The summary.
PROPAGATION IS CACHES EXPIRING, NOT DATA SPREADING
There is nothing to accelerate. Lowering the time-to-live well before a change is the only preparation available.
SEPARATE AUTHORITATIVE AND RECURSIVE FUNCTIONS
They have different exposure and different tuning, and combining them increases risk.
Never operate an open resolver — it will be used to amplify attacks at someone else.
NAMESERVERS ON ONE NETWORK FAIL TOGETHER
Diversity of network, location and routing is what makes DNS resilient. Monitor that every nameserver returns the same serial.
BADLY OPERATED DNSSEC IS WORSE THAN NONE
A signing mistake makes a domain unreachable, not merely unverified. Automate re-signing, alert well before expiry, and validate from outside.
THE COMMONEST SELF-INFLICTED OUTAGE
A parent delegation record no longer matching the current key.
AUDIT FOR DANGLING RECORDS
A record pointing at a decommissioned service can be claimed by someone else. Remove records when removing services.
LOCK THE DOMAIN AT THE REGISTRAR
Hijacking at the registrar bypasses every technical control you operate.