Dynamic DNS · wildcard certificates · EU-hosted

Every service in your house, reachable by name. With a padlock.

One wildcard Let’s Encrypt certificate covers everything under yourname.home.network, including the services that never touch the public internet. Dynamic DNS keeps your addresses current.

.home.network

€4 a month. 14-day trial, cancel anytime.

dyndns2
# what your router already does, pointed at us
curl -u alice:TOKEN \
  "https://api.home.network/nic/update?hostname=nas.alice.home.network&myip=auto"
good 192.168.1.10

What it looks like when it works

Reach your NAS by name

nas.alice.home.network resolves at home, on mobile data, and on your tailnet. One name, every device, no port forwarding and no bookmarked IP addresses.

Padlocks on everything

Home Assistant, Jellyfin, Proxmox and the router admin page all served over HTTPS with a real certificate. No browser warnings, no self-signed exceptions, no certificate to click through on a phone.

Your device names stay private

One wildcard covers every service, so nothing internal is published. nas, nvr and bitwarden never appear in Certificate Transparency logs.

Set up in about five minutes

1. Your router updates the address

Standard dyndns2, already built into FritzBox, OpenWrt, Synology, Ubiquiti and ddclient. Nothing to install.

2. Your proxy gets the certificate

Standard acme-dns, already supported by Caddy, Traefik, acme.sh, lego and cert-manager. The software you already run is the client.

3. Renewal takes care of itself

Renewals run on your hardware, unattended. We store TXT records and nothing else, so your private keys never leave your network.

dynamic DNS
# a router, or anything that speaks dyndns2
curl -u alice:TOKEN \
  "https://api.home.network/nic/update?hostname=nas.alice.home.network&myip=auto"
Caddyfile, wildcard cert for *.alice.home.network
tls {
  dns acmedns {
    username   "6f1c..."
    password   "..."
    subdomain  "b2a4..."
    server_url "https://api.home.network/acmedns"
  }
}

Works with the hardware already on your shelf

Both halves use published protocols rather than a proprietary client, so the software you already run is the client. Anything that speaks dyndns2 updates a record, and anything that speaks acme-dns gets a certificate.

Routers and NAS boxes

FRITZ!Box · OpenWrt · Synology DSM · QNAP · UniFi and UDM · pfSense · OPNsense · MikroTik · DD-WRT · Keenetic · ASUS · TrueNAS

Plus ddclient, inadyn, or four lines of cron on anything with curl.

Certificate clients

Caddy · Traefik · acme.sh · lego · cert-manager · Certbot · Nginx Proxy Manager · step-ca

Wildcard issuance over DNS-01, so nothing needs port 80 and nothing needs to be reachable from the internet.

Why €4 beats free

Records update in under a second

Writes land in the authoritative database directly, with no zone reload and no propagation wait. When your router changes address at 03:00, the name follows before you notice.

Two nameservers, two datacentres

Independent machines in separate facilities, both DNSSEC-signed, backed by a database replicated four ways with point-in-time recovery. Your DNS fails at the worst possible moment, so ours is built not to.

One-click export of your zone

A standard BIND file of every record, ready to load into any nameserver, available whenever you want it. Monthly billing means you are never committed beyond the current cycle.

Privacy is the default, not a setting

Wildcard-only issuance

Challenges are writable only at the label apex, so the only certificates obtainable are alice.home.network and *.alice.home.network. Per-hostname certificates are impossible by construction, which is what keeps your internal names out of public logs.

No query logs, no tracking

DNS query logging is off, leaving aggregate counters only. No third-party analytics, no pixels, no fingerprinting. Data never collected is data nobody can lose, leak, or be compelled to produce.

Any network underneath

Point a record at a LAN address, a public IP, or an overlay address from Tailscale, Headscale, Netbird or plain WireGuard. Your names stay the same when you switch between them. Names and certificates for a tailnet →

EU companies, EU datacentres

Nameservers and database on EU-headquartered providers, customer data at rest in EU facilities. The full inventory is on the privacy page.

Get started Read the docs