Dynamic DNS · wildcard certificates · EU-hosted
Every service in your house, reachable by name. With a padlock.
One wildcard Let’s Encrypt certificate covers everything under yourname.home.network, including the services that never touch the public internet. Dynamic DNS keeps your addresses current.
€4 a month. 14-day trial, cancel anytime.
# what your router already does, pointed at us
curl -u alice:TOKEN \
"https://api.home.network/nic/update?hostname=nas.alice.home.network&myip=auto"
good 192.168.1.10What it looks like when it works
Reach your NAS by name
nas.alice.home.network resolves at home, on mobile data, and on your tailnet. One name, every device, no port forwarding and no bookmarked IP addresses.
Padlocks on everything
Home Assistant, Jellyfin, Proxmox and the router admin page all served over HTTPS with a real certificate. No browser warnings, no self-signed exceptions, no certificate to click through on a phone.
Your device names stay private
One wildcard covers every service, so nothing internal is published. nas, nvr and bitwarden never appear in Certificate Transparency logs.
Set up in about five minutes
1. Your router updates the address
Standard dyndns2, already built into FritzBox, OpenWrt, Synology, Ubiquiti and ddclient. Nothing to install.
2. Your proxy gets the certificate
Standard acme-dns, already supported by Caddy, Traefik, acme.sh, lego and cert-manager. The software you already run is the client.
3. Renewal takes care of itself
Renewals run on your hardware, unattended. We store TXT records and nothing else, so your private keys never leave your network.
# a router, or anything that speaks dyndns2
curl -u alice:TOKEN \
"https://api.home.network/nic/update?hostname=nas.alice.home.network&myip=auto"tls {
dns acmedns {
username "6f1c..."
password "..."
subdomain "b2a4..."
server_url "https://api.home.network/acmedns"
}
}Works with the hardware already on your shelf
Both halves use published protocols rather than a proprietary client, so the software you already run is the client. Anything that speaks dyndns2 updates a record, and anything that speaks acme-dns gets a certificate.
Routers and NAS boxes
FRITZ!Box · OpenWrt · Synology DSM · QNAP · UniFi and UDM · pfSense · OPNsense · MikroTik · DD-WRT · Keenetic · ASUS · TrueNAS
Plus ddclient, inadyn, or four lines of cron on anything with curl.
Certificate clients
Caddy · Traefik · acme.sh · lego · cert-manager · Certbot · Nginx Proxy Manager · step-ca
Wildcard issuance over DNS-01, so nothing needs port 80 and nothing needs to be reachable from the internet.
Why €4 beats free
Records update in under a second
Writes land in the authoritative database directly, with no zone reload and no propagation wait. When your router changes address at 03:00, the name follows before you notice.
Two nameservers, two datacentres
Independent machines in separate facilities, both DNSSEC-signed, backed by a database replicated four ways with point-in-time recovery. Your DNS fails at the worst possible moment, so ours is built not to.
One-click export of your zone
A standard BIND file of every record, ready to load into any nameserver, available whenever you want it. Monthly billing means you are never committed beyond the current cycle.
Privacy is the default, not a setting
Wildcard-only issuance
Challenges are writable only at the label apex, so the only certificates obtainable are alice.home.network and *.alice.home.network. Per-hostname certificates are impossible by construction, which is what keeps your internal names out of public logs.
No query logs, no tracking
DNS query logging is off, leaving aggregate counters only. No third-party analytics, no pixels, no fingerprinting. Data never collected is data nobody can lose, leak, or be compelled to produce.
Any network underneath
Point a record at a LAN address, a public IP, or an overlay address from Tailscale, Headscale, Netbird or plain WireGuard. Your names stay the same when you switch between them. Names and certificates for a tailnet →
EU companies, EU datacentres
Nameservers and database on EU-headquartered providers, customer data at rest in EU facilities. The full inventory is on the privacy page.