Docs › Dynamic DNS

Dynamic DNS on pfSense

pfSense sends real HTTP Basic authentication, so the credentials stay in their own fields. Add a client with Service Type set to Custom.

Where the setting lives

Services ▸ Dynamic DNS ▸ Dynamic DNS Clients

Configuration

pfSense: Services ▸ Dynamic DNS
Service Type: Custom
Username:     alice
Password:     <your update password>
Update URL:   https://api.home.network/nic/update?hostname=nas.alice.home.network&myip=%IP%
Result Match: (leave empty)

Replace alice with your label and <your update password> with the password from the setup wizard. The username is your label, never your email address.

Worth knowing. %IP% is the only token pfSense substitutes, so write the hostname out in full rather than looking for a hostname variable. Leave Result Match empty. pfSense compares it exactly, so putting good there marks every nochg response as a failure, and nochg is the normal answer once the address has settled.

Check it worked

verify
# confirm the record moved
dig +short nas.alice.home.network @ns1.home.network

# the update endpoint answers with the dyndns2 status word
curl -u 'alice:<your update password>' \
  'https://api.home.network/nic/update?hostname=nas.alice.home.network&myip=auto'
good 203.0.113.7

good means the record changed, nochg means it was already correct. Both are success. badauth means the username or password is wrong, and 911 means the fault is at our end, so retry rather than reconfigure.

Still not resolving at home?

If the name answers from ns1.home.network but not from your own resolver, the resolver is stripping the private address as rebind protection. Fix it for your resolver.

← All documentation