Blog
4 min read

DNS Propagation Explained: Why Domain Changes Take Time (and How to Speed Them Up)

You changed a DNS record and your site still points to the old place. What "DNS propagation" really is (caching, not spreading), how TTL controls the wait, why nameserver changes take longest, how to check from different places, and how to flush your own cache.

You updated a DNS record to point your domain at a new host. Your friend sees the new site; you still see the old one. Or nothing works for an hour, then everything does. This is DNS propagation, and once you understand what's actually happening, the waiting stops being mysterious — and you can often shorten it.

What's really going on: caching

"Propagation" makes it sound like your change slowly spreads across the internet. That's not quite it.

When someone visits your domain, their device asks a DNS resolver (usually run by their internet provider, or a public one like 1.1.1.1 or 8.8.8.8) for your domain's address. The resolver looks it up and then caches — remembers — the answer, so it doesn't have to look it up again for every visitor.

When you change a record, resolvers that already cached the old answer keep using it until their cached copy expires. Different resolvers cached it at different times, so they expire at different times. That's why some people see the new site and some see the old one.

(Background: what is a domain name? and DNS records explained.)

TTL: the number that controls the wait

Every DNS record has a TTL — time to live — in seconds. It tells resolvers how long they may cache the answer.

TTL Means
300 5 minutes
3600 1 hour
86400 24 hours

If your record's TTL was 3600 when someone's resolver last looked it up, they may see the old answer for up to an hour after your change.

The trick: lower the TTL first

If you're planning a move:

  1. A day before, lower the TTL on the records you'll change to 300.
  2. Wait for the old, longer TTL to expire everywhere.
  3. Make the change. Now everyone picks it up within about five minutes.
  4. Once settled, raise the TTL again if you like.

Why nameserver changes take longest

Changing your domain's nameservers — moving DNS management to a different provider — is a different kind of change. The record pointing your domain at its nameservers is held by the domain's registry (for .com, Verisign), and those records commonly have TTLs of a day or two. You can't lower them yourself.

So nameserver changes can take up to 24–48 hours to be seen everywhere, while ordinary record changes with a low TTL take minutes. If you only need to point your site at a new host, change the A or CNAME record rather than moving nameservers.

How to check what people are seeing

Check from many places at once. Online "DNS propagation checker" tools query resolvers around the world and show what each returns. If most show the new value, you're nearly done.

Check from the command line:

# What does a public resolver say?
dig example.com A @1.1.1.1 +short

# What does the authoritative nameserver say (the source of truth)?
dig example.com NS +short
dig example.com A @ns1.yourdnsprovider.com +short

On Windows without dig, use nslookup example.com 1.1.1.1.

If the authoritative nameserver returns the new value, your change is correct and you're just waiting for caches. If it returns the old value, the change wasn't saved — or you edited DNS at the wrong provider (a very common mistake when nameservers point somewhere other than your registrar).

Clearing your own caches

Your computer and browser cache DNS too. To see the change sooner on your own machine:

  • Windows: ipconfig /flushdns
  • macOS: sudo dscacheutil -flushcache; sudo killall -HUP mDNSResponder
  • Chrome: visit chrome://net-internals/#dns and clear the host cache
  • Phone: toggle airplane mode on and off

Or test from your phone on mobile data, which uses a different resolver.

Things that look like propagation but aren't

  • SSL errors after the move: the new host can't issue a certificate until DNS points at it. Usually resolves itself shortly after DNS settles. See how automatic SSL works.
  • Email stopped working: you changed nameservers and didn't copy your MX records to the new DNS provider. See custom email for your domain.
  • Redirect loops: a proxy and your host both forcing HTTPS. See ERR_TOO_MANY_REDIRECTS.

The summary

  • "Propagation" is really caches expiring at different times.
  • TTL sets how long the old answer can be cached; lower it before planned changes.
  • Record changes can take minutes; nameserver changes up to 48 hours.
  • Check the authoritative nameserver to confirm your change is correct, then wait — or flush your local cache.

EasySpawn tells you exactly which DNS records to add when you connect your domain, and issues SSL automatically once they resolve. See how it works or join the waitlist.

Related: How to Connect a Custom Domain to Your App · How to Transfer a Domain · www vs non-www · What Is Caching?

Keep reading