Docs › Dynamic DNS

Dynamic DNS on OpenWrt

Install the ddns-scripts package with an HTTPS-capable fetcher, then add one service block. On 25.12 and later the package manager is apk: apk update && apk add ddns-scripts ca-certificates wget-ssl.

Where the setting lives

/etc/config/ddns, or Services ▸ Dynamic DNS in LuCI

Configuration

/etc/config/ddns
config service 'home_network'
  option enabled     '1'
  option update_url  'https://[USERNAME]:[PASSWORD]@api.home.network/nic/update?hostname=[DOMAIN]&myip=[IP]'
  option domain      'nas.alice.home.network'
  option username    'alice'
  option password    '<your update password>'
  option lookup_host 'nas.alice.home.network'
  option ip_source   'web'
  option ip_url      'https://ip.app'

Replace alice with your label and <your update password> with the password from the setup wizard. The username is your label, never your email address.

Worth knowing. Two traps here, and the first fails silently. ddns-scripts has no separate authentication step: it only substitutes into the URL, so credentials must be embedded as [USERNAME]:[PASSWORD]@ or the request goes out unauthenticated. Values are URL-encoded during substitution, so a token containing punctuation is safe. Second, do not set service_name at all. There is no service called "custom", and LuCI writes option service_name '-' when you pick --custom--, which has to be deleted by hand. ip_source 'web' is correct behind carrier-grade NAT, where reading the interface reports an address nobody can reach.

Check it worked

verify
# confirm the record moved
dig +short nas.alice.home.network @ns1.home.network

# the update endpoint answers with the dyndns2 status word
curl -u 'alice:<your update password>' \
  'https://api.home.network/nic/update?hostname=nas.alice.home.network&myip=auto'
good 203.0.113.7

good means the record changed, nochg means it was already correct. Both are success. badauth means the username or password is wrong, and 911 means the fault is at our end, so retry rather than reconfigure.

Still not resolving at home?

If the name answers from ns1.home.network but not from your own resolver, the resolver is stripping the private address as rebind protection. Fix it for your resolver.

← All documentation