60-second updates. Generous free tier. RFC 2136 TSIG. Bring your own domain. DNSSEC. For homelabs, edge routers, and infrastructure teams.
Most DDNS providers cache for 30 minutes. DynIP propagates in under a minute end-to-end. Your router sends an update, your hostname resolves correctly worldwide within ~60 seconds.
60s TTL · NOTIFY-driven · Multi-region nameservers
RFC 2136 TSIG means your FortiGate, OPNsense, OpenWRT, or any router that speaks DNS UPDATE works out of the box with our code generator. Kubernetes external-dns, cert-manager generated snippets.
RFC 2136 TSIG · REST API · UDP/53 native
Modern ISPs increasingly give you native IPv6 alongside CGNATed IPv4. DynIP supports both: update A and AAAA records side-by-side, run IPv6-only zones, or both. Built for the network you have today and the network you'll have tomorrow.
AAAA records · Dual-stack · IPv6-only support · DNSSEC by toggle
Set New Password
Password Recovery
Two-Factor Authentication
Access Control
You signed in using a backup code. {{ backupCodeLoginNotice.remaining }} codes remaining. Consider generating new codes to ensure continued access.
The agent gets this zone's credentials, both update transports, and the rule for choosing between them. See the agent guide.
API tokens are a Pro feature. The update and record-management instructions work on every plan — see pricing to add zone lifecycle.
{{ nsupdateRecordErrors.name }}
Relative to {{ snippetData.domain }}. Leave blank or use @ for the zone itself.
{{ nsupdateRecordErrors.content }}
Hostnames are taken as full names. See the RFC 2136 guide for each record type's format.
RouterOS /tool fetch has no flag to force the address family. Dual-stack updates both A and AAAA records; the single-family variants pin the connection with :resolve.
{{ clusterNameError }}
A short identifier for this cluster (e.g. prod-eu, staging, homelab). Used by external-dns to track which records it owns. Must be unique per cluster if you run multiple clusters against this zone.
{{ acmeContactEmailError }}
Required. Used as the Let's Encrypt account contact — renewal/expiry notifications go here.
{{ certManagerNamespaceError }}
Required. The namespace where the issued certificate Secret will be created (e.g. default, app, ingress).
{{ acmeAccountUriError }}
Your ACME account URI from Let's Encrypt — see docs for how to find or create one.
{{ snippetData.domain }}{{ snippetData.key }}
{{ generatedSnippet }}
Apply these manifests to your Kubernetes cluster for automatic certificate issuance via cert-manager. Replace <YOUR-CONTACT-EMAIL> and <YOUR-APP-NAMESPACE> before applying.
--dns01-recursive-nameservers-only --dns01-recursive-nameservers=1.1.1.1:53,8.8.8.8:53
{{ certManagerSecretYaml }}
{{ certManagerIssuerYaml }}
{{ certManagerCertYaml }}
No ACME account yet? Register one without issuing a certificate, then paste the account URL into the field above.
{{ dnsPersistAccountSnippet }}
Already have an account (certbot, lego, acme.sh)? Its URL lives in the account file your client saved. Full walkthrough in the docs.
{{ optionsData.domain }}{{ optionsData.key }}
••••••••••••••••••••••••••••••••
This key authorizes both apex record updates via RFC 2136 / nsupdate and external AXFR-out transfers. Example apex update:
nsupdate -y {{ tsigAlgoNsupdate(optionsData.algorithm) }}:key-{{ optionsData.domain }}:<secret> << EOF
server update.dynip.dev
zone {{ optionsData.domain }}
update add {{ optionsData.domain }} 60 A 192.0.2.1
send
EOF
HMAC-SHA256 (recommended) — Works with external-dns, BIND nsupdate, most modern RFC 2136 clients, and the HTTP API. This is the default for new keys.
HMAC-MD5 — Required only for FortiGate genericDDNS, which is fixed to MD5 and cannot use SHA-256. Choose this only if your device requires it.
Your key secret does not change when you switch algorithms — only the algorithm itself. After switching, you must update the algorithm setting on your device to match, or updates will fail. Changes take ~2 minutes to propagate across all nameservers.
⚠ {{ subscription.locked_zones_count }} zone(s) locked
Your plan was downgraded. The oldest {{ subscription.max_domains }} zone(s) stay active; the rest are locked and can't receive IP updates. Subscribe again or delete excess zones to unlock.
Issuing a Let's Encrypt certificate for
{{ dnssecPrompt.zone }}
requires DNSSEC to be active on this zone.
We'll automatically:
{{ dnssecPrompt.parentZone }})This is a one-time setup. Your zone stays signed afterward, which is recommended anyway.
Estimated time: 30 seconds.
Enabling DNSSEC{{ dnssecPrompt.parentZone ? ' and publishing DS in ' + dnssecPrompt.parentZone : '' }}...
{{ sslError.message }}
Authoritative Control Plane
1. Create a Zone: Type your device name, select your preferred base domain, and click Create Zone.
2. Get the Config: Click the Snippets button next to your new domain.
3. Deploy: Select your device type and copy the generated configuration block directly into your router's CLI.
Note: IPv4 and IPv6 (Dual-Stack) are detected and updated automatically based on the incoming connection.
| Domain & Tools | Current IP | TSIG | DNSSEC | SSL Cert |
|---|---|---|---|---|
|
{{ zone.name }}
⚠
{{ zone.owner_email === activeUser.email ? 'You' : zone.owner_email }}
Locked
|
{{ zone.ip }}
Sync: {{ formatSyncTime(zone.last_sync) }}
|
Unavailable |
Delegation required
|
|
| No domains registered. Create one above to get started. | ||||
Bring your own domain to DynIP. Once added, you can provision dynamic subdomains under your own namespace.
✅ Active
Ownership verified and delegated to ns1/ns2.dynip.dev. Records resolve publicly.
Publish this DS record at your DNS provider for {{ dom.dnssecParentZone }}.
Add it as a DS record on the parent zone (Cloudflare, Route53, your registrar, …). After it propagates, DNSSEC validation activates for {{ dom.domain }}.
Three formats of the same key. Most registrars accept SHA-256 (the middle one) — use that unless yours specifies otherwise.
🛡️ Signed and DS published automatically — chain of trust is live.
✅ Ownership verified — not delegated
Your zone is fully usable on the platform (TSIG key, RFC 2136 / API updates, snippets). But your domain isn't yet delegated to ns1/ns2.dynip.dev, so records won't resolve publicly until you add these NS records at your registrar:
Required Registrar Action:
To activate this namespace, create BOTH NS (Name Server) records at your domain registrar. Single-NS delegation will be rejected:
Verify ownership with a TXT record
Add this TXT record at your registrar, then click Validate now. Your zone becomes usable on the platform — but DNS won't resolve publicly until you delegate nameservers separately.
❌ {{ dom.txtMessage }}
Instantly update your selected zones to match this device's current external IP address.
Programmatically register new zones with your current session token. Send a POST request to the /register endpoint.
curl -X POST "{{ backendUrl }}/register?subdomain=my-new-router&base_domain={{ baseDomains[0] }}" \
-H "Authorization: Bearer {{ token }}"
Session tokens expire on logout — use an API token below for long-running automation.
API tokens are a Pro feature
Long-lived tokens for automation: monitoring scripts, CI pipelines, MSP integrations. Tokens don't expire when you log out.
Upgrade to Pro →Long-lived tokens for automation. Each token can be scoped read-only or full access, and revoked at any time.
| Name | Token | Scope | Last used | Expires | Action |
|---|---|---|---|---|---|
| {{ t.name }} | {{ t.token_prefix }} | {{ t.scope === 'read' ? 'Read-only' : 'Full' }} | {{ t.last_used_at ? formatPlanDate(t.last_used_at) : 'Never' }} | {{ t.expires_at ? formatPlanDate(t.expires_at) : 'Never' }} |
Invite others to share access to your zones. Zone quotas pool across all team members' plans. Owning a team requires a Pro or higher subscription; members can be on any plan.
Team invitations are a Pro feature
Share zone management with your household or team. You can still join someone else's team on any plan — ask them to send you an invitation.
Upgrade to Pro →You're the only member of your team. Invite others to share zone access — their zones move with them, and their plan's allowance joins your pool.
They'll get an email with an accept link, valid 7 days. When they accept, their zones join the team and their plan's zone allowance is added to the pool.
{{ inviteModal.error }}
{{ teamInvite.preview.owner_email }} invited you to join {{ teamInvite.preview.team_name }}.
{{ teamInvite.error }}
Tokens are shown once at creation — store them in a password manager or secrets vault.
{{ apiTokenModal.error }}
This token won't be shown again. Store it somewhere secure (1Password, Bitwarden, your CI's secrets manager).
{{ apiTokenModal.created.token }}
Each code works once. Store them somewhere safe — a password manager or printed copy. They won't be shown again; if you lose them, generate a new set.
{{ code }}
{{ regenerateModal.error }}
This overrides email 2FA.
Single-use codes to sign in if you lose access to your authenticator. {{ backupCodesStatus.remaining }} of {{ backupCodesStatus.total }} remaining.
Upgrade your account security by requiring a time-based code from Google Authenticator or another TOTP app when you sign in.
Open Google Authenticator, Authy, or your preferred 2FA app and scan this code.
Same secret as the QR — for password managers and authenticators that can't scan it.
Permanently delete your account, all DNS zones you have created, and any TLS certificates issued to them. This cannot be undone or reversed by support.
This action cannot be undone. Deletion will:
If you have an active paid subscription, please cancel it first via your account billing area.