A Cloudflare DNS handover is risky because the zone is both a record list and a collection of account-bound settings. Exporting records is necessary, but it doesn't recreate every security, proxy, certificate, or add-on choice.
Treat the move as a controlled rebuild in the client's Cloudflare account. The old zone should keep serving traffic until the new zone is ready and the registrar nameservers can be changed with confidence.
Before you start
- Export the current DNS records and capture screenshots of proxy, DNSSEC, SSL, and page-rule settings.
- Confirm whether the registrar also changes hands or only the DNS account changes.
- Plan a low-traffic handover window for records that affect website, email, and verification services.
On Cloudflare, specifically
- Cloudflare says a domain registered with Cloudflare Registrar needs a manual request to move the registration to a new Cloudflare account. Source, checked September 3, 2026.
- Before moving an active Cloudflare domain to another account, Cloudflare says to remove DNSSEC configurations, add-ons, and subscriptions. Source, checked September 3, 2026.
- Cloudflare recommends exporting DNS records from the old zone and importing the correct records into the new account. Source, checked September 3, 2026.
- When an active Cloudflare domain moves accounts, the old account shows it as Moved Away, then Deleted after seven days, then permanently removed after another seven days. Source, checked September 3, 2026.
The three stages
Prepare
Freeze record edits, remove settings the provider requires you to remove, and identify records that cannot simply be copied because they are tied to account-level services.
Transfer
Create the zone in the client's account, import or recreate the records, and update nameservers only when the new zone is ready.
Confirm
Compare old and new records, check website and email resolution, verify SSL issuance, and remove your account from the critical path.
What to tell your client
- Which DNS records control the website and email.
- Which settings cannot be transferred and must be recreated.
- When the old account will stop serving the zone.
After it is done
Record the asset in Everkey, change its ownership status from needs_transfer to client_owned, and leave a short note with the account that now controls the DNS zone. The free tier is enough for a small handover map.