Domains, nameservers and DNS zones
We identify which nameservers are authoritative, confirm who controls the live zone and check for missing, duplicated or stale records, propagation issues and unsuitable TTL values.
DNS & Business Email Support
W.E.B.S Ltd provides end-to-end support across domains, DNS, servers, Google Workspace and Microsoft 365. We diagnose mail-flow problems, configure MX, SPF, DKIM and DMARC, and plan changes without losing sight of the other services attached to your domain.
Joined-up technical support
A mail problem is not always a mailbox problem. The cause may be at the registrar, in the authoritative DNS zone, on a web server, in Google Workspace or Microsoft 365, or with a third-party sender. Changing one record without understanding the complete setup can create a second fault while trying to fix the first.
We trace the route from domain ownership and nameservers through to the receiving and sending platforms. That means you have one technical partner who can investigate the whole chain rather than being passed between a registrar, hosting company and email provider.
What we troubleshoot
We can investigate an active fault, review a configuration before it causes one, or manage the DNS work for a new business email service.
We identify which nameservers are authoritative, confirm who controls the live zone and check for missing, duplicated or stale records, propagation issues and unsuitable TTL values.
MX records are checked for the correct provider, priority and destination. We also look for split delivery, old routes and server settings that can send mail to the wrong place or reject it.
SPF is reviewed against every legitimate sender, including Workspace, Microsoft 365, website forms, CRM systems and mailing platforms. Multiple SPF records and unsafe record replacement are corrected.
We enable or repair DKIM signing, publish the correct selector records and confirm that messages are actually being signed and validated—not simply that a DNS record exists.
DMARC is introduced at a sensible policy, with reporting used to find legitimate and unauthorised senders. Enforcement is tightened only after alignment has been checked to avoid blocking valid mail.
Headers, bounce codes, message logs, forwarding rules, blocklists and provider settings help us separate a DNS fault from reputation, authentication, routing, quota or account problems.
Practical troubleshooting
Email faults can be time-sensitive, but hurried DNS changes make diagnosis harder. We start with the evidence, establish which systems are live and then make the smallest controlled change needed.
Who cannot send or receive, which direction is affected and whether it is consistent.
Confirm domain status, authoritative DNS, MX destinations and the active mail platform.
Use headers, bounce responses, message logs and authentication results to locate the fault.
Apply the agreed change, test in both directions and document the working configuration.
Moves and migrations
Moving a website, changing nameservers or transferring a domain should not automatically move or interrupt email. Before a change, we inventory the live DNS zone and identify mailboxes, aliases, groups, forwarding, website forms and third-party senders that rely on it.
For Google Workspace or Microsoft 365 migrations, we plan user and data preparation separately from the DNS cutover. Existing services can overlap while delivery and authentication are verified, and old services are retained until the new route is confirmed. Wider moves can be coordinated through our website and domain migration service.
Common questions
The new DNS zone may not contain the MX and authentication records used by the existing email provider. Website and email hosting are often separate, so the correct fix is usually to restore the missing email records—not to move mailboxes without a plan.
Yes. That is common. We identify which provider controls each layer, confirm the live configuration and coordinate the required changes across the registrar, DNS host, server and email platform.
No. SPF, DKIM and DMARC perform related but different jobs. DMARC also checks alignment between the domain visible to the recipient and the domain authenticated by SPF or DKIM. All three should be reviewed together.
Yes. Our dedicated service offering includes Google Workspace, but the DNS, authentication, routing and migration work can also cover Microsoft 365 and mixed setups involving websites and third-party senders.
Well-prepared changes can normally avoid noticeable interruption. We verify the destination first, retain the old service during propagation where possible and test delivery after cutover. The exact plan depends on the current providers and the type of change.
Ready to talk?
Tell us what is failing, what recently changed and which providers are involved. We can trace the setup, explain the cause and plan a controlled fix.