{{ toast }}

Dynamic DNS that actually works.

60-second updates. Generous free tier. RFC 2136 TSIG. Bring your own domain. DNSSEC. For homelabs, edge routers, and infrastructure teams.

Updates in seconds, not minutes

Most DDNS providers cache for 30 minutes. DynIP propagates in under a minute end-to-end. Your router sends an update, your hostname resolves correctly worldwide within ~60 seconds.

60s TTL · NOTIFY-driven · Multi-region nameservers

Built on real DNS standards

RFC 2136 TSIG means your FortiGate, OPNsense, OpenWRT, or any router that speaks DNS UPDATE works out of the box with our code generator. Kubernetes external-dns, cert-manager generated snippets.

RFC 2136 TSIG · REST API · UDP/53 native

IPv6 done right

Modern ISPs increasingly give you native IPv6 alongside CGNATed IPv4. DynIP supports both: update A and AAAA records side-by-side, run IPv6-only zones, or both. Built for the network you have today and the network you'll have tomorrow.

AAAA records · Dual-stack · IPv6-only support · DNSSEC by toggle

dynip.dev

Set New Password

Password Recovery

Two-Factor Authentication

Access Control

Your account has been deleted. Thank you for using dynip.dev.
{{ auth.message }}

At least 12 characters.

{{ auth.useBackupCode ? 'Enter a backup code' : (auth.twoFactorType === 'totp' ? 'Open Your Authenticator' : 'Check your email') }}

{{ auth.useBackupCode ? 'Use one of the single-use codes you saved at setup.' : (auth.twoFactorType === 'totp' ? 'Enter the 6-digit code from your app.' : 'We sent a 6-digit code to your inbox.') }}

Account temporarily locked

Too many incorrect attempts. Please try again in {{ lockoutDisplay }}.

At least 12 characters.

Too many incorrect attempts. Please try again in {{ lockoutDisplay }}.
OR

You signed in using a backup code. {{ backupCodeLoginNotice.remaining }} codes remaining. Consider generating new codes to ensure continued access.

Configuration Snippets

RFC 2136 / TSIG updates available in {{ tsigSecondsRemaining }} seconds
We're propagating this zone to our nameservers. FortiGate (RFC 2136 / TSIG) needs to wait — it's disabled below until propagation completes. HTTP API updates (cURL, PowerShell, Python, MikroTik, etc.) work right now.
TSIG algorithm mismatch
{{ snippetAlgorithmWarning }}
DNSSEC required
{{ snippetDnssecWarning }}

The agent gets this zone's credentials, both update transports, and the rule for choosing between them. See the agent guide.

API tokens are a Pro feature. The update and record-management instructions work on every plan — see pricing to add zone lifecycle.

{{ nsupdateRecordErrors.name }}

Relative to {{ snippetData.domain }}. Leave blank or use @ for the zone itself.

{{ nsupdateRecordErrors.content }}

Hostnames are taken as full names. See the RFC 2136 guide for each record type's format.

RouterOS /tool fetch has no flag to force the address family. Dual-stack updates both A and AAAA records; the single-family variants pin the connection with :resolve.

{{ clusterNameError }}

A short identifier for this cluster (e.g. prod-eu, staging, homelab). Used by external-dns to track which records it owns. Must be unique per cluster if you run multiple clusters against this zone.

{{ acmeContactEmailError }}

Required. Used as the Let's Encrypt account contact — renewal/expiry notifications go here.

{{ certManagerNamespaceError }}

Required. The namespace where the issued certificate Secret will be created (e.g. default, app, ingress).

{{ acmeAccountUriError }}

Your ACME account URI from Let's Encrypt — see docs for how to find or create one.

{{ snippetData.domain }}
{{ snippetData.key }}
Enter a Cluster Name above to render the external-dns manifest.
Enter a Contact Email and Kubernetes Namespace above to render the cert-manager manifest.
Enter your ACME Account URI above to render the DNS-PERSIST-01 publishing command.
Enter a Contact Email above to render the Proxmox setup script.
Enter a valid Name and Content above to render the nsupdate command.
{{ generatedSnippet }}
Checking DNSSEC status…
⚠ DNSSEC must be enabled first
Without DNSSEC, validating resolvers can't verify the chain of trust, so cert-manager's DNS-01 challenge will time out. Enable DNSSEC for this zone via the SSL section (the Renew / SSL flow prompts you to enable it), then reopen this panel.
Couldn't load cert-manager configuration
{{ certManager.error || 'Please try again in a moment.' }}

No ACME account yet? Register one without issuing a certificate, then paste the account URL into the field above.

{{ dnsPersistAccountSnippet }}

Already have an account (certbot, lego, acme.sh)? Its URL lives in the account file your client saved. Full walkthrough in the docs.

Domain Options

{{ optionsData.domain }}
{{ optionsData.key }} ••••••••••••••••••••••••••••••••
The secret is unchanged when you switch algorithms below.

This key authorizes both apex record updates via RFC 2136 / nsupdate and external AXFR-out transfers. Example apex update:

nsupdate -y {{ tsigAlgoNsupdate(optionsData.algorithm) }}:key-{{ optionsData.domain }}:<secret> << EOF server update.dynip.dev zone {{ optionsData.domain }} update add {{ optionsData.domain }} 60 A 192.0.2.1 send EOF
{{ tsigAlgoDisplay(optionsData.algorithm) }}
Currently active for this key.
Propagating new algorithm to nameservers — RFC 2136 / TSIG updates ready in ~{{ optionsData.secondsUntilReady }} seconds.

HMAC-SHA256 (recommended) — Works with external-dns, BIND nsupdate, most modern RFC 2136 clients, and the HTTP API. This is the default for new keys.

HMAC-MD5 — Required only for FortiGate genericDDNS, which is fixed to MD5 and cannot use SHA-256. Choose this only if your device requires it.

Your key secret does not change when you switch algorithms — only the algorithm itself. After switching, you must update the algorithm setting on your device to match, or updates will fail. Changes take ~2 minutes to propagate across all nameservers.

{{ subscription.tier }} Plan

⚠ {{ subscription.locked_zones_count }} zone(s) locked

Your plan was downgraded. The oldest {{ subscription.max_domains }} zone(s) stay active; the rest are locked and can't receive IP updates. Subscribe again or delete excess zones to unlock.

Status Free tier Active Cancelled Past Due {{ subscription.status || '—' }}
{{ subscription.status === 'cancelled' ? 'Access ends' : 'Renews on' }} {{ formatPlanDate(subscription.current_period_end) }}
Billing cycle {{ subscription.cycle }}
Payment failed. Please update your payment method to keep access.
Zones {{ subscription.zones_in_use }} of {{ subscription.max_domains }}
Upgrade →

Enable DNSSEC for this zone?

Issuing a Let's Encrypt certificate for {{ dnssecPrompt.zone }} requires DNSSEC to be active on this zone.

We'll automatically:

  • Generate signing keys
  • Publish them in the parent zone ({{ dnssecPrompt.parentZone }})
  • Sign all DNS records

This is a one-time setup. Your zone stays signed afterward, which is recommended anyway.

Estimated time: 30 seconds.

Enabling DNSSEC{{ dnssecPrompt.parentZone ? ' and publishing DS in ' + dnssecPrompt.parentZone : '' }}...

Certificate Issue

{{ sslError.message }}

dynip.dev

Authoritative Control Plane

{{ activeUser.email }}
Admin
Security

Quick Start Guide

{{ showHelp ? 'Hide' : 'Show' }}

1. Create a Zone: Type your device name, select your preferred base domain, and click Create Zone.

2. Get the Config: Click the Snippets button next to your new domain.

3. Deploy: Select your device type and copy the generated configuration block directly into your router's CLI.

Note: IPv4 and IPv6 (Dual-Stack) are detected and updated automatically based on the incoming connection.

⚠ Team over zone limit — {{ team.quota.used_zones }} zones in use, {{ team.quota.max_zones }} allowed by the combined plans of all team members. Existing zones keep working, but new zones can't be created until a member upgrades their plan or zones are deleted.
.
Domain & Tools Current IP TSIG DNSSEC SSL Cert
{{ zone.name }} ⚠
{{ zone.owner_email === activeUser.email ? 'You' : zone.owner_email }}
Locked
{{ zone.ip }}
Sync: {{ formatSyncTime(zone.last_sync) }}
Delegation required
{{ certDaysLabel(zone) }}
No domains registered. Create one above to get started.

Custom Namespaces (BYOD)

{{ showByod ? 'Hide' : 'Show' }}

Bring your own domain to DynIP. Once added, you can provision dynamic subdomains under your own namespace.

{{ dom.domain }}

Validated via {{ dom.validation_method === 'txt' ? 'TXT' : 'NS' }}

Quick Sync

{{ showSync ? 'Hide' : 'Show' }}

Instantly update your selected zones to match this device's current external IP address.

📡
Detected Network IP
{{ mobileIp || 'Detecting...' }}
No zones available. Create one above.

API Automation

{{ showApi ? 'Hide' : 'Show' }}

Quick test (uses your session — expires when you log out)

Programmatically register new zones with your current session token. Send a POST request to the /register endpoint.

curl -X POST "{{ backendUrl }}/register?subdomain=my-new-router&base_domain={{ baseDomains[0] }}" \
     -H "Authorization: Bearer {{ token }}"

Session tokens expire on logout — use an API token below for long-running automation.

API tokens (Pro+)

API tokens are a Pro feature

Long-lived tokens for automation: monitoring scripts, CI pipelines, MSP integrations. Tokens don't expire when you log out.

Upgrade to Pro →

Long-lived tokens for automation. Each token can be scoped read-only or full access, and revoked at any time.

Loading tokens…
No API tokens yet. Create one to get started.
Name Token Scope Last used Expires Action
{{ t.name }} {{ t.token_prefix }} {{ t.scope === 'read' ? 'Read-only' : 'Full' }} {{ t.last_used_at ? formatPlanDate(t.last_used_at) : 'Never' }} {{ t.expires_at ? formatPlanDate(t.expires_at) : 'Never' }}

Teams {{ team.members.length }} members

{{ showTeams ? 'Hide' : 'Show' }}

Invite others to share access to your zones. Zone quotas pool across all team members' plans. Owning a team requires a Pro or higher subscription; members can be on any plan.

Loading team…

Invite a member

They'll get an email with an accept link, valid 7 days. When they accept, their zones join the team and their plan's zone allowance is added to the pool.

{{ inviteModal.error }}

Team invitation

{{ teamInvite.preview.owner_email }} invited you to join {{ teamInvite.preview.team_name }}.

This invitation was sent to {{ teamInvite.preview.invited_email }}, which doesn't match this account. Sign in with that account to accept.
If you accept, the zones on your account move to the shared team and everyone on the team can manage them. If you later leave or are removed, your zones come back with you.

{{ teamInvite.error }}

New API Token

Tokens are shown once at creation — store them in a password manager or secrets vault.

{{ apiTokenModal.error }}

⚠ Save this token now

This token won't be shown again. Store it somewhere secure (1Password, Bitwarden, your CI's secrets manager).

{{ apiTokenModal.created.token }}

🔑 Save your backup codes

Each code works once. Store them somewhere safe — a password manager or printed copy. They won't be shown again; if you lose them, generate a new set.

{{ code }}

Generate new backup codes

Generating new codes invalidates your current set. Your saved codes will no longer work.

{{ regenerateModal.error }}

Account security

TOTP Enabled

This overrides email 2FA.

Backup Codes

Single-use codes to sign in if you lose access to your authenticator. {{ backupCodesStatus.remaining }} of {{ backupCodesStatus.total }} remaining.

You're running low on backup codes. Generate a new set to ensure you can recover access if you lose your authenticator.

Upgrade your account security by requiring a time-based code from Google Authenticator or another TOTP app when you sign in.

1. Scan the QR Code

Open Google Authenticator, Authy, or your preferred 2FA app and scan this code.

2. Verify & Save

Same secret as the QR — for password managers and authenticators that can't scan it.

Delete account

Permanently delete your account, all DNS zones you have created, and any TLS certificates issued to them. This cannot be undone or reversed by support.

Permanently delete your account?

This action cannot be undone. Deletion will:

  • Remove all your DNS zones immediately
  • Cancel any active TLS certificates
  • Cannot be reversed by support
  • Your data will be deleted; billing records retained per Swedish law (7 years)

If you have an active paid subscription, please cancel it first via your account billing area.

{{ deleteAccount.error }}