Automation
Your IP changes. Nothing else has to.
Your router tells InfraNest its new address, and everything that depends on it follows — the A and AAAA records so your name keeps resolving, and the cloud firewall rules so you are not locked out of your own servers. There is nothing to install: it speaks the dynamic DNS your router already has built in.
Free plan · No credit card · Works with the router you already have
- DNS records and firewall rules, one address
- Nothing to install on your router
- Only your entry in the rule is touched
- Told when it stops, before it costs you
IPv4
84.24.117.62
IPv6
2a02:a44f:12c3:1:9ad3:74be:5f01:2c18
Network
Utrecht · KPN B.V.
Last seen
1m
When it checks in, these update
Safety
Recent changes
Keep A (IPv4) and AAAA (IPv6) records pointed at this IP. Pick an existing record, or create a new one here.
Whitelist this IP in a firewall rule (e.g. allow SSH from your home IP). Only your entry is updated — other IPs in the rule are left untouched. It follows the IP your client reports (public addresses only), and every change is alerted.
A firewall target changes who can reach your servers (e.g. SSH). Check the rule and IP version carefully — you are responsible for the result; InfraNest accepts no liability for lockouts or exposure.
Your router tells InfraNest what your address is. Put the details below into your router’s Dynamic DNS settings, and everything you’ve linked follows it automatically.
Server
Just the address — no https:// in front
dyn.infranest.ioHostname
Any name your router accepts — we update whatever you linked below
vpn.northwind.comUsername
Identifies this Dynamic IP. It is not a password
dyn-4m2qhv7kPassword
Treat this like a password — only your router needs it
••••••••••••••••••••••••Your router reached us 1m and everything worked.
Works with your DNS providers
Not just DNS — the firewall rule as well
Most dynamic-DNS tools stop at the name. But if you allow SSH from your home IP, that allow-list is the thing that actually locks you out when your provider hands you a new address on a Sunday morning. InfraNest updates both from the same check-in. And it does it surgically: it changes the one entry it wrote and leaves every other IP in that rule exactly as it was, because a tool that rewrote your whole allow-list would be a security incident rather than a convenience.
- Only the entry we wrote is ever changed — every other IP in the rule is left alone
- The live rule is read back from your provider before every write, so a change you made in their console is not silently reverted
- A firewall only ever follows the address you genuinely connected from — the reported ?ipv4 override that DNS honours is ignored here, because a query parameter must not be able to open a port
- Always a single host route, /32 or /128, never a range
- Private, reserved and carrier-grade NAT addresses are never written anywhere
Whitelist this IP in a firewall rule (e.g. allow SSH from your home IP). Only your entry is updated — other IPs in the rule are left untouched. It follows the IP your client reports (public addresses only), and every change is alerted.
A firewall target changes who can reach your servers (e.g. SSH). Check the rule and IP version carefully — you are responsible for the result; InfraNest accepts no liability for lockouts or exposure.
This firewall rule no longer exists, so your address isn’t being kept up to date. Check the entry we last allowed — it may now point at someone else’s address.
Since 3d
You find out when it stops — that is the whole point
This is the part the category gets wrong. A dynamic-DNS updater that quietly stopped looks exactly like one that is working, right up until your name points at an address your provider has since given to somebody else. So InfraNest treats silence as news. Two days without a check-in and the row turns amber and you are told. And when a push fails, you are told what kind of failure it was — because “the provider refused it”, “that address is unreachable” and “the rule is gone” are three different problems that used to read as one.
- Two days of silence turns the row amber and sends one alert — cleared by any check-in, including a “nothing changed”
- What your provider actually accepted is tracked separately from what we wrote, and retried on every check-in until the two agree
- A firewall rule that lost its handle is the loudest alert in the module: the entry we last wrote is still open, on an address that may no longer be yours
- A DNS target that could never publish is refused when you create it, instead of reporting success forever
- One alert per problem, so the timestamp reads as “broken since” rather than arriving all over again every few minutes
Keep DNS records and firewall rules in sync with a changing IP — home connection, VPN endpoint, or any host without a static IP.
2 of 5 aren’t reporting yet.
Rotterdam line, Berlin office
They won’t update anything until their update URL is called at least once.
This firewall rule no longer exists, so your address isn’t being kept up to date. Check the entry we last allowed — it may now point at someone else’s address.
Recheck nowView detailLast update was 2 days ago — the source may have stopped checking in.
Recheck nowView detailNothing to sync yet — add a target and copy the update URL to finish.
Add targetFinish setupNothing to install — your router already speaks it
There is no agent and no daemon. InfraNest speaks dyndns2, the same protocol consumer routers and ddclient have implemented for twenty years, so your router is the client. Pick your device and the page shows the exact boxes that device asks for, filled in. And because routers do not send the URL you gave them — they keep the host and append a path of their own — six different aliases are accepted, so whatever yours appends still lands.
- Speaks dyndns2, which your router, OPNsense, pfSense or ddclient already implements
- Presets for FRITZ!Box, UniFi, Synology, ddclient, the command line and most other routers
- The exact fields your device asks for, with its own placeholders left intact
- Six URL aliases, so whichever path your router appends, the update still arrives
- Works equally from a cron line or a script — it is one HTTPS call
Which device are you setting up?
Set the service to “Custom” and fill in the boxes below. Works on OPNsense, pfSense, ASUS, MikroTik and most others. Step-by-step guide
Most routers ask for these under “Dynamic DNS”, with the service set to “Custom”. Copy each value into the box with the matching name.
Server
Just the address — no https:// in front
dyn.infranest.ioHostname
Any name your router accepts — we update whatever you linked below
vpn.northwind.comUsername
Identifies this Dynamic IP. It is not a password
dyn-4m2qhv7kPassword
Treat this like a password — only your router needs it
••••••••••••••••••••Under Internet › Permit Access › DynDNS, choose “Custom”. Paste the update address, then fill in the other boxes. Step-by-step guide
Most routers ask for these under “Dynamic DNS”, with the service set to “Custom”. Copy each value into the box with the matching name.
Update URL
Paste the whole address, exactly as shown
https://dyn.infranest.io/••••••••••••••••••••?ipv4=<ipaddr>&ipv6=<ip6addr>Hostname
Any name your router accepts — we update whatever you linked below
vpn.northwind.comUsername
Identifies this Dynamic IP. It is not a password
dyn-4m2qhv7kPassword
Treat this like a password — only your router needs it
••••••••••••••••••••Under Internet › Dynamic DNS, choose service “Custom”. The Server box takes the address and path together. Step-by-step guide
Most routers ask for these under “Dynamic DNS”, with the service set to “Custom”. Copy each value into the box with the matching name.
Server
Just the address — no https:// in front
dyn.infranest.io/nic/update?hostname=%h&myip=%iHostname
Any name your router accepts — we update whatever you linked below
vpn.northwind.comUsername
Identifies this Dynamic IP. It is not a password
dyn-4m2qhv7kPassword
Treat this like a password — only your router needs it
••••••••••••••••••••In DSM, Control Panel › External Access › DDNS › Customize provider. Paste the query URL, then add your details. Step-by-step guide
Most routers ask for these under “Dynamic DNS”, with the service set to “Custom”. Copy each value into the box with the matching name.
Query URL
Paste the whole address, exactly as shown
https://dyn.infranest.io/nic/update?hostname=__HOSTNAME__&myip=__IP__Hostname
Any name your router accepts — we update whatever you linked below
vpn.northwind.comUsername
Identifies this Dynamic IP. It is not a password
dyn-4m2qhv7kPassword
Treat this like a password — only your router needs it
••••••••••••••••••••Add this to /etc/ddclient.conf. Anything that speaks dyndns2 works the same way. Step-by-step guide
Paste this into the config file or run it as-is. It already contains your details.
protocol=dyndns2 server=dyn.infranest.io ssl=yes login=dyn-4m2qhv7k password='••••••••••••••••••••' vpn.northwind.com
Run it from a cron job every few minutes, or from a script when your connection comes up. Step-by-step guide
Paste this into the config file or run it as-is. It already contains your details.
curl -sS -u 'dyn-4m2qhv7k:••••••••••••••••••••' 'https://dyn.infranest.io/'
Your router reached us 1m and everything worked. 84.24.117.62 · FRITZ!Box 7590
Everything else it handles
The parts that are only interesting when you need them.
Attach it from where you already are
The same “Track with a Dynamic IP” option appears in the DNS record editor and the firewall rule editor, not only on this page. One source can drive many of both — a home connection updating three records and two firewall rules at once.
Where the connection came from
Every check-in resolves the address offline to a country, a city and the network it belongs to, so “is this still my office line?” is answerable at a glance rather than by pasting an IP into a lookup.
A flag when it moves to a datacentre
A source that is supposed to be a home or office line but arrives from a hosting or VPN network is usually a misconfigured or tunnelled client. That flag is also an automation condition, paired with a built-in action that closes the firewall access it granted.
Fail closed when it goes quiet
Switch it on and a source that stops reporting for about a week has its firewall openings removed and those targets disabled — so an abandoned or leaked token cannot leave a port open forever. The warning arrives an hour before, never after.
The token is treated as a password
Stored hashed, because the update endpoint is public by design. Revealing it again is a deliberate, re-authenticated and audited action, and you can rotate it whenever you like.
A username you can actually diagnose with
Every source carries a published username separate from the secret, so a failed login can be traced to a source. A wrong password against a real username fails exactly as a fake one does, so the endpoint cannot be used to discover which sources exist.
Alerts, webhooks and automations
Change, silence and broken-target alerts through your normal channels — email, Slack, Telegram or a webhook — plus an outbound dynamic_ip.changed event, and org-wide defaults so new sources start with the policy you want.
A history you can read
Every applied change is kept per source, old address to new, and written to the audit log alongside everything else.
Watch your own connection check in
Create a source and paste four values into your router. Nothing is updated until you link a record or a rule to it.
A free dynamic-DNS updater vs InfraNest
The difference between a name that still resolves and knowing whether it does.
A free updater
- The name quietly points at an address somebody else now holds
- DNS only — the firewall allow-list is still yours to remember
- Edit that allow-list by hand when your provider changes your address on a Sunday
- No way to tell a working updater from one that stopped a month ago
- A token you cannot rotate leaves a port open indefinitely
With InfraNest
- Two days of silence and you are told, before anything depends on it
- DNS records and cloud firewall rules follow the same check-in
- The allow-list entry rewrites itself — and only the entry that is yours
- Three named failures, each with the reason and what to do
- Fail closed removes the opening after a week, and warns you first
One login, ten modules
Every module is in every plan, Free included — what changes is how much of each you get.
The cost of doing it separately
Buy each piece from a different tool and it adds up fast:
- Domain & DNS
- ~€30
- Uptime monitoring
- ~€29
- SSL tracking
- ~€15
- Status page
- ~€29
- Server panel
- ~€15
- Across 4–5 separate tools
- €100–150/mo
Frequently asked
What is dynamic DNS, and why do I need it?
Most home and small-office connections do not get a fixed public address. Your provider hands you one and swaps it whenever it likes — often after a reconnect or a router reboot. Anything pointing at the old address then stops working: a name that no longer resolves to your machine, or a firewall rule that no longer lets you in. Dynamic DNS — DDNS — is the fix: something notices the new address and updates whatever depends on it. InfraNest does that for your DNS records and, unlike most DDNS services, for your cloud firewall rules too.
Will it work with my router — FRITZ!Box, UniFi, Synology?
Yes, and with almost anything else. InfraNest speaks dyndns2, the standard nearly every router implements: FRITZ!Box, UniFi, Synology, OPNsense, pfSense, ASUS, MikroTik and most consumer models, plus ddclient and inadyn. Pick your device on the setup screen and it shows the exact boxes that device asks for, already filled in. If yours is not listed, the generic “Custom” preset works — and so does a one-line curl from cron.
Can it update a firewall rule, not just DNS?
Yes, and that is the main reason to use it over a free dynamic-DNS service. Link a cloud firewall rule to a Dynamic IP and the address allowed by that rule follows your connection — useful for an SSH or database rule you want open to yourself and nobody else. Only your entry in the rule changes; every other IP in it is left untouched, and the address written is always a single host route.
What happens if my router stops reporting?
After two days without a check-in the source is marked stale and you get one alert — cleared the moment anything checks in again, including a “nothing changed”, which is what a healthy router sends most of the time. If you have turned on fail closed, a source silent for about a week has its firewall openings removed and those targets disabled, and the earlier warning tells you how many days are left. The two run an hour apart deliberately, so the warning is a warning and never a post-mortem.
Is it safe to let a tool change my firewall?
It is the part we have been most careful with. The live rule is re-read from your provider before every write, so nothing you changed in their console is reverted. Only the entry InfraNest wrote is modified. The address is always a single host route, never a range, and never a private or unroutable one. A firewall follows only the address you genuinely connected from — the reported override that DNS accepts is ignored outright, because a query parameter must not be able to open a port. Enabling a firewall target can require re-authentication if your organisation turns that on.
Does it work behind CGNAT?
Not usefully, and it says so rather than pretending. If your provider puts you behind carrier-grade NAT, the address your router reports is not reachable from the internet, so publishing it would point your name at nothing. InfraNest refuses to write it and tells you why — your provider can usually give you a real public address, often for free, if you ask.
How many Dynamic IPs can I have?
Two on the free plan, twenty-five on Pro and unlimited on Business. Each one can drive as many DNS records and firewall rules as you need, so a single home connection keeping three names and two rules in sync counts as one.
One address, everything follows
Create a source and point your router at it — two are included free.
Free plan · No credit card required · Set up in minutes