Habits worth adopting.
RECORD WHERE EVERYTHING LIVES
Registrar, DNS provider, and who has access. In your documentation, off the server.
EXPORT YOUR ZONE
After any change, and annually. No hosting backup includes external DNS.
LOWER TTLS BEFORE PLANNED CHANGES
A day in advance. It turns hours of inconsistency into minutes.
CHECK THE AUTHORITATIVE ANSWER
Before concluding a change failed. It distinguishes broken from waiting.
KEEP ONE SPF RECORD
Add mechanisms to the existing one rather than creating a second.
DO NOT REMOVE VERIFICATION RECORDS
Many services re-check periodically.
TEST MAIL AFTER ANY DNS CHANGE
Both directions. Mail is the most common casualty and the least immediately visible.
SECURE THE ACCOUNTS
Two-factor authentication on the registrar and the DNS provider. Controlling your DNS is more damaging than compromising your website.
USE A CONTACT ADDRESS ON ANOTHER DOMAIN
So notifications reach you when the domain itself has a problem.
CHECK ANNUALLY
Nameservers, records, expiry dates and anything pointing at a previous host.