Start With the Right Question
People often wait 48 hours for “propagation” when the change was never live in the first place. Before waiting, check what your domain’s authoritative nameservers return. Our guide How to check DNS propagation shows how. Then go through the causes below.
1. You Edited DNS at the Wrong Provider
A domain can have DNS zones at several companies — the registrar, the hosting company, a CDN — but only the provider named in the domain’s NS records is used. Look up the NS records with our DNS Record Lookup and make sure you edited the zone at that provider.
2. The Old TTL Has Not Expired Yet
Resolvers may keep the old answer for as long as the old record’s TTL. If the TTL was 86400 seconds, some users can see the old value for up to a day. Lowering the TTL after the change does not shorten caches that already hold the old record.
3. Negative Caching
If someone looked up a name before you created it, resolvers cache the “does not exist” answer. How long they keep it depends on the values in your zone’s SOA record. A newly created subdomain may therefore stay invisible for a while for anyone who queried it too early.
4. Local Caches on Your Device
Your operating system, browser and router all cache DNS. Flush them (see the commands in our propagation guide) or test from another network, such as mobile data, before concluding that the change has not spread.
5. A Hosts File Entry
A line in your computer’s hosts file overrides DNS completely. Developers often add entries while testing a migration and forget them. Check C:\Windows\System32\drivers\etc\hosts on Windows or /etc/hosts on macOS and Linux.
6. A Proxy or CDN Is in Front of the Site
When a site is proxied through a CDN such as Cloudflare, public DNS returns the CDN’s addresses, not your server’s. Changing the origin address in the CDN dashboard takes effect without any visible DNS change. Conversely, if you expected to see your server’s IP address in a lookup, the proxy will hide it.
7. A Nameserver Change Is Still in Progress
Moving to new nameservers takes longer than editing a record. The delegation for a .com domain, for example, is cached for up to 48 hours. During that time some resolvers ask the old nameservers and some ask the new ones. Keep both zones identical until the move is complete. If the domain uses DNSSEC, update or remove the DS record as part of the move — see DNSSEC explained.
8. The Problem Is Not DNS
Sometimes DNS is correct and something else serves old content:
- the new server is not configured for the domain and shows a default page;
- a CDN or browser cache serves old pages;
- for email, the sending side caches MX records, or mail is still delivered to the old mailbox because accounts were not moved.
Use HTTP Headers to see which server answers, and Is My Site Down to confirm the site responds.
Summary
| Symptom | Most likely cause |
|---|---|
| Authoritative nameserver shows the old value | Edited at the wrong provider |
| Some resolvers new, some old | Old TTL still running |
| New subdomain “does not exist” | Negative caching |
| Only your computer is wrong | Local cache or hosts file |
| DNS shows CDN addresses | Site is proxied |