Understand protected records and resolve DNS record conflicts

Some DNS records are managed by the provider or by another feature in your account. Others conflict because their names and record types describe incompatible arrangements. Identify the reason before removing a record that appears to block your change.

01 Records you may not edit directly

  • Provider-managed SOA: contains authority and zone timing information controlled by the DNS backend.
  • Protected record: a policy or supplied setup prevents direct customer changes.
  • Owned by a forwarder: the website or email forwarding service created the record and keeps it in sync with that rule.
  • Locked zone: the whole zone is temporarily or deliberately protected.

For a forwarding record, open its forwarding screen and edit or remove the underlying rule. Deleting a related entry through another tool can leave the feature inconsistent or cause the record to return. If a protected entry genuinely needs changing, ask support to review its purpose.

02 CNAME conflicts

A conventional CNAME aliases a name to another hostname. It cannot share that same owner name with ordinary A, AAAA, MX or TXT records. For example, changing www from A to CNAME normally requires replacing the old address record at www, after checking the intended final state.

The root domain also has authority records, so an ordinary apex CNAME is generally unsuitable. Some providers supply special flattening or alias features, but those are provider-specific. Follow the destination platform's supported apex instructions rather than forcing a CNAME into an unsupported arrangement.

Are records with the same name always duplicates?

Several records are sometimes intentional, such as multiple MX priorities or several TXT values at a verification name. Do not remove rows based only on repeated names. For SPF, however, separate competing v=spf1 policies at the same name are not a valid way to combine mail senders. Review the complete service configuration.

03 Resolve and verify

Export the zone, identify the service behind each affected entry and prepare the intended final record set. Use the editor or preview workflow to make one clear change. Refresh the completed records and test the associated service. If validation refuses a value, preserve the error and record details for support; repeated retries with the same conflicting arrangement will not resolve it.

  • 0 Users Found This Useful
  • domains-dns, domain-nexus
Was this answer helpful?

Related Articles

Back up and restore DNS records

A DNS backup records the zone's entries so you can review or restore a previous configuration....

Use bulk DNS changes across one or several zones

Bulk management is useful when several records need the same new address or TTL. It also...

Add a domain registered elsewhere to your DNS Manager

You can manage DNS for a domain registered with another company when your Nabtech service...

Read a DMARC aggregate report in DNS Manager

The Premium DNS Plus report reader helps you inspect a DMARC aggregate report received from an...

Enable DNSSEC and complete the DS-record setup

DNSSEC lets validating resolvers check signed DNS data against a chain of trust. It needs both...