Integration Guides

Use DynIP with the tools you already run

Step-by-step integration walkthroughs covering reverse proxies, mesh VPNs, home automation, and edge firewalls. Each guide is self-contained and assumes you already have a DynIP zone provisioned (free tier is enough). For the underlying REST and RFC 2136 reference, see the API documentation.

Automation · AI

AI Agents

Install a DynIP skill or tool into Claude Code, opencode, Cursor, Open WebUI or a Hermes-style model, and let it publish and change records itself — over the HTTP API or RFC 2136, whichever the job needs.

Mesh VPN

Tailscale

Use DynIP for public DNS alongside Tailscale's private mesh. One host, two hostnames, one TLS certificate.

Mesh VPN

Netbird

Self-hosted WireGuard mesh on a stable DynIP hostname. Drop the updater container into Netbird's docker-compose; bundled Traefik handles TLS.

Reverse Proxy + TLS

Caddy

Get automatic Let's Encrypt certificates via the DNS-01 challenge without exposing port 80. Single Caddyfile.

Home Automation

Home Assistant

Secure remote access to Home Assistant via a DynIP hostname and a reverse proxy with WebSocket support and TLS.

Reverse Proxy + TLS

Traefik

A multi-service Docker stack with TLS handled by Traefik and DNS-01 certificates issued through DynIP.

Edge Firewall

FortiGate

Native RFC 2136 dynamic DNS configuration on FortiOS with TSIG authentication. SD-WAN and multi-site ready.

Prosumer Router

MikroTik RouterOS

Native DDNS via /tool fetch. Works on RouterOS 6 and 7. Covers public dual-stack, IPv6, and private APN scenarios.

Prosumer Router

UniFi

Keep your zone's A record on the gateway's WAN IPv4 using UniFi's built-in Dynamic DNS client — UDM, UDR and UXG. Why to pick Custom over “Nsupdate”, field by field.

Kubernetes

external-dns

Publish DNS records from Kubernetes Service and Ingress annotations over RFC 2136 / TSIG. Covers upsert-only and full sync (delete) policy modes.

Kubernetes · TLS

cert-manager

Issue Let's Encrypt TLS certificates for a DynIP zone via the ACME DNS-01 challenge over RFC 2136 / TSIG. No port 80, no public ingress — covers the DNSSEC precondition and controller setup.

Virtualization · TLS

Proxmox VE

Let's Encrypt certificates for the Proxmox web UI via the built-in ACME client and RFC 2136 / TSIG. One non-interactive script; renewals handled by Proxmox itself. Covers PBS and PMG too.

Reference

Protocols DynIP speaks

The three update protocols — dyndns2 over HTTP (inadyn, ddclient, routers, UniFi), RFC 2136 DNS UPDATE over TSIG (external-dns, lego, certbot, nsupdate), and the native JSON API. What each is for, which clients use it, and how the platform picks a response format.

Operations & Scale

Fleet Operations

Managing hundreds or thousands of devices with DynIP. Naming, programmatic provisioning, monitoring, and the CGNAT / private-APN patterns common in cellular fleets. Includes a worked postal-locker example throughout.

Missing a guide?

More guides are landing roughly once a month — next up are Headscale, Plex/Jellyfin remote access, and a Cloudflare Tunnel comparison. If there's something specific you want covered sooner, let us know.