that make SPF fail for every sender, so the domain's mail is already being degraded whether or not the user has noticed.
Check nameservers-ours before you read anything else: it says whether this zone is what the world resolves at all. A domain delegated to another provider still accepts every DNS write here and none of them take effect, and the mixed case (some of the delegated nameservers are Porkbun's, some are not) means resolvers disagree query to query.
The one worth explaining because nobody expects it: wildcard-shadowed. Under RFC 4592 a wildcard answers only names that do NOT exist in the zone, so a name holding just an MX or TXT record stops inheriting the wildcard's address and stops resolving — with nothing in the zone looking wrong.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| domain | Yes | Domain to check, e.g. `example.com` | |
| intent | No | What you are about to do; scopes the checks. Defaults to general, which runs everything applicable. |