# Account Verification Source: https://docs.stackryze.com/docs/account-verification Verify your account to unlock custom domains, DNSSEC, and API tokens. Account verification is a one-time step that unlocks the full Stackryze surface — custom domains, DNSSEC signing, API tokens, webhook secrets, and higher rate limits. ## When do I need to verify? You'll be asked to verify if any of the following apply to your account: * You want to add a custom domain you don't own through Stackryze Domains * You want to enable DNSSEC on a delegated zone * You want to issue API tokens * Your zones have crossed the free-tier limits ## How to verify From the dashboard, click your avatar, then **Settings**, then the **Verification** tab. We send a confirmation link to the address on file. Click it within 24 hours. You need at least one of: * A domain you've proven control of (via a DNS TXT record we generate) * A payment method on file (we charge \$0 and refund immediately) Most verifications complete automatically within 60 seconds. Manual review (rare) completes within one business day. ## What you get | Unlocks | Free | Verified | | ------------------ | ---- | --------- | | Number of zones | 3 | Unlimited | | Records per zone | 100 | 1,000 | | API tokens | — | Yes | | Webhooks | — | Yes | | DNSSEC signing | — | Yes | | Custom nameservers | — | Yes | Stackryze DNS is **always free** — verification just raises limits and unlocks advanced features. No plan is ever required. # v0.1.0 Source: https://docs.stackryze.com/docs/changelog/domains/v0.1.0 **Release date:** Jul 1, 2023 ship the activity feed on the My Domains dashboard. # v0.10.0 Source: https://docs.stackryze.com/docs/changelog/domains/v0.10.0 **Release date:** Jan 24, 2024 ship the domain detail page with nameserver management. # v0.11.0 Source: https://docs.stackryze.com/docs/changelog/domains/v0.11.0 **Release date:** Feb 16, 2024 expose a registration REST endpoint at POST /v1/domains. # v0.12.0 Source: https://docs.stackryze.com/docs/changelog/domains/v0.12.0 **Release date:** Mar 10, 2024 ship a webhook for domain lifecycle events. # v0.13.0 Source: https://docs.stackryze.com/docs/changelog/domains/v0.13.0 **Release date:** Apr 2, 2024 ship TLS provisioning via ACME DNS-01 for every registered name. # v0.14.0 Source: https://docs.stackryze.com/docs/changelog/domains/v0.14.0 **Release date:** Apr 25, 2024 ship account lockout after 5 failed logins (30-minute cooldown). # v0.15.0 Source: https://docs.stackryze.com/docs/changelog/domains/v0.15.0 **Release date:** May 18, 2024 ship push notifications for renewals and abuse actions. # v0.16.0 Source: https://docs.stackryze.com/docs/changelog/domains/v0.16.0 **Release date:** Jun 10, 2024 add support for custom user-agent strings on abuse reports. # v0.17.0 Source: https://docs.stackryze.com/docs/changelog/domains/v0.17.0 **Release date:** Jul 3, 2024 add CAPTCHA-free registration for verified accounts. # v0.18.0 Source: https://docs.stackryze.com/docs/changelog/domains/v0.18.0 **Release date:** Jul 26, 2024 ship rate limits per IP for the registration endpoint. # v0.19.0 Source: https://docs.stackryze.com/docs/changelog/domains/v0.19.0 **Release date:** Aug 18, 2024 ship documentation pages for the four-namespace model. # v0.2.0 Source: https://docs.stackryze.com/docs/changelog/domains/v0.2.0 **Release date:** Jul 24, 2023 ship region-aware resolution — preferred nameserver selection now considers the resolver's region. # v0.20.0 Source: https://docs.stackryze.com/docs/changelog/domains/v0.20.0 **Release date:** Sep 10, 2024 ship the activity feed on the My Domains dashboard. # v0.21.0 Source: https://docs.stackryze.com/docs/changelog/domains/v0.21.0 **Release date:** Oct 3, 2024 ship region-aware resolution — preferred nameserver selection now considers the resolver's region. # v0.22.0 Source: https://docs.stackryze.com/docs/changelog/domains/v0.22.0 **Release date:** Oct 26, 2024 open the closed beta to verified accounts only. # v0.23.0 Source: https://docs.stackryze.com/docs/changelog/domains/v0.23.0 **Release date:** Nov 18, 2024 ship a deletion flow with a 7-day cooling-off period. # v0.24.0 Source: https://docs.stackryze.com/docs/changelog/domains/v0.24.0 **Release date:** Dec 11, 2024 ship the My Domains dashboard. # v0.25.0 Source: https://docs.stackryze.com/docs/changelog/domains/v0.25.0 **Release date:** Jan 3, 2025 ship the nameserver-delegation walkthrough in the dashboard. # v0.26.0 Source: https://docs.stackryze.com/docs/changelog/domains/v0.26.0 **Release date:** Jan 26, 2025 ship the domain detail page with nameserver management. # v0.27.0 Source: https://docs.stackryze.com/docs/changelog/domains/v0.27.0 **Release date:** Feb 18, 2025 expose a registration REST endpoint at POST /v1/domains. # v0.28.0 Source: https://docs.stackryze.com/docs/changelog/domains/v0.28.0 **Release date:** Mar 13, 2025 ship a webhook for domain lifecycle events. # v0.29.0 Source: https://docs.stackryze.com/docs/changelog/domains/v0.29.0 **Release date:** Apr 5, 2025 ship TLS provisioning via ACME DNS-01 for every registered name. # v0.3.0 Source: https://docs.stackryze.com/docs/changelog/domains/v0.3.0 **Release date:** Aug 16, 2023 open the closed beta to verified accounts only. # v0.30.0 Source: https://docs.stackryze.com/docs/changelog/domains/v0.30.0 **Release date:** Apr 28, 2025 ship account lockout after 5 failed logins (30-minute cooldown). # v0.31.0 Source: https://docs.stackryze.com/docs/changelog/domains/v0.31.0 **Release date:** May 21, 2025 ship push notifications for renewals and abuse actions. # v0.32.0 Source: https://docs.stackryze.com/docs/changelog/domains/v0.32.0 **Release date:** Jun 13, 2025 add support for custom user-agent strings on abuse reports. # v0.33.0 Source: https://docs.stackryze.com/docs/changelog/domains/v0.33.0 **Release date:** Jul 6, 2025 add CAPTCHA-free registration for verified accounts. # v0.34.0 Source: https://docs.stackryze.com/docs/changelog/domains/v0.34.0 **Release date:** Jul 29, 2025 ship rate limits per IP for the registration endpoint. # v0.35.0 Source: https://docs.stackryze.com/docs/changelog/domains/v0.35.0 **Release date:** Aug 21, 2025 ship documentation pages for the four-namespace model. # v0.36.0 Source: https://docs.stackryze.com/docs/changelog/domains/v0.36.0 **Release date:** Sep 13, 2025 expose a renewal REST endpoint at POST /v1/domains/yourname.indevs.in/renew. # v0.37.0 Source: https://docs.stackryze.com/docs/changelog/domains/v0.37.0 **Release date:** Oct 6, 2025 ship a CLI: `stackryze domains register`, `stackryze domains renew`. # v0.38.0 Source: https://docs.stackryze.com/docs/changelog/domains/v0.38.0 **Release date:** Oct 29, 2025 publish the first version of the open-source deployment scripts. # v0.39.0 Source: https://docs.stackryze.com/docs/changelog/domains/v0.39.0 **Release date:** Nov 21, 2025 open registrations to the waitlist. # v0.4.0 Source: https://docs.stackryze.com/docs/changelog/domains/v0.4.0 **Release date:** Sep 8, 2023 ship a deletion flow with a 7-day cooling-off period. # v0.40.0 Source: https://docs.stackryze.com/docs/changelog/domains/v0.40.0 **Release date:** Dec 14, 2025 ship an improved nameserver health check from the registry side. # v0.41.0 Source: https://docs.stackryze.com/docs/changelog/domains/v0.41.0 **Release date:** Jan 6, 2026 ship wildcard subdomain support (\*.yourname.indevs.in) on the registry side. # v0.42.0 Source: https://docs.stackryze.com/docs/changelog/domains/v0.42.0 **Release date:** Jan 29, 2026 ship password reset by email link with a one-time token. # v0.43.0 Source: https://docs.stackryze.com/docs/changelog/domains/v0.43.0 **Release date:** Feb 21, 2026 ship inbox-only email forwarding at the registry layer (later removed). # v0.44.0 Source: https://docs.stackryze.com/docs/changelog/domains/v0.44.0 **Release date:** Mar 16, 2026 ship a self-service email-change flow with confirmation links. # v0.45.0 Source: https://docs.stackryze.com/docs/changelog/domains/v0.45.0 **Release date:** Apr 8, 2026 add support for second-factor authentication on the linked GitHub account. # v0.46.0 Source: https://docs.stackryze.com/docs/changelog/domains/v0.46.0 **Release date:** May 1, 2026 add scoped API tokens (read-only vs read-write vs registrar-only). # v0.5.0 Source: https://docs.stackryze.com/docs/changelog/domains/v0.5.0 **Release date:** April 15, 2026 Initial closed beta of Stackryze Domains. Email signup, GitHub OAuth, `indevs.in` subdomain registration with default nameservers pointing at Stackryze DNS, and a basic My Domains dashboard. 50 beta seats opened to friends and family. # v0.6.0 Source: https://docs.stackryze.com/docs/changelog/domains/v0.6.0 **Release date:** May 20, 2026 Custom nameserver configuration in the dashboard and the first API endpoints for registration and renewal. # v0.7.0 Source: https://docs.stackryze.com/docs/changelog/domains/v0.7.0 **Release date:** June 10, 2026 Open beta. Captcha-free registration for verified accounts, multi-domain dashboard view, and a 5-day renewal grace period with email reminders at 60 and 10 days out. # v0.8.0 Source: https://docs.stackryze.com/docs/changelog/domains/v0.8.0 **Release date:** Dec 9, 2023 ship the My Domains dashboard. # v0.9.0 Source: https://docs.stackryze.com/docs/changelog/domains/v0.9.0 **Release date:** Jan 1, 2024 ship the nameserver-delegation walkthrough in the dashboard. # v1.0.0 Source: https://docs.stackryze.com/docs/changelog/domains/v1.0.0 **Release date:** July 4, 2026 First stable release of Stackryze Domains. Public registration, 7-day cooling-off period on deletion, audit log of every account action, scoped API tokens, and 5-domains-per-account quota with email-based quota increase requests. # v0.1.0 Source: https://docs.stackryze.com/docs/changelog/hosting/v0.1.0 **Release date:** May 30, 2026 Internal alpha of Stackryze Hosting. The platform accepts a container image, serves it on a free subdomain under `stackryze.run`, and rolls back to a previous deploy on health-check failure. Limited to 5 Stackryze employees. # v0.1.1 Source: https://docs.stackryze.com/docs/changelog/hosting/v0.1.1 **Release date:** Jul 1, 2023 internal alpha: scheduled scale-down for predictable off-hours. # v0.10.3 Source: https://docs.stackryze.com/docs/changelog/hosting/v0.10.3 **Release date:** Jan 24, 2024 closed beta: Slack notifications on deploy start, success, and failure. # v0.11.0 Source: https://docs.stackryze.com/docs/changelog/hosting/v0.11.0 **Release date:** Feb 16, 2024 internal alpha: serve on free subdomains under `stackryze.run`. # v0.12.3 Source: https://docs.stackryze.com/docs/changelog/hosting/v0.12.3 **Release date:** Mar 10, 2024 internal alpha: cold-start budget under 800ms. # v0.13.2 Source: https://docs.stackryze.com/docs/changelog/hosting/v0.13.2 **Release date:** Apr 2, 2024 internal alpha: environment variable groups (dev / preview / prod). # v0.14.6 Source: https://docs.stackryze.com/docs/changelog/hosting/v0.14.6 **Release date:** Apr 25, 2024 internal alpha: per-project runtime metrics exported to a Prometheus endpoint. # v0.15.6 Source: https://docs.stackryze.com/docs/changelog/hosting/v0.15.6 **Release date:** May 18, 2024 internal alpha: CLI (`stackryze deploy`, `stackryze logs`, `stackryze rollback`). # v0.16.3 Source: https://docs.stackryze.com/docs/changelog/hosting/v0.16.3 **Release date:** Jun 10, 2024 private beta: automatic HTTPS via ACME DNS-01. # v0.17.2 Source: https://docs.stackryze.com/docs/changelog/hosting/v0.17.2 **Release date:** Jul 3, 2024 internal alpha: per-project egress cap with overage notifications. # v0.18.3 Source: https://docs.stackryze.com/docs/changelog/hosting/v0.18.3 **Release date:** Jul 26, 2024 internal alpha: per-deploy environment variables. # v0.19.5 Source: https://docs.stackryze.com/docs/changelog/hosting/v0.19.5 **Release date:** Aug 18, 2024 closed beta: Discord notifications on deploy events. # v0.2.0 Source: https://docs.stackryze.com/docs/changelog/hosting/v0.2.0 **Release date:** June 15, 2026 Private beta. Custom domains via Stackryze DNS, automatic HTTPS via ACME DNS-01, Git-based deploys from GitHub, build logs streamed in real time, and a deploy history view in the dashboard. # v0.2.3 Source: https://docs.stackryze.com/docs/changelog/hosting/v0.2.3 **Release date:** Jul 24, 2023 internal alpha: team access — invite collaborators with role-based permissions. # v0.20.5 Source: https://docs.stackryze.com/docs/changelog/hosting/v0.20.5 **Release date:** Sep 10, 2024 internal alpha: automatic platform version upgrades on a 14-day cadence. # v0.21.6 Source: https://docs.stackryze.com/docs/changelog/hosting/v0.21.6 **Release date:** Oct 3, 2024 internal alpha: the platform accepts a container image. # v0.22.4 Source: https://docs.stackryze.com/docs/changelog/hosting/v0.22.4 **Release date:** Oct 26, 2024 internal alpha: per-deploy SLOs surfaced in the dashboard. # v0.23.5 Source: https://docs.stackryze.com/docs/changelog/hosting/v0.23.5 **Release date:** Nov 18, 2024 private beta: per-deploy CPU and RAM metrics. # v0.24.5 Source: https://docs.stackryze.com/docs/changelog/hosting/v0.24.5 **Release date:** Dec 11, 2024 closed beta: preview environments per pull request. # v0.25.3 Source: https://docs.stackryze.com/docs/changelog/hosting/v0.25.3 **Release date:** Jan 3, 2025 private beta: deploy history view in the dashboard. # v0.26.1 Source: https://docs.stackryze.com/docs/changelog/hosting/v0.26.1 **Release date:** Jan 26, 2025 internal alpha: support for monorepo path filters in the Git deploy. # v0.27.1 Source: https://docs.stackryze.com/docs/changelog/hosting/v0.27.1 **Release date:** Feb 18, 2025 internal alpha: support for multi-stage Dockerfiles. # v0.28.2 Source: https://docs.stackryze.com/docs/changelog/hosting/v0.28.2 **Release date:** Mar 13, 2025 internal alpha: webhook subscriptions for build, deploy, and runtime events. # v0.29.1 Source: https://docs.stackryze.com/docs/changelog/hosting/v0.29.1 **Release date:** Apr 5, 2025 private beta: scheduled scaling for predictable traffic. # v0.3.0 Source: https://docs.stackryze.com/docs/changelog/hosting/v0.3.0 **Release date:** July 1, 2026 Closed beta. Free tier introduced (1 project, 1 GB egress per month), preview environments per pull request, environment variables with secret scanning, and a public roadmap at stackryze.com/hosting/roadmap. # v0.3.3 Source: https://docs.stackryze.com/docs/changelog/hosting/v0.3.3 **Release date:** Aug 16, 2023 closed beta: webhook subscriptions for deploy events. # v0.30.0 Source: https://docs.stackryze.com/docs/changelog/hosting/v0.30.0 **Release date:** Apr 28, 2025 private beta: build logs streamed in real time. # v0.31.4 Source: https://docs.stackryze.com/docs/changelog/hosting/v0.31.4 **Release date:** May 21, 2025 internal alpha: per-project audit log. # v0.32.5 Source: https://docs.stackryze.com/docs/changelog/hosting/v0.32.5 **Release date:** Jun 13, 2025 internal alpha: per-domain automatic TLS provisioning. # v0.33.4 Source: https://docs.stackryze.com/docs/changelog/hosting/v0.33.4 **Release date:** Jul 6, 2025 closed beta: free tier with usage limits. # v0.34.0 Source: https://docs.stackryze.com/docs/changelog/hosting/v0.34.0 **Release date:** Jul 29, 2025 closed beta: public roadmap with shipping estimates. # v0.35.5 Source: https://docs.stackryze.com/docs/changelog/hosting/v0.35.5 **Release date:** Aug 21, 2025 internal alpha: region selection (NYC, Hyderabad, Nuremberg, São Paulo). # v0.36.2 Source: https://docs.stackryze.com/docs/changelog/hosting/v0.36.2 **Release date:** Sep 13, 2025 internal alpha: roll back to any prior deploy with one click. # v0.37.0 Source: https://docs.stackryze.com/docs/changelog/hosting/v0.37.0 **Release date:** Oct 6, 2025 internal alpha: per-project log retention of 30 days. # v0.38.0 Source: https://docs.stackryze.com/docs/changelog/hosting/v0.38.0 **Release date:** Oct 29, 2025 private beta: custom domains via Stackryze DNS. # v0.39.4 Source: https://docs.stackryze.com/docs/changelog/hosting/v0.39.4 **Release date:** Nov 21, 2025 internal alpha: automatic rollback on health-check failure. # v0.4.3 Source: https://docs.stackryze.com/docs/changelog/hosting/v0.4.3 **Release date:** Sep 8, 2023 internal alpha: dashboard redesign — single project view, multi-project switcher. # v0.40.3 Source: https://docs.stackryze.com/docs/changelog/hosting/v0.40.3 **Release date:** Dec 14, 2025 internal alpha: GitHub commit status integration. # v0.41.4 Source: https://docs.stackryze.com/docs/changelog/hosting/v0.41.4 **Release date:** Jan 6, 2026 internal alpha: cost preview before deploy (CPU × memory × minutes). # v0.42.6 Source: https://docs.stackryze.com/docs/changelog/hosting/v0.42.6 **Release date:** Jan 29, 2026 internal alpha: per-project API tokens with scoped permissions. # v0.43.4 Source: https://docs.stackryze.com/docs/changelog/hosting/v0.43.4 **Release date:** Feb 21, 2026 internal alpha: log search by service, level, time range. # v0.44.1 Source: https://docs.stackryze.com/docs/changelog/hosting/v0.44.1 **Release date:** Mar 16, 2026 private beta: Git-based deploys from GitHub. # v0.45.0 Source: https://docs.stackryze.com/docs/changelog/hosting/v0.45.0 **Release date:** Apr 8, 2026 internal alpha: zero-downtime deploys via blue/green cutover. # v0.46.4 Source: https://docs.stackryze.com/docs/changelog/hosting/v0.46.4 **Release date:** May 1, 2026 closed beta: environment variables with secret scanning. # v0.47.0 Source: https://docs.stackryze.com/docs/changelog/hosting/v0.47.0 **Release date:** May 24, 2026 internal alpha: free tier hard limits (3 projects, 1 GB RAM, 100 GB transfer). # v0.5.1 Source: https://docs.stackryze.com/docs/changelog/hosting/v0.5.1 **Release date:** Oct 1, 2023 internal alpha: GitLab and Bitbucket connectors. # v0.6.6 Source: https://docs.stackryze.com/docs/changelog/hosting/v0.6.6 **Release date:** Oct 24, 2023 internal alpha: container image layers cached across deploys. # v0.7.3 Source: https://docs.stackryze.com/docs/changelog/hosting/v0.7.3 **Release date:** Nov 16, 2023 internal alpha: per-environment `DATABASE_URL` secret injection. # v0.8.0 Source: https://docs.stackryze.com/docs/changelog/hosting/v0.8.0 **Release date:** Dec 9, 2023 internal alpha: per-PR preview environments with shareable URLs. # v0.9.1 Source: https://docs.stackryze.com/docs/changelog/hosting/v0.9.1 **Release date:** Jan 1, 2024 internal alpha: build artifact retention of 14 days. # Changelog Source: https://docs.stackryze.com/docs/changelog/introduction Track every Stackryze release, feature, improvement, and platform update. Welcome to the Stackryze changelog. Pick a product tab below to see its release history. ## All releases ### 2026 | Version | Date | Highlights | | ----------------------------------- | -------------- | ------------------------------------------------------------------------------------------------------------ | | [v1.0.0](/docs/changelog/domains/v1.0.0) | July 4, 2026 | First stable release — public registration, 7-day cooling-off, audit log, scoped API tokens, 5-domain quota. | | [v0.7.0](/docs/changelog/domains/v0.7.0) | June 10, 2026 | Open beta — captcha-free registration, multi-domain dashboard, renewal grace period. | | [v0.6.0](/docs/changelog/domains/v0.6.0) | May 20, 2026 | Custom nameservers in the dashboard, first API endpoints for registration and renewal. | | [v0.5.0](/docs/changelog/domains/v0.5.0) | April 15, 2026 | Closed beta — `indevs.in` registration, default Stackryze nameservers, My Domains dashboard. | ### 2026 | Version | Date | Highlights | | ----------------------------------- | ------------- | ---------------------------------------------------------------------------------------------------- | | [v0.3.0](/docs/changelog/hosting/v0.3.0) | July 1, 2026 | Closed beta — free tier, preview environments per PR, env vars with secret scanning, public roadmap. | | [v0.2.0](/docs/changelog/hosting/v0.2.0) | June 15, 2026 | Private beta — custom domains via Stackryze DNS, automatic HTTPS via ACME DNS-01, Git-based deploys. | | [v0.1.0](/docs/changelog/hosting/v0.1.0) | May 30, 2026 | Internal alpha — container deploy on `stackryze.run` subdomains, automatic health-check rollback. | ### 2026 | Version | Date | Highlights | | --------------------------------------- | -------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | | [v1.115.0](/docs/changelog/stackns/v1.115.0) | July 4, 2026 | Atomic bulk record operations, scoped read-only tokens, dynamic DNS rate limits via `X-Forwarded-For`, audit log CSV export. | | [v1.110.0](/docs/changelog/stackns/v1.110.0) | June 29, 2026 | Native `HTTPS` and `SVCB` records, ED25519 DNSSEC default, Cloudflare zone import, 30-second TTL minimum. | | [v1.105.0](/docs/changelog/stackns/v1.105.0) | June 22, 2026 | Bring Your Own Processor (BYOP), official Rust SDK release, Korean wallets and Przelewy24 payment methods, `brand_id` on every webhook payload, decimal-aware currency handling, higher entitlement limits, branded recovery emails, analytics v2.1, and dashboard polish. | | [v1.101.0](/docs/changelog/stackns/v1.101.0) | June 2, 2026 | Automatic subscription payment retries, business-level proration defaults with per-product-collection overrides, business name collection for B2B invoices. | | [v1.99.0](/docs/changelog/stackns/v1.99.0) | May 25, 2026 | Stacked discount codes (up to 20), seven new customer notification emails, Sunbit BNPL, checkout payment page overhaul, product form rework with live preview, Business Settings redesign. | | [v1.97.6](/docs/changelog/stackns/v1.97.6) | May 7, 2026 | Entitlements launch with five new fulfillment integrations, subscription cancellation reasons, configurable INR e-mandate floor, adaptive currency fees inclusive setting, Stackryze Desktop app for macOS/Windows/Linux, stablecoin payments, import existing license keys, `require_phone_number` for checkout. | | [v1.94.0](/docs/changelog/stackns/v1.94.0) | April 8, 2026 | Abandoned Cart Recovery, Subscription Dunning, discount metadata, recovery webhooks, Pix payments for Brazil, WeChat Pay for Chinese customers. | | [v1.93.0](/docs/changelog/stackns/v1.93.0) | March 28, 2026 | Checkout redesign with improved loading states, net revenue analytics, business-level payment method disabling, payout breakdown, Visa RDR configuration, DoNotBill proration mode, scheduled plan changes, delete customer payment method API. | | [v1.87.0](/docs/changelog/stackns/v1.87.0) | March 9, 2026 | Webhook signature verification v2 (HMAC-SHA256 with replay protection), zone import from BIND format, per-record comments, audit log export to JSONL, dashboard dark mode polish, and 14 minor bug fixes. | ## Subscribe Each release is announced on: * The [Stackryze Discord](https://discord.gg/stackryze) `#announcements` channel. * The [Stackryze blog](https://stackryze.com/blog). * RSS — coming soon. # v1.100.6 Source: https://docs.stackryze.com/docs/changelog/stackns/v1.100.6 **Release date:** Dec 2, 2024 ship 14 minor DNS engine bug fixes. # v1.101.0 Source: https://docs.stackryze.com/docs/changelog/stackns/v1.101.0 **Release date:** June 2, 2026 Automatic subscription payment retries to recover failed renewal revenue, business-level proration defaults with per-product-collection overrides, and business name collection for B2B invoices. # v1.101.3 Source: https://docs.stackryze.com/docs/changelog/stackns/v1.101.3 **Release date:** Dec 28, 2024 ship KSK rollover automation (90-day cadence). # v1.102.8 Source: https://docs.stackryze.com/docs/changelog/stackns/v1.102.8 **Release date:** Jan 23, 2025 ship Sunbit BNPL as a checkout option. # v1.103.3 Source: https://docs.stackryze.com/docs/changelog/stackns/v1.103.3 **Release date:** Feb 18, 2025 ship CAA record support with configurable issuer sets. # v1.104.4 Source: https://docs.stackryze.com/docs/changelog/stackns/v1.104.4 **Release date:** Mar 16, 2025 ship Visa RDR configuration for issuing banks. # v1.105.0 Source: https://docs.stackryze.com/docs/changelog/stackns/v1.105.0 **Release date:** June 22, 2026 Bring Your Own Processor (BYOP), official Rust SDK release, Korean wallets and Przelewy24 payment methods, `brand_id` on every webhook payload, decimal-aware currency handling, higher entitlement limits, branded recovery emails, analytics v2.1, and dashboard polish. # v1.105.6 Source: https://docs.stackryze.com/docs/changelog/stackns/v1.105.6 **Release date:** Apr 11, 2025 ship discount metadata on every order payload. # v1.106.5 Source: https://docs.stackryze.com/docs/changelog/stackns/v1.106.5 **Release date:** May 7, 2025 ship native HTTPS and SVCB record types. # v1.107.7 Source: https://docs.stackryze.com/docs/changelog/stackns/v1.107.7 **Release date:** Jun 2, 2025 ship Pix payments for the Brazilian market. # v1.108.8 Source: https://docs.stackryze.com/docs/changelog/stackns/v1.108.8 **Release date:** Jun 28, 2025 ship the first anycast site in NYC. # v1.109.7 Source: https://docs.stackryze.com/docs/changelog/stackns/v1.109.7 **Release date:** Jul 24, 2025 ship the dark-mode dashboard polish across all record types. # v1.110.0 Source: https://docs.stackryze.com/docs/changelog/stackns/v1.110.0 **Release date:** June 29, 2026 Native support for the `HTTPS` and `SVCB` record types, ED25519 DNSSEC by default with ECDSA-P256 fallback, zone import from Cloudflare's `Export DNS` button, and per-record TTL minimum of 30 seconds. # v1.110.1 Source: https://docs.stackryze.com/docs/changelog/stackns/v1.110.1 **Release date:** Aug 19, 2025 ship automatic subscription payment retries with exponential backoff. # v1.111.3 Source: https://docs.stackryze.com/docs/changelog/stackns/v1.111.3 **Release date:** Sep 14, 2025 ship decimal-aware currency handling in the billing layer. # v1.112.3 Source: https://docs.stackryze.com/docs/changelog/stackns/v1.112.3 **Release date:** Oct 10, 2025 ship the checkout payment page overhaul. # v1.113.1 Source: https://docs.stackryze.com/docs/changelog/stackns/v1.113.1 **Release date:** Nov 5, 2025 ship business name collection for B2B invoices. # v1.114.5 Source: https://docs.stackryze.com/docs/changelog/stackns/v1.114.5 **Release date:** Dec 1, 2025 ship the 30-second TTL minimum (down from 60). # v1.115.0 Source: https://docs.stackryze.com/docs/changelog/stackns/v1.115.0 **Release date:** July 4, 2026 Bulk record operations via `PATCH /api/v1/zones/{zone}/records` now atomic across the entire change set, scoped tokens for read-only access, dynamic DNS endpoint with `X-Forwarded-For` aware rate limits, and audit log export to CSV in addition to JSONL. # v1.116.9 Source: https://docs.stackryze.com/docs/changelog/stackns/v1.116.9 **Release date:** Jan 22, 2026 ship Korean wallets and Przelewy24 payment methods in the dashboard. # v1.117.8 Source: https://docs.stackryze.com/docs/changelog/stackns/v1.117.8 **Release date:** Feb 17, 2026 ship seven new customer notification emails. # v1.118.3 Source: https://docs.stackryze.com/docs/changelog/stackns/v1.118.3 **Release date:** Mar 15, 2026 ship record creation via API and dashboard. # v1.80.1 Source: https://docs.stackryze.com/docs/changelog/stackns/v1.80.1 **Release date:** Jul 1, 2023 ship scheduled plan changes (effective at next renewal). # v1.81.5 Source: https://docs.stackryze.com/docs/changelog/stackns/v1.81.5 **Release date:** Jul 27, 2023 ship stablecoin payments at checkout. # v1.82.4 Source: https://docs.stackryze.com/docs/changelog/stackns/v1.82.4 **Release date:** Aug 22, 2023 ship DoNotBill proration mode for cancel-and-replace workflows. # v1.83.3 Source: https://docs.stackryze.com/docs/changelog/stackns/v1.83.3 **Release date:** Sep 17, 2023 ship per-record comments surfaced in the dashboard. # v1.84.0 Source: https://docs.stackryze.com/docs/changelog/stackns/v1.84.0 **Release date:** Oct 13, 2023 ship Stackryze Desktop for macOS, Windows, and Linux (DNS client + dashboard). # v1.85.3 Source: https://docs.stackryze.com/docs/changelog/stackns/v1.85.3 **Release date:** Nov 8, 2023 ship zone creation via the dashboard and CLI. # v1.86.9 Source: https://docs.stackryze.com/docs/changelog/stackns/v1.86.9 **Release date:** Dec 4, 2023 ship OpenPGPKEY support in the supported record types. # v1.87.0 Source: https://docs.stackryze.com/docs/changelog/stackns/v1.87.0 **Release date:** March 9, 2026 Webhook signature verification v2 (HMAC-SHA256 with replay protection), zone import from BIND format, per-record comments, audit log export to JSONL, dashboard dark mode polish, and 14 minor bug fixes. # v1.87.1 Source: https://docs.stackryze.com/docs/changelog/stackns/v1.87.1 **Release date:** Dec 30, 2023 ship delete-customer-payment-method API. # v1.88.1 Source: https://docs.stackryze.com/docs/changelog/stackns/v1.88.1 **Release date:** Jan 25, 2024 ship atomic bulk record operations via PATCH /api/v1/zones//records. # v1.89.7 Source: https://docs.stackryze.com/docs/changelog/stackns/v1.89.7 **Release date:** Feb 20, 2024 ship import-existing-license-keys for license-driven products. # v1.90.1 Source: https://docs.stackryze.com/docs/changelog/stackns/v1.90.1 **Release date:** Mar 17, 2024 ship Bring Your Own Processor (BYOP) for high-volume accounts. # v1.91.8 Source: https://docs.stackryze.com/docs/changelog/stackns/v1.91.8 **Release date:** Apr 12, 2024 ship the dynamic DNS endpoint with X-Forwarded-For-aware rate limits. # v1.92.2 Source: https://docs.stackryze.com/docs/changelog/stackns/v1.92.2 **Release date:** May 8, 2024 ship the Business Settings redesign. # v1.93.0 Source: https://docs.stackryze.com/docs/changelog/stackns/v1.93.0 **Release date:** March 28, 2026 Checkout redesign with improved loading states, net revenue analytics, business-level payment method disabling, payout breakdown, Visa RDR configuration, DoNotBill proration mode, scheduled plan changes, and delete customer payment method API. # v1.93.2 Source: https://docs.stackryze.com/docs/changelog/stackns/v1.93.2 **Release date:** Jun 3, 2024 ship the checkout redesign with improved loading states. # v1.94.0 Source: https://docs.stackryze.com/docs/changelog/stackns/v1.94.0 **Release date:** April 8, 2026 Abandoned Cart Recovery, Subscription Dunning, discount metadata, recovery webhooks, Pix payments for Brazil, and WeChat Pay for Chinese customers. # v1.94.7 Source: https://docs.stackryze.com/docs/changelog/stackns/v1.94.7 **Release date:** Jun 29, 2024 ship Abandoned Cart Recovery flows with email and webhook hooks. # v1.95.8 Source: https://docs.stackryze.com/docs/changelog/stackns/v1.95.8 **Release date:** Jul 25, 2024 ship recovery webhooks for the Abandoned Cart sequence. # v1.96.2 Source: https://docs.stackryze.com/docs/changelog/stackns/v1.96.2 **Release date:** Aug 20, 2024 ship payout breakdown with line items per invoice. # v1.97.4 Source: https://docs.stackryze.com/docs/changelog/stackns/v1.97.4 **Release date:** Sep 15, 2024 ship audit log export to CSV. # v1.97.6 Source: https://docs.stackryze.com/docs/changelog/stackns/v1.97.6 **Release date:** May 7, 2026 Entitlements launch with five new fulfillment integrations (Discord, GitHub, Telegram, Framer, Notion), subscription cancellation reasons in the customer portal, configurable INR e-mandate floor, adaptive currency fees inclusive setting, Stackryze Desktop app for macOS/Windows/Linux, stablecoin payments (USDC/USDP/USDG), import existing license keys, and `require_phone_number` for checkout sessions. # v1.98.8 Source: https://docs.stackryze.com/docs/changelog/stackns/v1.98.8 **Release date:** Oct 11, 2024 ship cancellation reasons for subscription churn analysis. # v1.99.0 Source: https://docs.stackryze.com/docs/changelog/stackns/v1.99.0 **Release date:** May 25, 2026 Stacked discount codes (up to 20 per checkout, payment, or subscription), seven new customer notification emails for refunds and subscription lifecycle events, Sunbit BNPL for US customers, checkout payment page overhaul lifting success rates by 2–3%, product form rework with live preview and autosave, and Business Settings redesign. # v1.99.9 Source: https://docs.stackryze.com/docs/changelog/stackns/v1.99.9 **Release date:** Nov 6, 2024 ship DNSSEC with ECDSA P-256 signing. # API Source: https://docs.stackryze.com/docs/dns/api The REST API that powers the Stackryze DNS dashboard, available for your own automation. Every action in the Stackryze DNS dashboard is also a REST endpoint. The API is JSON over HTTPS, authenticated with bearer tokens, and built for automation. ## What it covers The API exposes: * **Zones** — create, list, get, delete. * **Records** — create, update, delete in bulk (atomic per zone). * **DNSSEC** — enable, disable, retrieve keys, force rollover. * **Nameservers** — read-only (the four are fixed). * **Dynamic DNS** — push an IP update from a client. * **Webhooks** — register endpoints for zone and record events. * **Tokens** — create, list, rotate, revoke. ## Base URL ``` https://dns.stackryze.com/api/v1 ``` All endpoints are versioned with `/v1`. The API is stable; breaking changes get a new version. ## Authentication Every request needs a bearer token: ```bash theme={null} curl https://dns.stackryze.com/api/v1/zones \ -H "Authorization: Bearer $TOKEN" ``` ### Token types | Type | Scope | Use | | --------------------- | --------------------------------------- | ---------------------------------------- | | Personal access token | All actions on your account | CLI scripts, manual automation | | Scoped zone token | Limited to one zone, one or more scopes | CI/CD, dynamic DNS clients | | Webhook signing key | Read-only, scoped to event types | Receivers that verify webhook signatures | Generate tokens in **Settings → API tokens**. Each token is shown once and stored hashed on the server. ### Scopes Tokens carry fine-grained scopes. Common ones: | Scope | Allows | | ---------------- | ---------------------------------------- | | `zones:read` | List and get zones | | `zones:write` | Create and delete zones | | `records:read` | List records in a zone | | `records:write` | Create, update, delete records | | `dnssec:write` | Enable, disable, rollover DNSSEC | | `dynamic:update` | Push Dynamic DNS updates | | `webhooks:read` | List webhook endpoints | | `webhooks:write` | Create, update, delete webhook endpoints | A typical dynamic-DNS client token needs only `dynamic:update`. A typical CI/CD token for record management needs `records:read` and `records:write`. ## Endpoints ### Zones ``` GET /api/v1/zones # list zones POST /api/v1/zones # create zone GET /api/v1/zones/{zone} # get zone details DELETE /api/v1/zones/{zone} # delete zone ``` Create a zone: ```bash theme={null} curl -X POST https://dns.stackryze.com/api/v1/zones \ -H "Authorization: Bearer $TOKEN" \ -H "Content-Type: application/json" \ -d '{"name": "example.com"}' ``` ### Records ``` GET /api/v1/zones/{zone}/records # list all records PATCH /api/v1/zones/{zone}/records # bulk update (atomic) ``` The `PATCH` is interesting: it's a single atomic operation that takes a list of record changes and applies them all or none. This is what makes the API safe to use for record migrations — you don't end up in a half-updated state. ```bash theme={null} curl -X PATCH https://dns.stackryze.com/api/v1/zones/example.com/records \ -H "Authorization: Bearer $TOKEN" \ -H "Content-Type: application/json" \ -d '{ "changes": [ { "type": "A", "name": "@", "value": "192.0.2.1", "ttl": 3600 }, { "type": "A", "name": "www", "value": "192.0.2.1", "ttl": 3600 }, { "type": "MX", "name": "@", "value": "10 mail.example.com.", "ttl": 3600 }, { "type": "TXT", "name": "@", "value": "\"v=spf1 -all\"", "ttl": 3600 }, { "type": "A", "name": "staging", "value": "203.0.113.5", "ttl": 60 } ] }' ``` ### DNSSEC ``` GET /api/v1/zones/{zone}/dnssec # get DNSSEC state POST /api/v1/zones/{zone}/dnssec/enable # enable DNSSEC POST /api/v1/zones/{zone}/dnssec/disable # disable DNSSEC POST /api/v1/zones/{zone}/dnssec/rollover # force key rollover ``` ### Dynamic DNS ``` POST /api/v1/dynamic/{zone}/{record} # push IP update ``` See [Dynamic DNS](/docs/dns/dynamic-dns) for the full request/response. ### Webhooks ``` GET /api/v1/webhooks # list webhooks POST /api/v1/webhooks # create webhook DELETE /api/v1/webhooks/{id} # delete webhook ``` ## Rate limits | Action | Limit | | ------------------- | ------------------ | | Reads | 600 / minute | | Writes | 120 / minute | | Zone creates | 10 / hour | | Dynamic DNS updates | 60 / record / hour | Exceeded limits return `429 Too Many Requests` with `Retry-After` and `X-RateLimit-Reset` headers. ## Errors Every error response is JSON with a stable shape: ```json theme={null} { "error": { "code": "zone_not_found", "message": "No zone matches example.com", "request_id": "req_abc123" } } ``` Common error codes: | Code | Meaning | | ------------------ | ------------------------------------- | | `unauthorized` | Missing or invalid token | | `forbidden` | Token doesn't have the required scope | | `not_found` | Resource doesn't exist | | `validation_error` | Request body failed validation | | `rate_limited` | Hit a rate limit | | `conflict` | Concurrent modification — retry | The `request_id` is useful when contacting support — it lets us trace the request server-side. ## Client libraries Official clients are published for: * **JavaScript / TypeScript** — `npm install @stackryze/dns` * **Python** — `pip install stackryze-dns` * **Go** — `go get github.com/stackryze/dns-go` * **CLI** — `brew install stackryze-cli` Community clients exist for most other languages; search [github.com/stackryze](https://github.com/stackryze) for the list. ## Where to go next The DDNS endpoint, with examples. Sign zones programmatically. # DNSSEC Source: https://docs.stackryze.com/docs/dns/dnssec Cryptographic validation for your zone — what it is, why it matters, and how to turn it on. DNSSEC is the cryptographic layer of DNS. It lets a resolver prove that an answer it received was signed by the zone's owner and was not tampered with in transit. This page explains the model, what DNSSEC gets you (and what it doesn't), and how to enable it on a Stackryze DNS zone. ## What DNSSEC is DNSSEC adds a chain of digital signatures to DNS. The signatures are verified by resolvers, parent zones, and ultimately the root zone. If the chain is intact, the answer is authentic. The chain runs from the root (`.`) downward: ```text theme={null} . (root) └── com (signed) └── example.com (signed) └── app.example.com (signed) ``` Each level signs the level below it. A resolver walks the chain from the root and verifies every signature before trusting the answer. ## What DNSSEC gets you * **Authentication.** The answer came from the zone's owner, not a man-in-the-middle. * **Integrity.** The answer wasn't tampered with on the way. * **Proof of non-existence.** A signed statement that a name doesn't exist (NSEC/NSEC3), instead of just an empty response. ## What DNSSEC doesn't get you * **Confidentiality.** DNSSEC-signed answers are not encrypted. DNS-over-HTTPS or DNS-over-TLS handles that. * **End-to-end trust.** If the resolver you're using doesn't validate DNSSEC, the chain is moot. * **Protection against compromised authoritative.** If an attacker controls your zone or your registrar account, they can sign anything they want. DNSSEC is a meaningful layer against network-level tampering, but it's not a silver bullet. ## How signing works When you enable DNSSEC on a Stackryze DNS zone: 1. The engine generates a **Key Signing Key (KSK)** and a **Zone Signing Key (ZSK)**. 2. The zone is signed — every record gets an `RRSIG` covering it. 3. The KSK is published as a `DNSKEY` record at the apex. 4. A **Delegation Signer (DS)** record is computed from the KSK and submitted to the parent zone (`com`, in our example). 5. The parent publishes the `DS` record, completing the chain. The signing and key generation are automated. You don't need to manage the keys yourself. Stackryze performs a key rollover every 90 days for ZSK and every 365 days for KSK, so even a key compromise has a built-in expiry. ## Enabling DNSSEC In the [Stackryze DNS dashboard](https://dns.stackryze.com): 1. Open the zone you want to sign. 2. Go to **Settings → DNSSEC**. 3. Click **Enable DNSSEC**. 4. Copy the `DS` record shown on the confirmation screen. 5. Submit that `DS` record at your registrar for the parent zone. The last step is critical. Without the `DS` record at the parent, no resolver can validate your zone — your signatures exist but no one trusts them. For Stackryze Domains, the `DS` record is added to the registry automatically — you don't need to do anything beyond step 3. ## Verifying DNSSEC To check that the chain is intact: ```bash theme={null} dig +dnssec example.com @1.1.1.1 ``` A correctly signed zone returns the records plus their `RRSIG` signatures. To check that the parent has the right `DS`: ```bash theme={null} dig DS example.com @1.1.1.1 ``` To check end-to-end validation from the root: ```bash theme={null} delv @1.1.1.1 example.com +rtrace +multiline ``` If `delv` returns the answer with no errors and the `; fully validated` flag at the end, the chain is intact. ## Common issues ### DS record not published at parent Symptom: `dig DS example.com` returns nothing. Fix: Submit the `DS` record at your registrar. For Stackryze Domains, contact [support@stackryze.com](mailto:support@stackryze.com) if it isn't published within an hour of enabling DNSSEC. ### Key rollover in progress Symptom: brief validation failures during a 90-day or 365-day rollover window. Fix: Nothing. Stackryze coordinates the rollover so old and new keys overlap. ### Algorithmic mismatch Symptom: resolvers that only support older algorithms reject the chain. Fix: Stackryze defaults to `ED25519` (algorithm 15) where supported, falling back to `ECDSA-P256` (algorithm 13). If you have a very old resolver that rejects both, you can force a specific algorithm in **Settings → DNSSEC → Algorithm**, but the default works for >99% of validators in the wild. ### Clock skew Symptom: signatures look expired even though they shouldn't be. Fix: Most validators have a small clock skew tolerance. If you run your own validator, make sure its clock is synchronized. ## What NSEC3 means NSEC3 is the signed-non-existence scheme that replaced NSEC. Instead of listing the next name in the zone (which leaks the full zone to anyone who can ask), NSEC3 hashes names and lists them in hash order. A query for a non-existent name returns a signed "no name exists between these two hashes" statement. Stackryze DNS uses NSEC3 with opt-out disabled — every empty gap in your zone is signed. ## When to skip DNSSEC DNSSEC is opt-in for good reason. Skip it if: * You're a hobby project with no threat model that includes network-level tampering. * You're using DNS as a low-stakes service-discovery mechanism. * You can't get the `DS` record published at the parent (rare, but possible if your registrar doesn't support it). Enable it if: * You're running anything that accepts credentials — logins, payments, admin panels. * You're a journalist, activist, or anyone with a heightened threat model. * Your domain name is part of your brand and worth protecting from cache poisoning. ## Where to go next The records that make DNSSEC possible. Where signed zones are served. Step-by-step walkthrough. Automate DNSSEC management. # Dynamic DNS Source: https://docs.stackryze.com/docs/dns/dynamic-dns Push updates to a record from anywhere — the use cases, the protocol, and how Stackryze supports it. Dynamic DNS is the practice of updating a DNS record from a device or service whose IP address isn't known in advance. It's the classic solution for home servers, gaming hosts, and any service running on a connection with a changing public IP. ## What Dynamic DNS solves A typical home or small-business internet connection has a public IP address that changes — sometimes daily, sometimes every few hours. If you want to host a service (a game server, a personal site, a VPN endpoint) on a machine behind that connection, you need a way to keep the DNS record in sync with the IP. The pattern: ```text theme={null} [your machine] → [updates IP] → [DNS provider] → [public sees the new IP] ``` Stackryze DNS supports this through an authenticated update endpoint — you POST the new IP, we update the record. ## When Dynamic DNS makes sense * **Home servers** — a Plex library, a Minecraft server, a personal VPN. * **Field-deployed devices** — sensors, kiosks, anything that gets a DHCP IP on a cellular or satellite link. * **Temporary infrastructure** — short-lived servers behind a NAT that need a stable name. ## When it doesn't * **Production web services.** Use a fixed IP or a CDN; don't depend on a home connection. * **Mail servers.** Mail servers need stable reverse DNS, fixed IPs, and SPF consistency — Dynamic DNS is the wrong tool. * **Anything requiring TLS.** Public CAs won't issue certs for hostnames that resolve to a residential IP. ## The protocol Stackryze supports Stackryze exposes a Dynamic DNS endpoint that accepts standard HTTP updates: ``` POST https://dns.stackryze.com/api/v1/dynamic/{zone}/{record} ``` The request: ```bash theme={null} curl -X POST https://dns.stackryze.com/api/v1/dynamic/example.com/home \ -H "Authorization: Bearer $STACKRYZE_TOKEN" \ -H "Content-Type: application/json" \ -d '{"value": "192.0.2.42"}' ``` The response: ```json theme={null} { "zone": "example.com", "record": "home", "type": "A", "value": "192.0.2.42", "ttl": 60, "updated_at": "2026-07-05T12:34:56Z" } ``` The endpoint supports `A` and `AAAA` records. Other record types go through the regular API. ## Authentication Dynamic DNS uses a **scoped token** — a regular API token with the `dynamic:update` scope. Tokens are scoped per zone, so a token that can update `home.example.com` can't touch `db.example.com`. Generate a token in **Settings → API tokens → Create** with the `dynamic:update` scope. The token is shown once and stored hashed — you can't retrieve it later, only regenerate. ## Auto-detection If you don't know your current public IP, the endpoint can detect it from the request: ```bash theme={null} curl -X POST https://dns.stackryze.com/api/v1/dynamic/example.com/home \ -H "Authorization: Bearer $STACKRYZE_TOKEN" \ -H "Content-Type: application/json" \ -d '{}' ``` When you omit the `value`, the server uses the source IP of the request. This is the form most routers and DDNS clients use. ## Rate limits Dynamic updates are rate-limited to prevent runaway loops: | Limit | Value | | ---------------------------- | ----- | | Updates per record per hour | 60 | | Updates per token per minute | 30 | A typical home connection that changes IP every few hours is well within these limits. If you hit them, the endpoint returns `429 Too Many Requests` with a `Retry-After` header. ## TTL guidance Dynamic DNS records should have a **short TTL** — typically 60 seconds. The reason is that even after your dynamic endpoint updates the record, public resolvers cache the old answer for the TTL duration. A 60-second TTL means a maximum 60-second stale window after each update. For the record itself: | Field | Recommended | | ----- | --------------------------------------------- | | Name | `home.example.com.` | | Type | `A` (or `AAAA` for IPv6) | | TTL | 60 | | Value | Your current public IP, updated by the client | ## Client setup Most home routers and Linux clients speak the DynDNS2 protocol. The Stackryze endpoint is HTTP-JSON, not DynDNS2, so you need a small wrapper: ```bash theme={null} #!/bin/bash # update-home.sh TOKEN="your-token-here" ZONE="example.com" RECORD="home" curl -fsS -X POST "https://dns.stackryze.com/api/v1/dynamic/${ZONE}/${RECORD}" \ -H "Authorization: Bearer ${TOKEN}" \ -H "Content-Type: application/json" \ -d '{}' ``` Run it from cron every 5 minutes: ```cron theme={null} */5 * * * * /home/you/update-home.sh ``` The `-fsS` flags fail silently — if the network is down, the script exits non-zero but doesn't spam your inbox. ## Common issues ### Token rejected The token may have been rotated, or it might be missing the `dynamic:update` scope. Generate a new one in the dashboard. ### Update succeeds but old IP is still cached You're seeing cached answers at the resolver level. Wait for the TTL (60 seconds) to elapse, or use `dig @1.1.1.1 home.example.com +short` to query a fresh resolver. ### IPv6 not working If your connection has IPv6 but `dig AAAA home.example.com` returns nothing, the AAAA record doesn't exist. Create one explicitly or include both `A` and `AAAA` in the dynamic update. ### Rate limited Slow down. Real home connections don't change IPs faster than every few hours. ## Where to go next Full REST API, including Dynamic DNS endpoints. The record model behind Dynamic DNS. Set up a zone in five minutes. Step-by-step walkthrough. # Introduction Source: https://docs.stackryze.com/docs/dns/index Modern DNS hosting for everyone — fast, free, and security-first. Stackryze DNS is the authoritative DNS hosting service behind every Stackryze Domain and available as a standalone product for any domain you own. It is free, security-first, and built on the same open-source engine the rest of the Stackryze surface runs on. The full service lives at [dns.stackryze.com](https://dns.stackryze.com). Status & live metrics are at [status.stackryze.com](https://status.stackryze.com). ## What it is A managed authoritative DNS service. You give Stackryze a zone, it serves it from a global anycast network. You add records through the dashboard, the API, or by bringing your own zone file. | Aspect | Value | | --------------------- | --------------------------------------------- | | Cost | Free | | Authentication | Stackryze account | | Authoritative servers | 4 globally distributed | | Modern record support | `SVCB`, `HTTPS`, `TLSA`, plus classics | | DNSSEC | Yes, opt-in | | API | REST, JSON | | Quota | 3 zones free; verified accounts get unlimited | ## Who it's for Stackryze DNS is built for the same audience as the rest of Stackryze: * **Founders** launching a product and want clean, debuggable DNS without paying for it. * **Freelancers** managing DNS for client domains and tired of upsell-heavy dashboards. * **Small teams** that need a unified DNS surface for staging, production, and per-customer zones. * **The curious** who want to learn DNS hands-on with a modern API. ## The four pillars Every Stackryze product is built around the same guarantees. For DNS specifically: 1. **Modern records.** Native support for `SVCB`, `HTTPS`, `TLSA`, plus every classic record type. The modern web's primitives, not just the 1990s subset. 2. **Simple interface.** The dashboard is small, fast, and free of modal soup and upsells. 3. **API-first.** The same JSON/REST API powers the dashboard. Anything you can click, you can script. 4. **Open source.** The authoritative engine is MIT-licensed at [github.com/stackryze/DNS](https://github.com/stackryze/DNS). ## What you get Out of the box on every zone: * **Global anycast** — four nameservers in NYC, Hyderabad, Nuremberg, and São Paulo. * **DNSSEC** with automated signing and rollover. * **Wildcard records** at any depth. * **Free TLS** via automatic ACME integration if you want to terminate HTTPS at the edge. * **API tokens** with scoped permissions. * **Webhooks** for zone and record change events. * **Audit log** of every change. ## What it isn't Stackryze DNS is not: * **A recursive resolver.** It's authoritative only — it answers queries for zones you host, it doesn't fetch answers from upstream resolvers on your behalf. * **A registrar.** It hosts DNS for domains you bring (from any registrar) or for Stackryze Domains. It doesn't sell top-level domains. * **A CDN.** There's no caching layer or edge logic. If you want caching and DDoS protection in front of your origin, pair Stackryze DNS with a CDN (Cloudflare, Fastly, etc.). ## How it fits the Stackryze surface | Product | Role | | ----------------- | --------------------------------------------------------- | | Stackryze DNS | The resolution. Hosted authoritative DNS for any zone. | | Stackryze Domains | The name. Free subdomains under `indevs.in`. | | Stackryze API | The automation layer. Same APIs that power the dashboard. | ## Concepts Dive into the concept that matches what you're working on. The mental model behind DNS data. Every record type, including modern ones. Where your zones are served from. Cryptographic validation for your zone. Push IP updates from anywhere. Automate every zone and record. ## Task-oriented guides Once you understand the concepts, the guides walk you through the actual steps. From zero to a working zone in five minutes. Wire up a domain you already own. Add records step by step. Turn on cryptographic validation. Set up a DDNS client. # Nameservers Source: https://docs.stackryze.com/docs/dns/nameservers The four authoritative nameservers that serve every Stackryze DNS zone. Stackryze DNS zones are served by four globally distributed authoritative nameservers. This page explains where they live, how they're configured, and how to verify they're answering for your zone. ## The four nameservers | Hostname | Location | Network | | ------------------- | ------------------ | ------- | | `ns1.stackryze.com` | New York City, USA | Anycast | | `ns2.stackryze.com` | Hyderabad, India | Anycast | | `ns3.stackryze.com` | Nuremberg, Germany | Anycast | | `ns4.stackryze.com` | São Paulo, Brazil | Anycast | The four sites are not failover pairs — they all answer authoritatively at all times. Anycast announces the same IP prefix from each location, so a resolver in Singapore reaches Nuremberg in milliseconds while a resolver in São Paulo reaches São Paulo directly. ## Why four Four sites give you: * **Geographic spread.** Every continent has a local ingress point. * **Redundancy across any two failures.** Lose any two sites, the other two keep the zone live. * **Capacity headroom.** A single zone going viral doesn't degrade service for other zones. The engine runs the same open-source authoritative server (PowerDNS) at every site, backed by a replicated database. Updates from the API or dashboard are written once and propagated to every site within seconds. ## How queries reach the right site When a recursive resolver (your ISP's, or 8.8.8.8, or 1.1.1.1) needs to answer a query for `app.example.com`, it follows the delegation chain: 1. Look up `example.com` `NS` records at the `.com` nameservers. 2. Find `example.com`'s nameservers — for example, `ns1.stackryze.com`. 3. Resolve `ns1.stackryze.com` itself, which returns any of the four anycast IPs. 4. The IP selected depends on BGP routing — closest path wins. 5. Send the original `app.example.com` query to that IP. 6. Receive the answer from whichever physical site is closest on the network. Steps 3–6 take milliseconds. The first two are the "real" DNS lookup latency, and they depend on the upstream resolvers, not on Stackryze. ## Verifying delegation To confirm a zone is delegated to Stackryze: ```bash theme={null} dig NS example.com @1.1.1.1 +short ``` You should see the four `ns*.stackryze.com` hostnames. If you see anything else, the zone is still delegated elsewhere. To confirm a specific nameserver is answering: ```bash theme={null} dig A app.example.com @ns1.stackryze.com +short ``` If you get back an IP, the nameserver is live and authoritative for the zone. ## Latency expectations Approximate resolver-to-nameserver RTTs by region (95th percentile): | Region | Expected RTT | | ------------------------ | --------------------------------- | | North America east coast | \< 20 ms (NYC) | | North America west coast | \< 80 ms (NYC via backbone) | | Europe | \< 30 ms (Nuremberg) | | Middle East / South Asia | \< 30 ms (Hyderabad) | | East Asia / Oceania | \< 80 ms (Nuremberg via backbone) | | South America | \< 30 ms (São Paulo) | If you see RTTs above these numbers for a long time, something is wrong with your upstream resolver or with the path to the nearest site. ## Health and status Live health metrics for every nameserver are at [status.stackryze.com](https://status.stackryze.com). The status page shows query rates, response times, and any incidents in flight. ## When to bring your own nameservers If you need nameservers in a region Stackryze doesn't yet cover, or you need a custom setup (split-horizon DNS, geo-routing, etc.), you can BYOD — see [Nameserver delegation](/docs/domains/nameserver-delegation) for the model and [DNS providers](/docs/guides/domains/dns-providers) for setup guides. ## Where to go next What Stackryze DNS is. Cryptographic validation. The zone/record mental model. Automate zone changes. # Supported records Source: https://docs.stackryze.com/docs/dns/supported-records Every record type Stackryze DNS serves, including the modern ones most providers skip. Stackryze DNS serves every classic DNS record type and a strong set of modern ones — the records the modern web actually uses, not just the 1990s subset. ## Classic records | Type | Purpose | Example | | ------- | --------------------------------------------------- | ------------------------------------- | | `A` | Map a name to an IPv4 address | `192.0.2.1` | | `AAAA` | Map a name to an IPv6 address | `2001:db8::1` | | `CNAME` | Alias one name to another | `app.example.com. → example.com.` | | `DNAME` | Redirect a whole subtree | `old.example.com. → new.example.com.` | | `MX` | Mail exchange | `10 mail.example.com.` | | `NS` | Delegation (managed by Stackryze for its own zones) | `ns1.stackryze.com.` | | `TXT` | Free-form text — SPF, DKIM, DMARC, verification | `"v=spf1 -all"` | | `SRV` | Service locator (XMPP, SIP, Matrix, Minecraft) | `_minecraft._tcp.example.com.` | | `CAA` | Restrict which CAs can issue certs | `0 issue "letsencrypt.org"` | | `PTR` | Reverse DNS | handled via the API only | | `SOA` | Start of authority (managed by Stackryze) | — | ## Modern records These are the records the modern web is built on and most providers still don't support. Stackryze DNS serves them natively. ### `SVCB` and `HTTPS` Service bindings — a single record that says "to reach this service, here's the host, the port, the ALPN, and the IP hints." ```dns theme={null} _app.example.com. 300 IN SVCB 1 app.example.com. alpn="h3,h2" port=443 ipv4hint=192.0.2.1 ipv6hint=2001:db8::1 www.example.com. 300 IN HTTPS 1 . alpn="h3,h2" port=443 ipv4hint=192.0.2.1 ``` `HTTPS` is a mandatory-`alpn` alias of `SVCB` for the common case of serving HTTPS. Common SvcParams: | Param | Purpose | | ---------- | ------------------------------------ | | `alpn` | Protocols to negotiate (`h2`, `h3`) | | `port` | Port to reach the service on | | `ipv4hint` | IPv4 hints to skip resolver lookups | | `ipv6hint` | IPv6 hints | | `dohpath` | DNS-over-HTTPS path for the resolver | | `ech` | Encrypted Client Hello config | ### `TLSA` DANE — associate a TLS certificate or public key with a name. Used to lock down SMTP, HTTPS, and other TLS endpoints against rogue CAs. ```dns theme={null} _443._tcp.example.com. 3600 IN TLSA 3 1 1 ( 5c1502d3377fe1e0a4f8e2cd9c8b3e5d4e8e3b6d8c4a6b1c5d3a7c8b9d0e1f2a 3b4c5d6e7f80 ) ``` Three fields: | Field | Value | Meaning | | ----------------- | ---------- | ---------------------------------------------------------- | | Certificate usage | `0`–`3` | `3` (DANE-EE) is the most common — pin the end-entity cert | | Selector | `0` or `1` | Match full cert (`0`) or public key (`1`) | | Matching type | `0`–`2` | Exact match (`1`), SHA-256 (`1`), SHA-512 (`2`) | ### `OPENPGPKEY` and `SMIMEA` Associate an OpenPGP or S/MIME key with an email address for end-to-end crypto verification: ```dns theme={null} ._openpgpkey.example.com. IN OPENPGPKEY ``` ### `CAA`, `CERT`, `DS`, `DNSKEY`, `RRSIG`, `NSEC`, `NSEC3` The DNSSEC chain records, plus `CAA` and `CERT`. All served correctly. NSEC3 with opt-out is supported. ### `URI` Publish a target URI for a name, used by some SSHFP and call-home protocols: ```dns theme={null} _ftp._tcp.example.com. IN URI 10 1 "ftp://ftp.example.com/public" ``` ### `NAPTR` Naming Authority Pointer — used by ENUM, SIP, and XMPP federation: ```dns theme={null} sip.example.com. IN NAPTR 100 50 "s" "SIP+D2U" "" _sip._udp.example.com. ``` ## What's *not* supported A few record types deliberately aren't served by Stackryze DNS: * **Wildcard DNSSEC** at multiple levels without explicit signing. * **`TYPE65534`** and other private/experimental types. If you need an exotic record type not listed here, open an issue on [github.com/stackryze/DNS](https://github.com/stackryze/DNS). ## Where to go next The mental model behind records. Cryptographic validation for your zone. Step-by-step record creation. Manage records programmatically. # Zones and records Source: https://docs.stackryze.com/docs/dns/zones-and-records The mental model that makes DNS make sense — zones, records, delegation, and the lifetime of a query. DNS is simple once you have the right mental model. This page explains what zones and records actually are, how they relate, and what happens when a query is answered. ## A zone is a slice of the namespace A **zone** is a contiguous portion of the DNS namespace that one entity is responsible for serving authoritatively. For example, `example.com` is a zone if `example.com` and everything under it (`app.example.com`, `mail.example.com`, ...) is served by one set of nameservers. The boundary is set by **delegation**. The parent zone (`.com` in this case) holds `NS` records pointing at the nameservers that serve `example.com`. From that point down, `example.com` is its own zone. ## Records are facts about names Inside a zone, **records** are facts about names. Each record says "for this name, this is true." A zone file (or its database equivalent) is just a list of those facts. ```dns theme={null} example.com. 3600 IN A 192.0.2.1 app.example.com. 300 IN CNAME example.com. mail.example.com. 3600 IN A 192.0.2.10 @ 3600 IN MX 10 mail.example.com. ``` | Name | Type | Value | What it means | | ------------------- | ------- | ---------------------- | --------------------------------------------- | | `example.com.` | `A` | `192.0.2.1` | The apex resolves to 192.0.2.1 | | `app.example.com.` | `CNAME` | `example.com.` | `app` is an alias for the apex | | `mail.example.com.` | `A` | `192.0.2.10` | The mail server is at 192.0.2.10 | | `@` | `MX` | `10 mail.example.com.` | Mail for the zone goes to `mail.example.com.` | The trailing dots matter: `example.com.` is the fully-qualified name, and `@` is shorthand for "the apex of this zone." ## The lifetime of a query When a resolver needs the IP for `app.example.com`, here's what happens: 1. **Query the root.** The resolver asks a root server (`.`) where to find `.com`. 2. **Query `.com`.** The `.com` nameservers respond with the `NS` records for `example.com`. 3. **Query the authoritative.** The resolver picks one of those nameservers (or anycast IP) and asks for `app.example.com`. 4. **Follow CNAMEs.** The authoritative responds with a `CNAME` to `example.com`. The resolver follows it. 5. **Final answer.** The authoritative for `example.com` returns the `A` record `192.0.2.1`. 6. **Cache.** The resolver caches the answer for the TTL on the record (here, 300 seconds). Steps 1–4 are called *delegation chasing*. They're the slow part of DNS. Step 5 is fast — once you're at the right authoritative, the answer is local. ## Delegation vs. zone Delegation is the act of one zone pointing at another. `example.com` is delegated from `.com`; `mail.example.com` is *not* delegated (it's the same zone as `example.com`). A common point of confusion: every `NS` record creates a delegation. Sub-delegations (`app.example.com NS ns1.other.com`) are possible but rare and usually a mistake — they hand control of the subtree to a different set of nameservers. In Stackryze DNS, you don't typically create sub-delegations. Every name you add lives inside your one zone, served by Stackryze's four nameservers. ## TTL controls caching Every record has a **TTL** (Time To Live) — the number of seconds a resolver is allowed to cache the answer before re-querying. Stackryze DNS defaults to 300 seconds (5 minutes) for most records. | TTL | When to use | | ------------- | --------------------------------------------------------------- | | 60–300 | Frequently changing records, low-traffic overhead of re-queries | | 3600 | Default for most records | | 86400 (1 day) | Stable records, large deployments that care about query volume | Long TTLs reduce load on the authoritative but slow down changes. Short TTLs let you change records fast but cost more queries. Use long TTLs for `A` records pointing at static infrastructure; use short TTLs during migrations or for dynamic records. ## Wildcards fill gaps A wildcard record (`*.example.com.`) matches any name in the zone that doesn't have a more specific record. It's a way to say "for anything I haven't explicitly named, here's the answer." ## Why zones aren't the same as domains The two get conflated because in practice you usually have one zone per registered domain. But you can have: * **One zone, multiple domains** — common in `CNAME`-based setups. * **Multiple zones, one domain** — rare; happens with sub-delegations. * **Empty zones** — placeholder zones that exist only for the delegation. In Stackryze DNS, the typical model is: one zone per registered domain, with records living under it. Sub-delegations are not exposed in the dashboard because they cause more confusion than they solve. ## Where to go next Every record type Stackryze serves. Where your zone is served from. Add records step by step. # Domain lifecycle Source: https://docs.stackryze.com/docs/domains/domain-lifecycle What happens to a Stackryze Domain from registration through expiry, grace, deletion, and re-release. Every Stackryze Domain moves through the same fixed lifecycle. Knowing the timeline means you can plan renewals, avoid surprise releases, and recover from accidental deletions with confidence. ## States A Stackryze Domain is in exactly one of these states at a time: | State | Meaning | | ------------------------- | ----------------------------------------------------- | | **Active** | Working normally. | | **Expiring Soon** | Less than 60 days until expiry. | | **Expired (grace)** | Past expiry, still resolvable, DNS intact. | | **Pending Deletion** | Soft-deleted; DNS removed; cooling-off timer running. | | **Deleted (cooling-off)** | Name is locked for re-registration. | | **Released** | Name is available for a new registration. | ## The full timeline Day counts are from the original expiry date of a one-year registration: | Day | What happens | | -------------- | --------------------------------------------------------------------------------- | | **−60** | Renewal window opens. Status flips to "Expiring Soon". First email reminder sent. | | **−10** | Second email reminder sent. | | **0** | Domain expires. Status moves to "Expired (grace)". DNS continues to resolve. | | **+1 to +15** | Grace period. Domain still works, all records intact. You can still renew. | | **+15** | Soft deletion. DNS records removed. Name enters cooling-off. | | **+15 to +22** | Cooling-off period. Nobody — including you — can register the name. | | **+22** | Name is released. Anyone can register it again. | The grace period gives you two weeks of buffer after expiry to renew. After the grace period, the DNS is removed and the name enters a one-week cooling-off before it becomes registrable again. ## Renewal Renewal is the only operation that extends a domain's life. It's free for Stackryze Domains and available from 60 days before expiry. After you renew, the expiry clock is reset by one year from the current expiry date (not from today). You can renew: * **From the dashboard** — My Domains → Renew → confirm. * **From the renewal email reminders** — both contain a deep link. * **Up to one renewal per day** is allowed; multiple renewals stack by adding years. After day 0 but before day 15, renewal is still possible from the same dashboard. Once day 15 hits, the domain is deleted and there's no path back. ## Grace period behavior During the 15-day grace period: * **Resolution continues.** Your site, API, and any service backed by the domain keeps working. * **Records remain editable.** You can still update records in the Stackryze DNS dashboard or at your BYOD provider. * **Renewal still works.** Click **Renew** in the dashboard; the expiry extends by one year from the original expiry date. The grace period is your last chance. After day 15, the DNS is removed and the name enters cooling-off. ## Deletion You can delete a domain manually from the **Danger Zone** in the dashboard. Deletion: * Removes all DNS records immediately. * Starts the cooling-off timer at day 0. * Cannot be undone by support. Cooling-off is enforced even for the original owner. If you delete by accident, the fastest recovery is to wait out the cooling-off and re-register — *if* no one else got there first. ## Cooling-off period The cooling-off period protects against foot-shoot scenarios and prevents rapid churn on the same name: * 7 days for deletions you initiate. * 7 days for auto-deletions after the grace period expires. During cooling-off: * The name cannot be registered by anyone, including you. * Anyone hitting the registration form gets a "this name is in cooling-off" message with the days remaining. The cooling-off always runs to completion. There is no override. ## Release and re-registration Once cooling-off ends, the name is released back to the pool. Registration is first-come, first-served. There's no priority for the previous owner. If you want to keep a name, **renew before expiry** or **renew during the grace period**. After release, the name is gone. ## Common questions **Can I shorten the grace period?** No. **Can I shorten the cooling-off?** No. **Can support override the cooling-off?** No. **Does the grace period reset if I renew?** No — the grace period is a one-shot window after expiry. Renewing during grace keeps the original expiry date and doesn't re-arm the grace timer. ## Where to go next What a Stackryze Domain is. Account security, abuse handling. The task-oriented walkthrough for renewals. Common errors and fixes. # Introduction Source: https://docs.stackryze.com/docs/domains/index Free subdomains for founders, freelancers, and small teams — register, manage, and connect in minutes. Stackryze Domains gives you a real, public subdomain you can use on any project, portfolio, or side hustle. It is a free registration service run by the same team behind Stackryze DNS. The full service lives at [domain.stackryze.com](https://domain.stackryze.com). ## What it is A Stackryze Domain is a public subdomain registered under one of four namespaces: ```text theme={null} yourname.indevs.in yourname.sryze.cc yourname.ryzedns.org yourname.nx.kg ``` You pick the namespace at registration time and it stays fixed for the life of the name. The same lifecycle, quota, and feature set apply to every namespace — pick whichever fits your project. ## What you get Every Stackryze Domain includes, out of the box: * A public subdomain in one of four namespaces. * An editable DNS zone, hosted on [Stackryze DNS](/docs/dns) by default. * Two Stackryze nameservers (mandatory) plus up to 4 custom nameservers — Cloudflare, Route 53, DigitalOcean, or any other provider. * A 1-year registration, renewable from 60 days before expiry. * Up to **4 names per account**, one of each namespace. For the rest of the feature set — naming rules, lifecycle details, nameserver delegation — see the [Concepts](#concepts) section below. ## How it fits the Stackryze surface | Product | Role | | ----------------- | ----------------------------------------------------------------- | | Stackryze Domains | The name. Register here. | | Stackryze DNS | The resolution. Hosted authoritative DNS, free with every domain. | | Stackryze API | The automation layer for both. | ## Trust and isolation A Stackryze Domain behaves exactly like a paid domain on the public DNS. There is no read-only mode, no "internal-only" suffix, and no special handling. Browsers, TLS clients, and APIs treat it the same way they treat any other registered name. Every registered name is also submitted to the **Public Suffix List** (PSL). The boundary is enforced by the consumers — browsers, certificate authorities, password managers — not by Stackryze. In practice that means: * Browsers scope cookies and storage to the registered label, so sibling names under `indevs.in` cannot read each other's data. * Certificate authorities verify control of the registered label before issuing TLS certs, the same as for `example.com`. * Password managers segregate credentials per registered name. ## Boundaries A Stackryze Domain is not: * A top-level domain you own. The `indevs.in`, `sryze.cc`, `ryzedns.org`, and `nx.kg` zones belong to the Stackryze registry; you rent your slot under one of them. * A replacement for a paid registrar if you need a custom TLD (`example.com`, `example.io`, etc.). Use [Stackryze DNS](/docs/dns) and [point your own domain](/docs/guides/point-domain-to-stackryze) at it. * Transferable to another registrar. The name lives under its chosen namespace for its lifetime. * Movable between namespaces. Once registered, the namespace is fixed. To switch, delete the name and re-register under a different namespace. ## Concepts Dive into the concept that matches what you're working on. What characters and lengths are valid. Use Stackryze nameservers or bring your own. Register, renew, expire, restore. Account security and abuse handling. ## Task-oriented guides Once you understand the concepts, the guides walk you through the actual steps. Register your first domain. Renewals, nameservers, deletion. Bring your own DNS provider. Common errors and fixes. # Nameserver delegation Source: https://docs.stackryze.com/docs/domains/nameserver-delegation How a Stackryze Domain gets pointed at authoritative nameservers, and what changes when you bring your own. Every Stackryze Domain is delegated to authoritative nameservers the moment you register it. By default those are Stackryze nameservers. You can swap them for any provider you control — that's the "BYOD" (Bring Your Own DNS) model. ## What delegation means A delegation is a set of `NS` records that says "for queries about this zone, ask these nameservers." Whoever controls those nameservers controls the DNS for the domain. For a Stackryze Domain, the registry holds the parent zone (`indevs.in`, `sryze.cc`, `ryzedns.org`, or `nx.kg`). When you register, the registry writes `NS` records under your subdomain pointing at the nameservers you specified. From that point on, every resolver on the internet queries those nameservers for everything under your subdomain. ## Default delegation Every Stackryze Domain is delegated to two **mandatory** Stackryze nameservers: ```dns theme={null} yourname.indevs.in. IN NS ns1.stackryze.com. yourname.indevs.in. IN NS ns2.stackryze.com. ``` The same delegation applies under every namespace. These two are not optional — they're the registry's nameservers and they stay in the zone for the life of the name. You can also add up to **4 extra (custom) nameservers** for redundancy or to point at a third-party provider alongside Stackryze's. The full delegation supports up to **6 NS records** in total — 2 Stackryze (mandatory) plus 4 custom (optional): ```dns theme={null} yourname.indevs.in. IN NS ns1.stackryze.com. yourname.indevs.in. IN NS ns2.stackryze.com. yourname.indevs.in. IN NS ns1.cloudflare.com. ; optional extra yourname.indevs.in. IN NS ns2.cloudflare.com. ; optional extra ``` You then manage records inside the [Stackryze DNS dashboard](https://dns.stackryze.com). This is the path of least resistance — one dashboard, one place to add records, free DNSSEC, modern record types, and an API. ## Adding custom nameservers To point at a third-party provider without losing Stackryze, add its nameservers as extras from the **Nameservers** panel of your domain in the dashboard: 1. Open the domain. 2. Scroll to **Custom nameservers**. 3. Add one or more authoritative hostnames. Up to 4 extras can be configured, for a maximum of 6 NS records in total (2 Stackryze + 4 custom). The provider must already have a zone configured for your subdomain with the nameservers you specified. Stackryze verifies the delegation after a short propagation window and confirms the cutover. A few constraints apply: * **Maximum 6 NS records total** — 2 Stackryze (mandatory) plus up to 4 custom. * **The two Stackryze nameservers cannot be removed** — they anchor the delegation to the registry. * **Publicly reachable.** Stackryze doesn't accept RFC 1918 addresses or hidden primaries. * **Authoritative for your subdomain.** The provider must serve the zone you delegated, not just forward to it. * **Glue records, if needed.** If your nameservers are themselves under one of the four Stackryze namespaces, glue records must be in place. The dashboard handles this automatically. ## Replacing Stackryze entirely (advanced) In some cases — for example, when a third-party provider requires exclusive control of the zone — you may want to delegate only to the third party. Reach out to [support@stackryze.com](mailto:support@stackryze.com) to discuss a fully custom delegation. The two Stackryze nameservers remain in the zone by default, but a support-side handoff can move them out for accounts that need it. ## What changes when you BYOD The DNS records for your domain live at the new provider, not in Stackryze. Stackryze still owns the registration and the renewal clock, but the *resolution* is now your responsibility. Things that stay the same: * The registration and expiry date. * The ability to sign in and renew from the dashboard. * The ability to bring nameservers back to Stackryze at any time. Things that move: * `A`, `AAAA`, `CNAME`, `TXT`, `MX` records. * DNSSEC signing (if you enable it on your side). * Nameserver redundancy strategy. ## Propagation timing Delegation changes propagate through the DNS hierarchy: | Layer | Typical | | -------------------------------------- | -------------- | | Stackryze registry → parent zone | seconds | | Public resolvers picking up the change | 5–10 minutes | | Long-tail resolvers (ISP caches) | up to 48 hours | The registry update is fast. The full internet catching up is not. Plan changes for low-traffic windows when you can, but accept that you cannot control the long tail. ## Switching back to Stackryze nameservers At any point, return the nameservers to: ```text theme={null} ns1.stackryze.com ns2.stackryze.com ``` Your existing zone in Stackryze DNS is preserved — records you had before the BYOD experiment come back. Records you added at the third-party provider are not migrated; copy them by hand if you need them. ## Where to go next Setup guides for Cloudflare, Route 53, DigitalOcean, and more. The default delegation's infrastructure. The walkthrough for changing nameservers. # Security and abuse Source: https://docs.stackryze.com/docs/domains/security-and-abuse How Stackryze Domains keeps accounts safe, handles abuse reports, and reacts to threats. Stackryze Domains is a public service that anyone can register on. That openness comes with responsibility: account security on one side, abuse handling on the other. This page explains both. ## Account security Your Stackryze account is the only thing standing between your domain and someone who wants to take it. A few practices are mandatory; the rest are strongly recommended. ### Authentication | Layer | Required? | | ---------------------------------------------------------------- | ----------- | | Email + password (min 8 chars) | Yes | | Email verification on signup | Yes | | Account lockout after 5 failed attempts (30-minute cooldown) | Yes | | Two-factor authentication on the linked GitHub account (if used) | Recommended | There is no in-app 2FA on the Stackryze Domains dashboard itself — the account is gated by your auth provider (email password, GitHub OAuth). Strengthen *that* account and you strengthen this one. ### What you control Your account has visibility into: * Every domain it owns and their current status. * Nameservers configured for each domain. * Activity history: registrations, nameserver updates, renewals, deletions, logins. If anything on these screens doesn't match what you did, treat it as a security incident. ### What you should enable * **Two-factor authentication** on the email account you registered with. * **Two-factor authentication** on the GitHub account, if you link one. * **A unique password** for the Stackryze Domains account. Don't reuse it. * **A second contact channel** so renewal reminders reach you even if one inbox is compromised. ### Account lockout After five failed login attempts within the lockout window, the account is locked for 30 minutes. This is automatic and not configurable. The lockout applies to all login methods for that account. If you're locked out: 1. Wait 30 minutes. 2. Use the password reset flow if you don't remember the password. 3. Email [support@stackryze.com](mailto:support@stackryze.com) from the address on file if neither works. ## Activity monitoring The **History** section in the dashboard shows every state-changing action on your account. Look for: * Nameserver changes you didn't make. * Renewals on dates you don't recognize. * Login events from IPs or regions you don't recognize. Any of these are reasons to email [security@stackryze.com](mailto:security@stackryze.com) immediately. ## Abuse handling Abuse is anything that uses Stackryze Domains to harm others: spam, phishing, malware hosting, scanning, credential stuffing, and so on. The abuse pipeline is deliberately fast. ### How to report abuse | Channel | Use for | | ------------------------------------------------------------- | ------------------------------------------------------------------------------------- | | [reportabuse@stackryze.com](mailto:reportabuse@stackryze.com) | Any abuse from a `*.indevs.in`, `*.sryze.cc`, `*.ryzedns.org`, or `*.nx.kg` subdomain | | [security@stackryze.com](mailto:security@stackryze.com) | Security issues with the Stackryze Domains service itself | | [support@stackryze.com](mailto:support@stackryze.com) | General questions about a domain or account | A useful report includes: * The exact subdomain being abused (`phish.example.indevs.in`, `phish.example.sryze.cc`, etc.). * The abuse type (phishing kit, malware C2, etc.). * A reproducible URL or sample email. * Timestamps in UTC. The more concrete the report, the faster the response. ### How we handle a report Reports are triaged within one business day. The standard response timeline: 1. **Confirm** the report is well-formed and the abuse is real. 2. **Suspend** the offending nameserver or record (the smallest change that resolves the abuse). 3. **Notify** the domain owner with the report details and the action taken. 4. **Restore** access once the owner addresses the underlying issue, or **escalate** to deletion if the abuse is repeated or severe. Suspended nameservers are not deleted outright — the owner is given the chance to remediate, except in cases of egregious, repeated abuse. ### What we won't do * Disclose owner identity in response to a casual request. (We will, however, cooperate with lawful process.) * Take action on a report without evidence of abuse. * Pre-emptively block entire services or providers because one user abused them. ## Account bans Accounts that violate the [Terms of Service](https://domain.stackryze.com/terms) or [Acceptable Use Policy](https://domain.stackryze.com/aup) can be banned. A banned account: * Is signed out on all devices immediately. * Has all owned domains suspended. * Cannot register new domains. Bans are not reversible through the dashboard. To appeal, email [support@stackryze.com](mailto:support@stackryze.com) from the address on file with your GitHub username and a clear explanation. ## Where to go next What a Stackryze Domain is. Register, renew, expire, restore. Common questions about accounts and bans. Fixes for login and registration errors. # Subdomain naming rules Source: https://docs.stackryze.com/docs/domains/subdomain-naming What characters, lengths, and shapes a Stackryze subdomain name can take. Every Stackryze Domain follows the same naming rules. The rules are enforced at registration and during any custom-nameserver update, so it's worth understanding them once. ## The shape A Stackryze Domain is a single label under one of the four Stackryze namespaces: ```text theme={null} .indevs.in .sryze.cc .ryzedns.org .nx.kg ``` `` is the part you choose. The namespace suffix is fixed at registration and never changes — the same naming rules apply to all four namespaces. ## Length | Bound | Value | | ----------- | --------------- | | Minimum | 3 characters | | Maximum | 63 characters | | Recommended | 8–24 characters | A 3-character name like `abc.indevs.in` is valid but rare. Names in the 8–24 range are easier to read, share, and remember. The same length bounds apply under every namespace. ## Allowed characters A label may contain only: * Lowercase ASCII letters (`a`–`z`) * Digits (`0`–`9`) * Hyphens (`-`) It may **not** contain: * Uppercase letters * Spaces * Underscores or any other punctuation * Internationalized characters (`münchen`, `日本語`, emojis) The system lowercases anything you type, so `MyProject.indevs.in` and `myproject.indevs.in` resolve to the same name. Case insensitivity applies across all four namespaces. ## Position rules for hyphens * A hyphen **cannot** appear as the first character. * A hyphen **cannot** appear as the last character. * Consecutive hyphens are allowed in the middle but are discouraged for readability. | Label | Valid | Why | | ---------------- | ----- | ----------------------- | | `myproject` | ✅ | Lowercase, alphanumeric | | `john-portfolio` | ✅ | Hyphen in the middle | | `api2024` | ✅ | Letters and digits | | `-myproject` | ❌ | Starts with hyphen | | `myproject-` | ❌ | Ends with hyphen | | `My_Project` | ❌ | Uppercase, underscore | | `my project` | ❌ | Space | | `ab` | ❌ | Too short | ## Case insensitivity DNS is case-insensitive. The registry treats `MyProject.indevs.in` and `myproject.indevs.in` as the same name. To avoid ambiguity, always write and share your domain in lowercase, regardless of which namespace it lives under. ## Uniqueness and reuse A name can be owned by one Stackryze account at a time. When a name is released — through deletion, expiry past the grace period, or a registry pull — it enters a **cooling-off period** before it can be registered again. See [Domain lifecycle](/docs/domains/domain-lifecycle) for the timeline. ## Reserved names A small set of labels are reserved for Stackryze services and cannot be registered: * `www`, `mail`, `admin`, `api`, `dashboard` * `ns1`, `ns2`, `ns3`, `ns4` * Anything matching `stackryze`, `indevs`, or a known abuse pattern The registration form rejects these with a clear message before you spend time filling in the CAPTCHA. ## Choosing a good name A few heuristics that hold up over time: * **Pronounceable** beats clever. `tarun.dev` is easier to share than `t8rn-d3v`. * **Stable** beats topical. Names tied to a single project get awkward when the project pivots. * **Short** beats long, once it's still readable. * **Lowercase everywhere** to avoid the casing ambiguity trap. ## Where to go next What a Stackryze Domain is. What happens to a name over time. Register your first domain. Common rejection messages and fixes. # Introduction Source: https://docs.stackryze.com/docs/hosting/index Affordable, transparent hosting with the same Stackryze guarantees — coming soon. Stackryze Hosting is the next product in the Stackryze lineup. The same four pillars as DNS and Domains — trustworthy, affordable, independent, and open by default — extended into application hosting. Hosting is currently in planning. The full service will live at `hosting.stackryze.com` when it ships. ## What it will be Stackryze Hosting is an application hosting platform built around three principles: 1. **Flat, upfront pricing.** No bandwidth surprises, no renewal traps. The price you see is the price you pay. 2. **Open-source runtime.** Built on open software, with a public roadmap and a public issue tracker. No vendor lock-in. 3. **First-class DNS.** Every hosted project ships with a Stackryze DNS zone, pre-wired. ## What you'll get When Stackryze Hosting launches, every project will include: * **Free tier.** A usable free plan, the same way DNS and Domains do it today. * **HTTPS by default.** Automatic certificate provisioning and renewal. * **Custom domains.** Bring your own or use a free Stackryze Domain. * **Git-based deploys.** Push to deploy from any Git host. * **Predictable scaling.** No "request-based" billing surprises. ## What it won't be Stackryze Hosting will deliberately not be: * **A hyperscaler competitor.** We're not trying to match AWS on feature breadth. * **A lock-in platform.** You can leave at any time, taking your code and your data with you. * **A marketplace.** No third-party "add-ons" with their own pricing. ## Status | Product | Status | Live URL | | ----------------- | ------- | -------- | | Stackryze Hosting | Planned | — | ## Where to go next The DNS service that pairs with every hosted project. The naming layer. Get started with DNS and Domains today. # Add a Custom Domain Integration Guide Source: https://docs.stackryze.com/docs/guides/add-a-custom-domain Wire up a domain you already own to a Stackryze-hosted service. This guide walks you through adding a custom domain — one you bought at any registrar — to a Stackryze product (DNS, Domains, or the API). ## Prerequisites To add a custom domain, you'll need: * A Stackryze account (free — see [quickstart](/docs/quickstart)) * A domain you own * Access to your registrar's DNS settings ## Domain Setup Open [dns.stackryze.com](https://dns.stackryze.com) and sign in. Click **Domains → Add Domain**, then enter the apex (for example `example.com`). Stackryze creates an empty zone and provisions four globally-distributed nameservers. Stackryze assigns four nameservers. Copy them — you'll need them in the next step. ```text theme={null} ns1.stackryze.com ns2.stackryze.com ns3.stackryze.com ns4.stackryze.com ``` At your registrar (Namecheap, Cloudflare Registrar, GoDaddy, Porkbun, etc.) set the nameservers to the four above. Save. Propagation typically completes within 30 minutes but can take up to 24 hours. Run: ```bash theme={null} dig NS example.com @1.1.1.1 +short ``` You should see the four Stackryze nameservers. ## Next steps * Add records: see [Configure DNS records](/docs/guides/configure-dns-records) * Turn on DNSSEC: see [Enable DNSSEC](/docs/guides/enable-dnssec) # Configure DNS Records Source: https://docs.stackryze.com/docs/guides/configure-dns-records The complete reference for every record type Stackryze supports. Stackryze supports every standard DNS record type plus the modern ones (SVCB, HTTPS, TLSA) the rest of the industry is still catching up to. ## Classic records Map a name to an IPv4 (`A`) or IPv6 (`AAAA`) address. ```dns theme={null} example.com. 3600 IN A 192.0.2.1 api.example.com. 300 IN AAAA 2001:db8::1 ``` Alias one name to another. `CNAME` is for the leftmost label; `DNAME` redirects the whole subtree. ```dns theme={null} www.example.com. 3600 IN CNAME example.com. ``` Mail exchange. Always pair with an `SPF` (TXT) record and sign with DKIM. ```dns theme={null} example.com. 3600 IN MX 10 mail.example.com. ``` Free-form text. Used for SPF, DKIM, DMARC, domain verification, and DNS-based ACME challenges. ```dns theme={null} example.com. 3600 IN TXT "v=spf1 include:_spf.stackryze.com ~all" _dmarc.example.com. 3600 IN TXT "v=DMARC1; p=reject; rua=mailto:dmarc@example.com" ``` Delegation. You almost never edit this by hand — Stackryze manages it for you. Service locator. Used for XMPP, SIP, Minecraft, Matrix, etc. ```dns theme={null} _minecraft._tcp.example.com. 3600 IN SRV 0 5 25565 mc.example.com. ``` Restrict which CAs may issue certificates for your domain. ```dns theme={null} example.com. 3600 IN CAA 0 issue "letsencrypt.org" ``` ## Modern records Service bindings — the modern way to tell clients *how* to connect to your origin. Stackryze has full RFC 9460 + 9461 support including `alpn`, `port`, `ech`, `ipv4hint`, and `ipv6hint`. ```dns theme={null} example.com. 300 IN HTTPS 1 . alpn="h2,h3" port=443 ipv4hint=192.0.2.1 ech="..." ``` DANE TLS association. Pin a CA, a leaf, or a certificate hash for a service. ```dns theme={null} _443._tcp.example.com. 3600 IN TLSA 3 1 1 abc123... ``` Publish an OpenPGP key in DNS, so anyone can email you encrypted without a keyserver. ## Editing records You can edit records from: 1. The dashboard — click any record to inline-edit 2. The CLI — `stackryze records set --zone example.com ...` (preview) # FAQ Source: https://docs.stackryze.com/docs/guides/dns/faq Common questions about Stackryze DNS — pricing, limits, DNSSEC, and the API. Quick answers to the questions we get most. For deeper reference material, follow the links into the [StackNS documentation](/docs/dns). Stackryze DNS is free for everyone. Verification raises zone limits and unlocks advanced features. ## Pricing and limits ### Is Stackryze DNS really free? Yes. The base service is free for any account. Unverified accounts get three zones; verified accounts get unlimited. ### What does verification unlock? Verified accounts get unlimited zones, scoped API tokens, DNSSEC, webhooks, and the audit log. See [Account verification](/docs/account-verification). ### Are there rate limits? Yes — per-token, per-IP, per-zone. The dynamic-DNS endpoint has a relaxed limit, configurable via `X-Forwarded-For`. See the [API reference](/docs/dns/api) for the exact numbers. ## Zones and records ### How many records can one zone hold? Up to 10,000 records per zone. Most zones are well under 100. The limit exists to keep anycast lookups fast. ### What record types do you support? Every classic record plus the modern ones: `SVCB`, `HTTPS`, `TLSA`, `OPENPGPKEY`, `CAA`, and others. See [Supported records](/docs/dns/supported-records) for the full list. ### Can I import a BIND zone file? Yes. The dashboard accepts zone files in BIND format. The CLI also supports `stackryze zones import --file example.com.zone`. ### What is the minimum TTL? 30 seconds. Lower values are clamped. ## Nameservers and delegation ### Where are your nameservers? Four anycast sites in NYC, Hyderabad, Nuremberg, and São Paulo. See [Nameservers](/docs/dns/nameservers). ### Can I bring my own nameservers? Yes — set custom NS records on your zone. Stackryze still serves as a backup, and DNSSEC continues to work. ### Why do my NS records show all four of your nameservers? That's the default. You can replace any of them with your own; the four we publish are a fallback. ## DNSSEC ### Do you support DNSSEC? Yes, opt-in per zone. Default algorithm is ED25519; ECDSA P-256 and RSA are available. ### Will enabling DNSSEC break anything? No — the change is additive. Until you publish the `DS` record at your registrar, validating resolvers won't trust the chain, but standard resolvers are unaffected. ### How do I roll the KSK? Open the zone, go to **Settings → DNSSEC → Rollover**. The new key is published alongside the old one for the rollover period. ## Dynamic DNS ### How do I push an IP update? ```bash theme={null} curl -X POST https://dns.stackryze.com/api/v1/dynamic/update \ -H "Authorization: Bearer $TOKEN" \ -d '{"zone":"example.com","name":"home","type":"A","value":"192.0.2.1"}' ``` See [Dynamic DNS](/docs/dns/dynamic-dns) and the [Dynamic DNS guide](/docs/guides/dynamic-dns). ### Can I use the same token for DDNS and zone management? You can, but it's better practice to issue a scoped token limited to `dynamic:update` for DDNS clients. ## API ### Where is the API base URL? ``` https://dns.stackryze.com/api/v1 ``` ### How do I authenticate? Bearer tokens. Generate one in **Settings → API tokens**. See the [API reference](/docs/dns/api). ### Are breaking changes versioned? Yes. The `/v1` namespace is stable. Breaking changes ship under a new version (`/v2`) and the old version continues to work. ### Can I scope a token to one zone? Yes. Scoped zone tokens are the recommended pattern for CI/CD and DDNS clients. ## Troubleshooting ### My record changes aren't showing up. Check TTL and propagation. Stackryze pushes changes globally within seconds, but downstream resolvers cache up to the TTL. Run `dig +trace` to see where the stale answer comes from. ### I get `NXDOMAIN` for a record that exists. The most common cause is a missing trailing dot. `example.com` is a relative name inside the zone, but `app.example.com.` (with the trailing dot) is fully qualified. ### My zone won't load in the dashboard. If the dashboard is failing to fetch a zone, the API may be rate-limiting. Wait a minute and reload. ## Where to go next * [API reference](/docs/dns/api) — full endpoint list. * [Supported records](/docs/dns/supported-records) — every record type. * [Nameservers](/docs/dns/nameservers) — where your zone lives. * [DNSSEC](/docs/dns/dnssec) — how to enable it. * [Dynamic DNS](/docs/dns/dynamic-dns) — push IP updates. * [Account verification](/docs/account-verification) — unlock unlimited zones. # Introduction Source: https://docs.stackryze.com/docs/guides/dns/index Task-oriented guides for Stackryze DNS — from your first zone to advanced automation. Pick a guide that matches what you're working on. Each one walks through the actual steps, in order. ## Getting started Wire up a domain you already own. Three ways to point an existing domain at a Stackryze service. ## Day-to-day operations The complete reference for every record type Stackryze supports. Cryptographically verify your zone in three steps. Keep a hostname pointed at a changing IP. # Introduction Source: https://docs.stackryze.com/docs/guides/domains/dns-providers Connect your Stackryze Domain to any DNS provider — pick the one that fits your stack. Stackryze Domains uses a **Bring Your Own DNS (BYOD)** approach. You can point your subdomain at any DNS provider that supports nameserver delegation. This page lists popular providers that work well with Stackryze Domains, with a setup guide for each. ## Pick a provider ### Cloudflare **Free tier:** Yes\ **Features:** Fast global network, DDoS protection, free SSL, analytics\ **Best for:** Most users, from beginners to advanced Step-by-step walkthrough with screenshots. ### AWS Route 53 **Free tier:** Limited (first 12 months)\ **Features:** Highly reliable, integrates with AWS services, health checks\ **Best for:** AWS users, enterprise applications Step-by-step walkthrough with screenshots. ### Google Cloud DNS **Free tier:** Limited\ **Features:** Low latency, integrates with GCP, DNSSEC support\ **Best for:** Google Cloud users, high-traffic applications Quick setup. ### Azure DNS **Free tier:** Limited\ **Features:** Integrates with Azure, high availability\ **Best for:** Microsoft Azure users Quick setup. ### DigitalOcean DNS **Free tier:** Yes (with any DigitalOcean account)\ **Features:** Simple interface, free with any DigitalOcean service\ **Best for:** DigitalOcean users, simple setups Step-by-step walkthrough with screenshots. ### Hetzner DNS **Free tier:** Yes\ **Features:** Free DNS hosting, simple API, reliable infrastructure\ **Best for:** Hetzner customers, European users Quick setup. ### ClouDNS **Free tier:** Yes\ **Features:** Free DNS hosting, multiple record types, API access\ **Best for:** Budget-conscious users, small projects Quick setup. ### Hurricane Electric (HE.net) **Free tier:** Yes\ **Features:** Fully free, IPv6 support, DNSSEC\ **Best for:** Advanced users, IPv6 enthusiasts Quick setup. ### Namecheap FreeDNS **Free tier:** Yes\ **Features:** Free DNS hosting, easy to use\ **Best for:** Namecheap customers, simple projects Quick setup. ### Vercel DNS **Free tier:** Yes (with a Vercel account)\ **Features:** Automatic SSL, edge network, simple setup\ **Best for:** Vercel users, frontend developers Quick setup. ### deSEC **Free tier:** Yes\ **Features:** Free DNSSEC-enabled DNS, privacy-focused, open source\ **Best for:** Privacy-conscious users, DNSSEC requirements Quick setup. ### PowerDNS (self-hosted) **Free tier:** Yes (open source)\ **Features:** Self-hosted, API-driven, highly customizable\ **Best for:** Advanced users, custom infrastructure Full Docker-based setup with PostgreSQL. ### Custom DNS server **Free tier:** Depends on your software\ **Features:** Full control, any server stack you run\ **Best for:** Operators running their own DNS infrastructure Requirements and a reference zone file. ## Choosing a provider ### For beginners Start with [Cloudflare](/docs/guides/domains/dns-providers/cloudflare): * Free tier with no rate limits. * User-friendly dashboard. * Excellent global performance. * Built-in security features. ### For AWS users [Route 53](/docs/guides/domains/dns-providers/route53) integrates cleanly with other AWS services. ### For budget projects [Hurricane Electric](/docs/guides/domains/dns-providers/hurricane-electric) and [ClouDNS](/docs/guides/domains/dns-providers/cloudns) are fully free. ### For enterprise [Route 53](/docs/guides/domains/dns-providers/route53), [Google Cloud DNS](/docs/guides/domains/dns-providers/google-cloud-dns), and [Azure DNS](/docs/guides/domains/dns-providers/azure-dns) provide enterprise-grade reliability with SLA guarantees. ## General requirements Every DNS provider must meet these requirements: * **Nameserver support** — must provide authoritative nameservers. * **Zone management** — must allow you to create and manage DNS zones. * **Public accessibility** — nameservers must be reachable from the internet. * **Standard records** — must support `A`, `AAAA`, `CNAME`, `TXT`, `MX`, and other standard DNS records. Your DNS provider should let you create a zone for your subdomain (for example `yourname.indevs.in`, `yourname.sryze.cc`, `yourname.ryzedns.org`, or `yourname.nx.kg`) and provide at least two nameservers. ## Need help? * [FAQ](/docs/guides/domains/faq) * [Discord Community](https://discord.gg/wr7s97cfM7) * [Email support](mailto:support@stackryze.com) ## Contributing Know a provider that should be listed here? [Open a pull request](https://github.com/stackryze/docs) or [file an issue](https://github.com/stackryze/domains-docs/issues). # Azure DNS Source: https://docs.stackryze.com/docs/guides/domains/dns-providers/azure-dns Connect a Stackryze Domain to Azure DNS. Azure DNS is Microsoft's DNS hosting service, with high availability and tight Azure integration. This guide is in progress. For the most up-to-date instructions, join the [Discord community](https://discord.gg/wr7s97cfM7) or email [support@stackryze.com](mailto:support@stackryze.com). ## Quick setup 1. Create a Microsoft Azure account. 2. Create a DNS zone for your subdomain. 3. Note your Azure DNS nameservers. 4. Register with Stackryze Domains using your nameservers. For detailed instructions, check back soon, join the Discord community, or contact support. ## Resources * [Azure DNS documentation](https://learn.microsoft.com/azure/dns/) ## Need help? * [Discord community](https://discord.gg/wr7s97cfM7) * [Email support](mailto:support@stackryze.com) # Cloudflare Source: https://docs.stackryze.com/docs/guides/domains/dns-providers/cloudflare Connect a Stackryze Domain to Cloudflare DNS in seven steps. Use Cloudflare as the DNS provider for your Stackryze Domain. This is the recommended setup for most users. ## Why Cloudflare? * **Free** — no cost for DNS hosting. * **Fast global network** — 300+ data centers. * **DDoS protection** — built-in. * **Free SSL** — automatic HTTPS for your subdomain. * **Easy to use** — clean dashboard. * **API access** — automate DNS management. ## Prerequisites Before you begin: * ✅ A registered Stackryze Domain on [domain.stackryze.com](https://domain.stackryze.com/). * ✅ A free Cloudflare account — [sign up here](https://cloudflare.com). Haven't registered your subdomain yet? See [Getting started](/docs/guides/domains/getting-started). ## Step 1 — Add your subdomain to Cloudflare 1. Sign in to the [Cloudflare dashboard](https://dash.cloudflare.com/). 2. Click **Add a Site**. Cloudflare dashboard with Add a Site highlighted 3. Enter your **full subdomain**, for example `yourname.indevs.in` (or whichever of the four Stackryze namespaces — `indevs.in`, `sryze.cc`, `ryzedns.org`, `nx.kg` — you registered under). 4. Click **Continue**. Cloudflare add site form with subdomain field Enter your complete subdomain (`myproject.indevs.in`), not just the base domain. ## Step 2 — Select the Free plan 1. Select **Free**. 2. Click **Continue**. Cloudflare plan selection with Free highlighted The Free plan includes everything you need for DNS hosting. Upgrade later if you need more. ## Step 3 — Copy your Cloudflare nameservers Cloudflare assigns unique nameservers to your site: 1. Find the nameserver information on screen. 2. You'll see something like: ```text theme={null} ava.ns.cloudflare.com curt.ns.cloudflare.com ``` 3. Copy both nameservers — you'll need them in the next step. Cloudflare nameservers assigned to the new site Your nameservers will differ from this example. Copy the exact values Cloudflare assigns. **To find them later:** go to **DNS → Records**, then look at the **Cloudflare Nameservers** section. Or check the **Overview** tab. ## Step 4 — Update nameservers in Stackryze Domains 1. Open [domain.stackryze.com](https://domain.stackryze.com/). 2. Go to **My Domains**. 3. Click your domain. 4. In **DNS Configuration**, click **Edit**. 5. Replace the nameservers with your Cloudflare ones: * **Primary:** `ava.ns.cloudflare.com` * **Secondary:** `curt.ns.cloudflare.com` 6. Click **Save**. DNS changes typically propagate in 5–10 minutes, but can take up to 48 hours globally. ## Step 5 — Verify the connection 1. Return to your Cloudflare dashboard **Overview** page. 2. Click **Check nameservers now** to start a check. Cloudflare Check nameservers now button 3. Cloudflare verifies your nameservers. This usually takes a few minutes, but can take up to 24 hours. 4. Cloudflare emails you when your site is active. 5. On success, you see a confirmation message: Cloudflare success message showing the domain is active ## Step 6 — Configure DNS records Now add your DNS records in Cloudflare: 1. Go to **DNS → Records**. Cloudflare DNS Records page 2. Click **Add record**. 3. Configure the record based on your needs: Cloudflare Add record form **Example: GitHub Pages** | Field | Value | | ------------ | ------------------------- | | Type | `CNAME` | | Name | `@` (or your subdomain) | | Target | `yourusername.github.io` | | Proxy status | **DNS only** (gray cloud) | | TTL | Auto | **Example: IP address** | Field | Value | | ------------ | ------------------------- | | Type | `A` | | Name | `@` | | IPv4 address | `192.0.2.1` | | Proxy status | **DNS only** (gray cloud) | | TTL | Auto | **Example: WWW subdomain** | Field | Value | | ------------ | ------------------------- | | Type | `CNAME` | | Name | `www` | | Target | `yourname.indevs.in` | | Proxy status | **DNS only** (gray cloud) | | TTL | Auto | ## Step 7 — Enable SSL (recommended) Once your domain is live: 1. Go to **SSL/TLS**. 2. Set SSL mode to **Full** or **Full (strict)**. 3. Enable **Always Use HTTPS**. Cloudflare provisions SSL certificates automatically. This can take up to 24 hours. ## Proxy status: orange vs gray cloud * **Gray cloud (DNS only)** — recommended to start. * DNS resolution only. * No Cloudflare caching or protection. * Required for some services (email, etc.). * **Orange cloud (Proxied)** — optional. * Traffic routes through Cloudflare. * DDoS protection and caching. * Can break some services (email, certain APIs). Start with the gray cloud until your domain works, then experiment with proxying if needed. ## Common issues ### Nameservers not showing Wait a few minutes after adding your site. Cloudflare needs to provision nameservers. ### DNS not resolving * Confirm nameservers are correct in the Stackryze Domains dashboard. * Wait 5–10 minutes for DNS propagation. * Check DNS records in Cloudflare. * Verify with [DNS Checker](https://dnschecker.org/). ### SSL errors * Confirm your origin server supports HTTPS. * Set SSL mode to **Flexible** if your origin doesn't have SSL. * Wait up to 24 hours for the certificate to provision. ### Domain not working after setup * Confirm nameservers in the Stackryze Domains dashboard match Cloudflare. * Check DNS records in Cloudflare. * Clear browser and DNS cache. * Wait up to 48 hours for full propagation. ## Advanced features * **Page Rules** — custom caching, redirects, and more. * **Workers** — serverless code at the edge. * **Analytics** — traffic statistics and insights. * **API access** — automate DNS management. ## Resources * [Cloudflare documentation](https://developers.cloudflare.com/) * [Cloudflare community](https://community.cloudflare.com/) * [DNS propagation checker](https://dnschecker.org/) ## Need help? * [Discord community](https://discord.gg/wr7s97cfM7) * [Email support](mailto:support@stackryze.com) # ClouDNS Source: https://docs.stackryze.com/docs/guides/domains/dns-providers/cloudns Connect a Stackryze Domain to ClouDNS. ClouDNS offers free DNS hosting with support for multiple record types and API access. This guide is in progress. For the most up-to-date instructions, join the [Discord community](https://discord.gg/wr7s97cfM7) or email [support@stackryze.com](mailto:support@stackryze.com). ## Quick setup 1. Create a ClouDNS account at [cloudns.net](https://www.cloudns.net). 2. Add your subdomain as a zone. 3. Note your ClouDNS nameservers. 4. Register with Stackryze Domains using your nameservers. For detailed instructions, check back soon, join the Discord community, or contact support. ## Resources * [ClouDNS documentation](https://www.cloudns.net/wiki/) ## Need help? * [Discord community](https://discord.gg/wr7s97cfM7) * [Email support](mailto:support@stackryze.com) # Custom DNS server Source: https://docs.stackryze.com/docs/guides/domains/dns-providers/custom Run your own DNS infrastructure and point a Stackryze Domain at it. If you prefer to run your own DNS infrastructure, you can use custom DNS servers with Stackryze Domains. This guide covers the requirements and a reference setup. Stackryze Domains supports four namespaces — `indevs.in`, `sryze.cc`, `ryzedns.org`, and `nx.kg`. Examples below use `yourname.indevs.in`; substitute your registered namespace where applicable. ## Requirements Your custom DNS servers must meet these requirements: * **Publicly accessible** — reachable from the internet. * **Authoritative** — configured as authoritative for your subdomain. * **Reliable** — uptime above 99% recommended. * **Standards compliant** — follow DNS RFCs. * **Multiple servers** — at least two for redundancy. ## Popular DNS server software ### BIND9 **Platform:** Linux, BSD, Windows\ **Difficulty:** Advanced\ **Best for:** Enterprise setups, experienced administrators [BIND documentation](https://www.isc.org/bind/) ### PowerDNS **Platform:** Linux, BSD\ **Difficulty:** Intermediate to advanced\ **Best for:** Modern setups, API-driven management [PowerDNS documentation](https://doc.powerdns.com/) ### NSD **Platform:** Linux, BSD\ **Difficulty:** Intermediate\ **Best for:** Authoritative-only DNS, security-focused setups [NSD documentation](https://www.nlnetlabs.nl/projects/nsd/) ### Knot DNS **Platform:** Linux, BSD\ **Difficulty:** Intermediate\ **Best for:** High-performance setups, DNSSEC [Knot DNS documentation](https://www.knot-dns.cz/) ## Setup overview ### Step 1 — Install DNS server software Choose and install your preferred DNS server on your server(s). ### Step 2 — Configure the zone Create a zone file for your subdomain: ```bind theme={null} $TTL 3600 @ IN SOA ns1.yourdomain.com. admin.yourdomain.com. ( 2024010101 ; Serial 3600 ; Refresh 1800 ; Retry 604800 ; Expire 86400 ) ; Minimum TTL ; Nameservers @ IN NS ns1.yourdomain.com. @ IN NS ns2.yourdomain.com. ; A Records @ IN A 192.0.2.1 www IN A 192.0.2.1 ; AAAA Records (IPv6) @ IN AAAA 2001:db8::1 ; CNAME Records blog IN CNAME yourusername.github.io. ``` ### Step 3 — Test your configuration Before registering, test your DNS servers: ```bash theme={null} # Test nameserver response dig @ns1.yourdomain.com yourname.indevs.in # Test from an external resolver dig yourname.indevs.in @8.8.8.8 ``` ### Step 4 — Register with Stackryze Domains Create your registration in the dashboard: ```json theme={null} { "owner": { "username": "yourgithubusername", "email": "your@email.com" }, "record": { "NS": [ "ns1.yourdomain.com", "ns2.yourdomain.com" ] } } ``` Then in the Stackryze Domains dashboard: 1. Open **My Domains** → your domain → **DNS Configuration**. 2. Replace the nameservers with your custom ones. 3. Click **Save**. ## Best practices ### Use multiple nameservers Always configure at least two nameservers for redundancy: * **Primary:** `ns1.yourdomain.com` * **Secondary:** `ns2.yourdomain.com` ### Geographic distribution Place nameservers in different geographic locations for reliability and performance. ### Monitor uptime Use monitoring tools to ensure your nameservers stay available: * UptimeRobot * Pingdom * StatusCake ### Keep software updated Update your DNS server regularly to patch vulnerabilities. ### Enable DNSSEC (optional) For stronger security, enable DNSSEC on your nameservers. ## Common issues ### Nameservers not responding * Check firewall rules (allow UDP/TCP 53). * Verify the DNS service is running. * Test with `dig @your-nameserver-ip yourdomain.com`. ### Zone not loading * Check zone file syntax. * Review DNS server logs. * Verify the zone is loaded in configuration. ### Slow DNS resolution * Optimize TTL values. * Enable DNS caching. * Check server resources (CPU, memory). ## Security considerations ### Restrict zone transfers Only allow zone transfers to authorized secondaries: ```bind theme={null} allow-transfer { 192.0.2.2; }; ``` ### Rate limiting Implement rate limiting to prevent DNS amplification attacks. ### Glue records If your nameserver hostnames are under the same zone you're delegating, set up glue records with your registrar. ## Need help? * [Discord community](https://discord.gg/wr7s97cfM7) * [Email support](mailto:support@stackryze.com) # deSEC Source: https://docs.stackryze.com/docs/guides/domains/dns-providers/desec Connect a Stackryze Domain to deSEC. deSEC is a free, privacy-focused DNS service with built-in DNSSEC — a good fit for security-conscious users. This guide is in progress. For the most up-to-date instructions, join the [Discord community](https://discord.gg/wr7s97cfM7) or email [support@stackryze.com](mailto:support@stackryze.com). ## Quick setup 1. Create a deSEC account at [desec.io](https://desec.io). 2. Create a domain for your subdomain. 3. Note your deSEC nameservers. 4. Register with Stackryze Domains using your nameservers. For detailed instructions, check back soon, join the Discord community, or contact support. ## Resources * [deSEC documentation](https://desec.readthedocs.io/) ## Need help? * [Discord community](https://discord.gg/wr7s97cfM7) * [Email support](mailto:support@stackryze.com) # DigitalOcean Source: https://docs.stackryze.com/docs/guides/domains/dns-providers/digitalocean Connect a Stackryze Domain to DigitalOcean DNS in six steps. Use DigitalOcean DNS as the DNS provider for your Stackryze Domain. ## Why DigitalOcean DNS? * **Free DNS hosting** — included with any DigitalOcean account. * **Simple interface** — easy-to-use control panel. * **Reliable infrastructure** — built on DigitalOcean's global network. * **Fast propagation** — quick DNS updates. * **API access** — automate DNS management. ## Prerequisites Before you begin: * ✅ A registered Stackryze Domain on [domain.stackryze.com](https://domain.stackryze.com/). * ✅ A DigitalOcean account — [sign up here](https://www.digitalocean.com/). Haven't registered your subdomain yet? See [Getting started](/docs/guides/domains/getting-started). ## Step 1 — Sign in to DigitalOcean 1. Sign in to the [DigitalOcean dashboard](https://cloud.digitalocean.com/). 2. Open **Networking** in the left sidebar. DigitalOcean dashboard with Networking highlighted in the sidebar ## Step 2 — Open the Domains tab 1. Click **Domains**. 2. If this is your first time, add a payment method to continue. 3. Click **Add a domain**. DigitalOcean Networking Domains tab with Add a domain button ## Step 3 — Add your domain 1. In the domain field, enter your **full subdomain** (for example `yourname.indevs.in` — or whichever of the four Stackryze namespaces you registered under). 2. Click **Add Domain**. DigitalOcean Add a domain dialog with subdomain field Enter your complete subdomain from Stackryze Domains (`myproject.indevs.in`), not just the base domain. ## Step 4 — Copy the DigitalOcean nameservers After adding the domain, DigitalOcean shows your nameservers: 1. You'll see three nameservers: ```text theme={null} ns1.digitalocean.com ns2.digitalocean.com ns3.digitalocean.com ``` 2. Copy all three — you'll need them in the next step. DigitalOcean domain record listing showing NS records DigitalOcean uses the same nameservers for every domain. Always copy the values shown in your dashboard. ## Step 5 — Update nameservers in Stackryze Domains 1. Open [domain.stackryze.com](https://domain.stackryze.com/). 2. Go to **My Domains**. 3. Click your domain. 4. In **DNS Configuration**, click **Edit**. 5. Replace the nameservers with your DigitalOcean ones. 6. Click **Save**. See [Managing domains → Updating nameservers](/docs/guides/domains/managing-domains#updating-nameservers) for the full walkthrough. DNS changes propagate within 24–48 hours globally. ## Step 6 — Create an A record Add your DNS records in DigitalOcean: 1. Open your domain's DNS management page. 2. Click **Create a record**. DigitalOcean domain management page with Create a record highlighted 3. Select **A** as the record type. 4. Fill in the form: * **Hostname:** `@` (for the root domain) or your subdomain name. * **Will direct to:** your server's IP address (for example `192.0.2.1`). * **TTL:** `3600` (one hour), or your preferred value. 5. Click **Create Record**. DigitalOcean Create a record dialog filled with A record values That's it — all steps are complete. **Common record types:** * **A** — points to an IPv4 address. * **CNAME** — points to another domain (for example GitHub Pages). * **AAAA** — points to an IPv6 address. * **MX** — for email routing. ## SSL configuration DigitalOcean DNS provides DNS only — SSL certificates must be managed by your hosting provider. **For common hosting platforms:** * **Vercel / Netlify** — automatic SSL provisioning. * **GitHub Pages** — automatic SSL after DNS verification. * **DigitalOcean App Platform** — free automatic SSL. * **Custom server** — use Let's Encrypt or a commercial certificate. Most modern hosting platforms provide free automatic SSL once DNS is configured. ## Common issues ### Domain not added * Confirm you entered the complete subdomain. * Confirm you have an active DigitalOcean account. * Confirm the subdomain format is correct. * Refresh the page and retry. ### DNS not resolving * Confirm nameservers are correct in the Stackryze Domains dashboard. * Wait 10–30 minutes for propagation. * Check DNS records in DigitalOcean. * Verify with [DNS Checker](https://dnschecker.org/). * Confirm all three nameservers are entered. ### Records not updating * Check the TTL value — changes may be cached. * Verify record syntax is correct. * Confirm there are no conflicting records. * Wait for the TTL period to expire before expecting changes. ### Domain not working after setup * Confirm nameservers in the Stackryze Domains dashboard match DigitalOcean. * Check DNS records in DigitalOcean. * Clear browser and DNS cache. * Wait up to 48 hours for full propagation. ## Advanced features * **API access** — manage DNS programmatically. * **IPv6 support** — full AAAA support. * **CAA records** — Certificate Authority Authorization. * **SRV records** — service records. * **Bulk operations** — manage multiple records efficiently. ## Resources * [DigitalOcean DNS documentation](https://docs.digitalocean.com/products/networking/dns/) * [DigitalOcean API reference](https://docs.digitalocean.com/reference/api/api-reference/#tag/Domains) * [DNS propagation checker](https://dnschecker.org/) ## Need help? * [Discord community](https://discord.gg/wr7s97cfM7) * [Email support](mailto:support@stackryze.com) # Google Cloud DNS Source: https://docs.stackryze.com/docs/guides/domains/dns-providers/google-cloud-dns Connect a Stackryze Domain to Google Cloud DNS. Google Cloud DNS is a scalable, reliable DNS service running on Google's infrastructure — a good fit for GCP users. This guide is in progress. For the most up-to-date instructions, join the [Discord community](https://discord.gg/wr7s97cfM7) or email [support@stackryze.com](mailto:support@stackryze.com). ## Quick setup 1. Create a Google Cloud account. 2. Enable the Cloud DNS API. 3. Create a managed zone for your subdomain. 4. Note your Cloud DNS nameservers. 5. Register with Stackryze Domains using your nameservers. For detailed instructions, check back soon, join the Discord community, or contact support. ## Resources * [Google Cloud DNS documentation](https://cloud.google.com/dns/docs) ## Need help? * [Discord community](https://discord.gg/wr7s97cfM7) * [Email support](mailto:support@stackryze.com) # Hetzner Source: https://docs.stackryze.com/docs/guides/domains/dns-providers/hetzner Connect a Stackryze Domain to Hetzner DNS. Hetzner DNS is a free DNS service from Hetzner with reliable infrastructure and a simple API. This guide is in progress. For the most up-to-date instructions, join the [Discord community](https://discord.gg/wr7s97cfM7) or email [support@stackryze.com](mailto:support@stackryze.com). ## Quick setup 1. Create a Hetzner account. 2. Open the Hetzner DNS Console. 3. Create a zone for your subdomain. 4. Note your Hetzner nameservers. 5. Register with Stackryze Domains using your nameservers. For detailed instructions, check back soon, join the Discord community, or contact support. ## Resources * [Hetzner DNS documentation](https://docs.hetzner.com/dns-console/dns/general) ## Need help? * [Discord community](https://discord.gg/wr7s97cfM7) * [Email support](mailto:support@stackryze.com) # Hurricane Electric (HE.net) Source: https://docs.stackryze.com/docs/guides/domains/dns-providers/hurricane-electric Connect a Stackryze Domain to Hurricane Electric DNS. Hurricane Electric provides fully free DNS hosting with IPv6 support and DNSSEC. This guide is in progress. For the most up-to-date instructions, join the [Discord community](https://discord.gg/wr7s97cfM7) or email [support@stackryze.com](mailto:support@stackryze.com). ## Quick setup 1. Create a Hurricane Electric account at [dns.he.net](https://dns.he.net). 2. Add a new domain for your subdomain. 3. Note your HE.net nameservers. 4. Register with Stackryze Domains using your nameservers. For detailed instructions, check back soon, join the Discord community, or contact support. ## Resources * [Hurricane Electric DNS documentation](https://dns.he.net/) ## Need help? * [Discord community](https://discord.gg/wr7s97cfM7) * [Email support](mailto:support@stackryze.com) # Namecheap FreeDNS Source: https://docs.stackryze.com/docs/guides/domains/dns-providers/namecheap Connect a Stackryze Domain to Namecheap FreeDNS. Namecheap FreeDNS offers free DNS hosting with an easy-to-use interface — ideal for Namecheap customers. This guide is in progress. For the most up-to-date instructions, join the [Discord community](https://discord.gg/wr7s97cfM7) or email [support@stackryze.com](mailto:support@stackryze.com). ## Quick setup 1. Create a Namecheap account. 2. Open the FreeDNS service. 3. Add your subdomain. 4. Note your Namecheap nameservers. 5. Register with Stackryze Domains using your nameservers. For detailed instructions, check back soon, join the Discord community, or contact support. ## Resources * [Namecheap FreeDNS documentation](https://www.namecheap.com/domains/freedns/) ## Need help? * [Discord community](https://discord.gg/wr7s97cfM7) * [Email support](mailto:support@stackryze.com) # PowerDNS (self-hosted) Source: https://docs.stackryze.com/docs/guides/domains/dns-providers/powerdns Self-host your nameservers with PowerDNS + PostgreSQL behind Docker. PowerDNS Authoritative Server is a versatile, open-source nameserver with multiple storage backends and an HTTP API. Stackryze uses PowerDNS to power `ns1.stackryze.com` and `ns2.stackryze.com`, which serve all Stackryze Domain subdomains under `indevs.in`, `sryze.cc`, `ryzedns.org`, and `nx.kg`. The walkthrough below uses `yourname.indevs.in` as a working example. If you registered under one of the other namespaces (`sryze.cc`, `ryzedns.org`, `nx.kg`), substitute the namespace everywhere you see `indevs.in`. **Advanced setup — not recommended for beginners.** PowerDNS requires comfort with Linux, DNS internals, Docker, and database administration. If that's not you, start with [Cloudflare](/docs/guides/domains/dns-providers/cloudflare) instead. ## Why PowerDNS? * **Complete control** — own your DNS infrastructure. * **Multiple backends** — PostgreSQL, SQLite, BIND zone files, and more. * **RESTful HTTP API** — programmatic DNS management. * **High performance** — built for millions of queries. * **DNSSEC support** — built in. * **Active development** — regular updates and security patches. ## Prerequisites Before you begin, confirm you have: * ✅ Linux server(s) with root access (minimum two for redundancy). * ✅ Docker and Docker Compose (20.10.0+ recommended). * ✅ A Stackryze Domain registered at [domain.stackryze.com](https://domain.stackryze.com/). * ✅ At least one public static IP. * ✅ Working knowledge of DNS zones and nameserver delegation. * ✅ Familiarity with PostgreSQL (if using the database backend). For production, you need at least two nameservers for redundancy. This guide starts with a single-server setup for learning, then covers replication. ## Docker images PowerDNS publishes official images at [hub.docker.com/u/powerdns](https://hub.docker.com/u/powerdns): | Image | Purpose | Use case | | --------------------------- | ------------------ | --------------------------------- | | `powerdns/pdns-auth-48` | Authoritative v4.8 | Production-ready | | `powerdns/pdns-auth-49` | Authoritative v4.9 | Latest stable | | `powerdns/pdns-auth-master` | Development build | Testing only — not for production | | `powerdns/pdns-recursor` | Recursive resolver | Caching resolver (not used here) | | `powerdns/dnsdist` | DNS load balancer | Advanced load balancing | This guide uses `powerdns/pdns-auth-49` — the latest stable authoritative server. ## Architecture overview ``` [Internet Users] → DNS query → [PowerDNS Auth Server] │ │ reads records ▼ [PostgreSQL Backend] │ ▼ (DNS Records) [Admin/API] → HTTP API → [PowerDNS Auth Server] → port 53 UDP/TCP [Admin/API] → port 8081 → [PowerDNS Auth Server] ``` ## Install with Docker and PostgreSQL PostgreSQL is a solid production backend for PowerDNS — robust, standards-compliant, and feature-rich. ### Step 1 — Create docker-compose.yml ```yaml theme={null} version: '3.8' services: postgres: image: postgres:15 container_name: powerdns-postgres environment: POSTGRES_DB: powerdns POSTGRES_USER: pdns POSTGRES_PASSWORD: pdns-password volumes: - postgres-data:/var/lib/postgresql/data - ./schema-postgres.sql:/docker-entrypoint-initdb.d/schema.sql:ro restart: unless-stopped healthcheck: test: ["CMD-SHELL", "pg_isready -U pdns"] interval: 10s timeout: 5s retries: 5 powerdns: image: powerdns/pdns-auth-49:latest container_name: powerdns-auth hostname: n1.yourdomain.com depends_on: postgres: condition: service_healthy ports: - "53:53/tcp" - "53:53/udp" - "8081:8081/tcp" environment: - PDNS_AUTH_API_KEY=your-secure-random-api-key-here volumes: - ./pdns-postgres.conf:/etc/powerdns/pdns.d/custom.conf:ro restart: unless-stopped volumes: postgres-data: ``` ### Step 2 — Create the PostgreSQL schema Create `schema-postgres.sql` with the official PowerDNS 4.7+ schema: ```sql theme={null} CREATE TABLE domains ( id SERIAL PRIMARY KEY, name VARCHAR(255) NOT NULL, master VARCHAR(128) DEFAULT NULL, last_check INT DEFAULT NULL, type TEXT NOT NULL, notified_serial BIGINT DEFAULT NULL, account VARCHAR(40) DEFAULT NULL, options TEXT DEFAULT NULL, catalog TEXT DEFAULT NULL, CONSTRAINT c_lowercase_name CHECK (((name)::TEXT = LOWER((name)::TEXT))) ); CREATE UNIQUE INDEX name_index ON domains(name); CREATE INDEX catalog_idx ON domains(catalog); CREATE TABLE records ( id BIGSERIAL PRIMARY KEY, domain_id INT DEFAULT NULL, name VARCHAR(255) DEFAULT NULL, type VARCHAR(10) DEFAULT NULL, content VARCHAR(65535) DEFAULT NULL, ttl INT DEFAULT NULL, prio INT DEFAULT NULL, disabled BOOL DEFAULT 'f', ordername VARCHAR(255), auth BOOL DEFAULT 't', CONSTRAINT domain_exists FOREIGN KEY(domain_id) REFERENCES domains(id) ON DELETE CASCADE, CONSTRAINT c_lowercase_name CHECK (((name)::TEXT = LOWER((name)::TEXT))) ); CREATE INDEX rec_name_index ON records(name); CREATE INDEX nametype_index ON records(name,type); CREATE INDEX domain_id ON records(domain_id); CREATE INDEX recordorder ON records (domain_id, ordername text_pattern_ops); CREATE TABLE supermasters ( ip INET NOT NULL, nameserver VARCHAR(255) NOT NULL, account VARCHAR(40) NOT NULL, PRIMARY KEY(ip, nameserver) ); CREATE TABLE comments ( id SERIAL PRIMARY KEY, domain_id INT NOT NULL, name VARCHAR(255) NOT NULL, type VARCHAR(10) NOT NULL, modified_at INT NOT NULL, account VARCHAR(40) DEFAULT NULL, comment VARCHAR(65535) NOT NULL, CONSTRAINT domain_exists FOREIGN KEY(domain_id) REFERENCES domains(id) ON DELETE CASCADE, CONSTRAINT c_lowercase_name CHECK (((name)::TEXT = LOWER((name)::TEXT))) ); CREATE INDEX comments_domain_id_idx ON comments (domain_id); CREATE INDEX comments_name_type_idx ON comments (name, type); CREATE INDEX comments_order_idx ON comments (domain_id, modified_at); CREATE TABLE domainmetadata ( id SERIAL PRIMARY KEY, domain_id INT REFERENCES domains(id) ON DELETE CASCADE, kind VARCHAR(32), content TEXT ); CREATE INDEX domainidmetaindex ON domainmetadata(domain_id); CREATE TABLE cryptokeys ( id SERIAL PRIMARY KEY, domain_id INT REFERENCES domains(id) ON DELETE CASCADE, flags INT NOT NULL, active BOOL, published BOOL DEFAULT TRUE, content TEXT ); CREATE INDEX domainidindex ON cryptokeys(domain_id); CREATE TABLE tsigkeys ( id SERIAL PRIMARY KEY, name VARCHAR(255), algorithm VARCHAR(50), secret VARCHAR(255), CONSTRAINT c_lowercase_name CHECK (((name)::TEXT = LOWER((name)::TEXT))) ); CREATE UNIQUE INDEX namealgoindex ON tsigkeys(name, algorithm); ``` ### Step 3 — Create the PowerDNS config Create `pdns-postgres.conf`: ```ini theme={null} # Database Backend - PostgreSQL launch=gpgsql gpgsql-host=postgres gpgsql-port=5432 gpgsql-dbname=powerdns gpgsql-user=pdns gpgsql-password=pdns-password gpgsql-dnssec=yes # API Configuration api=yes api-key=your-secure-random-api-key-here webserver=yes webserver-address=0.0.0.0 webserver-port=8081 webserver-allow-from=0.0.0.0/0 # Server Configuration master=yes guardian=yes daemon=no disable-syslog=yes log-dns-details=no loglevel=4 # Performance cache-ttl=20 query-cache-ttl=20 negquery-cache-ttl=60 ``` ### Step 4 — Start the services ```bash theme={null} docker-compose up -d ``` ### Step 5 — Verify the connection ```bash theme={null} # Confirm PostgreSQL is running docker exec -it powerdns-postgres psql -U pdns -d powerdns -c "\dt" # Expected tables: domains, records, supermasters, comments, # domainmetadata, cryptokeys, tsigkeys # Test the API curl -H "X-API-Key: your-secure-random-api-key-here" \ http://localhost:8081/api/v1/servers/localhost ``` ### Step 6 — Allow DNS traffic ```bash theme={null} # UFW (Ubuntu/Debian) sudo ufw allow 53/tcp sudo ufw allow 53/udp # Optional: restrict the API to your IP sudo ufw allow from YOUR_IP_ADDRESS to any port 8081 # iptables sudo iptables -A INPUT -p tcp --dport 53 -j ACCEPT sudo iptables -A INPUT -p udp --dport 53 -j ACCEPT ``` Never expose port 8081 (API) to the public internet without authentication and IP restrictions. Use a VPN, SSH tunnel, or firewall rules. ## Manage zones via the API PowerDNS exposes a RESTful HTTP API for zone and record management. ### Create a zone ```bash theme={null} curl -X POST http://YOUR_SERVER_IP:8081/api/v1/servers/localhost/zones \ -H "X-API-Key: your-secure-random-api-key-here" \ -H "Content-Type: application/json" \ -d '{ "name": "yourname.indevs.in.", "kind": "Native", "masters": [], "nameservers": ["n1.yourdomain.com.", "n2.yourdomain.com."] }' ``` Zone names must end with a dot — for example `yourname.indevs.in.`. ### Add an A record ```bash theme={null} curl -X PATCH http://YOUR_SERVER_IP:8081/api/v1/servers/localhost/zones/yourname.indevs.in. \ -H "X-API-Key: your-secure-random-api-key-here" \ -H "Content-Type: application/json" \ -d '{ "rrsets": [ { "name": "yourname.indevs.in.", "type": "A", "ttl": 3600, "changetype": "REPLACE", "records": [ { "content": "192.0.2.1", "disabled": false } ] } ] }' ``` ### Add a CNAME record ```bash theme={null} curl -X PATCH http://YOUR_SERVER_IP:8081/api/v1/servers/localhost/zones/yourname.indevs.in. \ -H "X-API-Key: your-secure-random-api-key-here" \ -H "Content-Type: application/json" \ -d '{ "rrsets": [ { "name": "www.yourname.indevs.in.", "type": "CNAME", "ttl": 3600, "changetype": "REPLACE", "records": [ { "content": "yourname.indevs.in.", "disabled": false } ] } ] }' ``` ### List all zones ```bash theme={null} curl -H "X-API-Key: your-secure-random-api-key-here" \ http://YOUR_SERVER_IP:8081/api/v1/servers/localhost/zones | jq . ``` ### View zone details ```bash theme={null} curl -H "X-API-Key: your-secure-random-api-key-here" \ http://YOUR_SERVER_IP:8081/api/v1/servers/localhost/zones/yourname.indevs.in. | jq . ``` ### Delete a record ```bash theme={null} curl -X PATCH http://YOUR_SERVER_IP:8081/api/v1/servers/localhost/zones/yourname.indevs.in. \ -H "X-API-Key: your-secure-random-api-key-here" \ -H "Content-Type: application/json" \ -d '{ "rrsets": [ { "name": "www.yourname.indevs.in.", "type": "CNAME", "changetype": "DELETE" } ] }' ``` ## Register with Stackryze Domains Once your PowerDNS server is running: 1. Open [domain.stackryze.com](https://domain.stackryze.com/). 2. Go to **My Domains**. 3. Click your domain. 4. In **DNS Configuration**, click **Edit**. 5. Enter your PowerDNS nameserver hostnames: * **Primary:** `n1.yourdomain.com` (must have an `A` record pointing to your server IP). * **Secondary:** `n2.yourdomain.com` (for redundancy, pointing to the secondary server). 6. Click **Save**. Your nameserver hostnames (`n1.yourdomain.com`) must have `A` records in their parent zone pointing to your PowerDNS server IPs. Set up glue records with your registrar if needed. ## Test DNS resolution ### Test against your server directly ```bash theme={null} # A record dig @YOUR_SERVER_IP yourname.indevs.in # Specific record types dig @YOUR_SERVER_IP yourname.indevs.in A dig @YOUR_SERVER_IP www.yourname.indevs.in CNAME # Delegation dig @YOUR_SERVER_IP yourname.indevs.in NS ``` ### Test through public DNS ```bash theme={null} # Wait 5–10 minutes for propagation dig yourname.indevs.in @8.8.8.8 dig yourname.indevs.in @1.1.1.1 ``` ### Online tools * [DNS Checker](https://dnschecker.org/) — global propagation. * [What's My DNS](https://www.whatsmydns.net/) — worldwide propagation. * [IntoDNS](https://intodns.com/) — DNS health check. ## High availability with master-slave replication For production DNS, run at least two nameservers for redundancy. PowerDNS supports master-slave replication using **AXFR (Authoritative Zone Transfer)**. ### How AXFR works 1. The **master** (n1) holds the authoritative data. 2. The **slave** (n2) periodically pulls zone updates from the master. 3. Zone data is transferred via AXFR over TCP port 53. 4. The slave stays in sync automatically. **Benefits:** * Redundancy if the master fails. * Load distribution across both servers. * Geographic distribution for performance. * Automatic synchronization. **Stackryze infrastructure:** * `ns1.stackryze.com` — **master (primary)**. * `ns2.stackryze.com` — **slave (secondary)**. When a user updates their nameservers through the Stackryze platform, the API updates n1; n2 receives changes via AXFR. ### Master configuration (`n1.yourdomain.com`) Create `pdns-master.conf`: ```ini theme={null} # Database Backend launch=gpgsql gpgsql-host=postgres gpgsql-port=5432 gpgsql-dbname=powerdns gpgsql-user=pdns gpgsql-password=pdns-password gpgsql-dnssec=yes # API Configuration api=yes api-key=your-secure-api-key webserver=yes webserver-address=0.0.0.0 webserver-port=8081 webserver-allow-from=127.0.0.1,YOUR_ADMIN_IP # Master Configuration master=yes slave=no # AXFR Settings allow-axfr-ips=SLAVE_SERVER_IP also-notify=SLAVE_SERVER_IP only-notify=SLAVE_SERVER_IP # Performance cache-ttl=20 query-cache-ttl=20 negquery-cache-ttl=60 ``` Replace `SLAVE_SERVER_IP` with your secondary server's IP (for example `203.0.113.2`). ### Slave configuration (`n2.yourdomain.com`) Create `pdns-slave.conf`: ```ini theme={null} # Database Backend launch=gpgsql gpgsql-host=postgres gpgsql-port=5432 gpgsql-dbname=powerdns gpgsql-user=pdns gpgsql-password=pdns-password gpgsql-dnssec=yes # Slave Configuration master=no slave=yes # Performance cache-ttl=20 query-cache-ttl=20 negquery-cache-ttl=60 # Logging loglevel=4 log-dns-queries=no ``` ### Set up replication **Step 1 — Add the master as a supermaster on the slave:** ```bash theme={null} docker exec -it powerdns-postgres-slave psql -U pdns -d powerdns -e \ "INSERT INTO supermasters (ip, nameserver, account) VALUES ('MASTER_SERVER_IP', 'n1.yourdomain.com.', 'admin');" ``` Replace `MASTER_SERVER_IP` with the master's IP. **Step 2 — Create the zone on the master as `Master`:** ```bash theme={null} curl -X POST http://MASTER_IP:8081/api/v1/servers/localhost/zones \ -H "X-API-Key: your-secure-api-key" \ -H "Content-Type: application/json" \ -d '{ "name": "yourname.indevs.in.", "kind": "Master", "masters": [], "nameservers": ["n1.yourdomain.com.", "n2.yourdomain.com."] }' ``` **Step 3 — Verify replication:** ```bash theme={null} # Query the slave directly dig @SLAVE_SERVER_IP yourname.indevs.in SOA # Compare SOA serial numbers dig @MASTER_IP yourname.indevs.in SOA dig @SLAVE_IP yourname.indevs.in SOA # Serials should match. ``` ### How updates propagate 1. Admin makes a change on the **master** (n1) via API. 2. Master increments the zone's SOA serial. 3. Master sends **NOTIFY** to the slave (n2). 4. Slave requests **AXFR** from the master. 5. Master transfers the full zone. 6. Slave updates its local database. 7. Both servers serve identical DNS data. ### Firewall for AXFR **On the master:** ```bash theme={null} # DNS queries from anyone sudo ufw allow 53/tcp sudo ufw allow 53/udp # AXFR from the slave only sudo ufw allow from SLAVE_SERVER_IP to any port 53 proto tcp ``` **On the slave:** ```bash theme={null} sudo ufw allow 53/tcp sudo ufw allow 53/udp ``` ### Troubleshooting replication **Slave not receiving zones:** ```bash theme={null} docker logs powerdns-auth-master | grep AXFR docker logs powerdns-auth-slave | grep AXFR docker exec powerdns-auth-slave pdns_control retrieve yourname.indevs.in ``` **AXFR denied:** * Confirm `allow-axfr-ips` on the master includes the slave IP. * Confirm the firewall allows TCP 53 from slave to master. * Confirm the slave IP is correct in the master config. ## Security best practices ### Restrict API access ```ini theme={null} # pdns.conf webserver-allow-from=127.0.0.1,YOUR_ADMIN_IP/32 ``` ### Use strong API keys ```bash theme={null} openssl rand -base64 32 ``` ### Enable DNSSEC (optional) ```bash theme={null} docker exec -it powerdns-auth pdnsutil secure-zone yourname.indevs.in docker exec -it powerdns-auth pdnsutil show-zone yourname.indevs.in ``` ### Keep software updated ```bash theme={null} docker-compose pull docker-compose up -d ``` ### Monitor logs ```bash theme={null} docker-compose logs -f powerdns ``` ### Disable query logging in production ```ini theme={null} # pdns.conf log-dns-queries=no log-dns-details=no ``` Query logging can hurt performance and fill disk. ## Common issues ### Port 53 already in use Another service (often `systemd-resolved`) is using port 53. ```bash theme={null} sudo lsof -i :53 # Stop systemd-resolved sudo systemctl stop systemd-resolved sudo systemctl disable systemd-resolved # Or configure it to not bind to port 53 sudo nano /etc/systemd/resolved.conf # Set: DNSStubListener=no sudo systemctl restart systemd-resolved ``` ### Database connection failed * Verify the database container is running: `docker-compose ps`. * Confirm credentials match in `docker-compose.yml` and `pdns.conf`. * Wait 30–60 seconds after starting the database before starting PowerDNS. * Check database logs: `docker-compose logs postgres`. ### DNS queries not responding ```bash theme={null} docker-compose ps docker-compose logs powerdns sudo netstat -tulpn | grep :53 dig @127.0.0.1 yourname.indevs.in sudo ufw status ``` ### API returns 401 Unauthorized * Confirm the `X-API-Key` header matches the key in `pdns.conf`. * Confirm `api=yes` is set. * Restart PowerDNS after config changes: `docker-compose restart powerdns`. * Test the API directly: `curl http://localhost:8081/api`. ### Zone not found ```bash theme={null} curl -H "X-API-Key: your-key" \ http://localhost:8081/api/v1/servers/localhost/zones docker exec -it powerdns-postgres psql -U pdns -d powerdns -e \ "SELECT * FROM domains;" ``` Confirm the zone name ends with a dot (`yourname.indevs.in.`). ## Monitoring and maintenance ### Server statistics ```bash theme={null} curl -H "X-API-Key: your-secure-random-api-key-here" \ http://YOUR_SERVER_IP:8081/api/v1/servers/localhost/statistics | jq . ``` ### Backup **SQLite:** ```bash theme={null} docker exec powerdns-auth sqlite3 /var/lib/powerdns/pdns.sqlite3 .dump \ > backup-$(date +%Y%m%d).sql ``` **PostgreSQL:** ```bash theme={null} docker exec powerdns-postgres pg_dump -U pdns powerdns \ > backup-$(date +%Y%m%d).sql ``` ### Restore **SQLite:** ```bash theme={null} docker exec -i powerdns-auth sqlite3 /var/lib/powerdns/pdns.sqlite3 \ < backup-20260114.sql ``` **PostgreSQL:** ```bash theme={null} docker exec -i powerdns-postgres psql -U pdns -d powerdns \ < backup-20260114.sql ``` ## Performance tuning ```ini theme={null} # pdns.conf cache-ttl=20 negquery-cache-ttl=60 query-cache-ttl=20 max-cache-entries=1000000 ``` ## Resources * [Official documentation](https://doc.powerdns.com/authoritative/index.html) * [Docker Hub](https://hub.docker.com/u/powerdns) * [Docker README](https://github.com/PowerDNS/pdns/blob/master/Docker-README.md) * [HTTP API](https://doc.powerdns.com/authoritative/http-api/index.html) * [PostgreSQL backend](https://doc.powerdns.com/authoritative/backends/generic-postgresql.html) * [GitHub](https://github.com/PowerDNS/pdns) * [Community forum](https://community.powerdns.com) ## Simpler alternatives If PowerDNS feels heavy, try one of these instead: * [Cloudflare](/docs/guides/domains/dns-providers/cloudflare) — recommended for beginners. * [Hurricane Electric](/docs/guides/domains/dns-providers/hurricane-electric) — free, simple interface. * [deSEC](/docs/guides/domains/dns-providers/desec) — privacy-focused, with an API. * [ClouDNS](/docs/guides/domains/dns-providers/cloudns) — free tier with good features. ## How Stackryze uses PowerDNS Stackryze runs PowerDNS to power our authoritative nameservers: * `ns1.stackryze.com` (primary) — PostgreSQL backend, receives updates from the API. * `ns2.stackryze.com` (secondary) — PostgreSQL replication from n1. These servers manage DNS delegation for every `indevs.in` subdomain through the PowerDNS HTTP API — zone creation and record management are fully automated when users register domains. Beginners should start with [Cloudflare](/docs/guides/domains/dns-providers/cloudflare). Self-hosting DNS requires significant expertise in system administration, security, and DNS protocols. ## Need help? * [Discord community](https://discord.gg/wr7s97cfM7) * [Email support](mailto:support@stackryze.com) # Route 53 Source: https://docs.stackryze.com/docs/guides/domains/dns-providers/route53 Connect a Stackryze Domain to AWS Route 53 in six steps. Use AWS Route 53 as the DNS provider for your Stackryze Domain. ## Why Route 53? * **Highly reliable** — 100% uptime SLA with global DNS infrastructure. * **Advanced routing** — traffic flow, geolocation, and failover policies. * **Full control** — complete DNS record management. * **Scalable** — enterprise-grade DNS for production workloads. * **AWS integration** — seamless with other AWS services. ## Prerequisites Before you begin: * ✅ A registered Stackryze Domain on [domain.stackryze.com](https://domain.stackryze.com/). * ✅ An AWS account — [sign up here](https://aws.amazon.com/). Haven't registered your subdomain yet? See [Getting started](/docs/guides/domains/getting-started). Route 53 is a paid service. Hosted zones cost \$0.50/month plus query charges. See [AWS pricing](https://aws.amazon.com/route53/pricing/) for details. ## Step 1 — Open Route 53 in the AWS console 1. Sign in to the [AWS Console](https://console.aws.amazon.com/). 2. In the search bar, search for **Route 53**. 3. Click the service. AWS console search for Route 53 ## Step 2 — Open Hosted zones 1. In the left sidebar, click **Hosted zones**. 2. Click **Create hosted zone**. Route 53 dashboard with Create hosted zone button ## Step 3 — Create the hosted zone 1. Enter your **full subdomain** (for example `yourname.indevs.in` — or whichever of the four Stackryze namespaces you registered under). 2. Fill in the details: * **Domain name:** your complete subdomain from Stackryze. * **Type:** select **Public Hosted Zone**. * **Description:** (optional) add a note. 3. Click **Create hosted zone**. Route 53 Create hosted zone form Enter your complete subdomain from Stackryze Domains (`myproject.indevs.in`), not just the base domain. ## Step 4 — Copy the nameservers Route 53 assigns four nameservers: 1. Find the **NS** record in your hosted zone. 2. You'll see four nameservers: ```text theme={null} ns-123.awsdns-45.com ns-678.awsdns-90.net ns-1234.awsdns-56.org ns-5678.awsdns-12.co.uk ``` 3. Copy all four — you'll need them in the next step. Route 53 hosted zone showing NS records Your nameservers differ from this example. Copy the exact values AWS assigns. ## Step 5 — Update nameservers in Stackryze Domains 1. Open [domain.stackryze.com](https://domain.stackryze.com/). 2. Go to **My Domains**. 3. Click your domain. 4. In **DNS Configuration**, click **Edit**. 5. Replace the nameservers with your Route 53 ones. 6. Click **Save**. See [Managing domains → Updating nameservers](/docs/guides/domains/managing-domains#updating-nameservers) for the full walkthrough. DNS changes propagate within 24–48 hours globally. ## Step 6 — Create a record Add DNS records in Route 53: 1. Select your hosted zone. 2. Click **Create record**. Route 53 hosted zone with Create record button 3. Select a record type and fill in the form: * **Record name:** `@` (for root) or your subdomain. * **Record type:** `A`, `CNAME`, `AAAA`, `MX`, etc. * **Value:** your target value (IP address, domain, etc.). * **TTL:** `300` (5 minutes) or your preferred value. * **Routing policy:** Simple routing (or an advanced policy). 4. Click **Create records**. Route 53 Create record form filled with A record values That's it — all steps are complete. **Common record types:** * **A** — points to an IPv4 address (for example `192.0.2.1`). * **CNAME** — points to another domain (for example `yourusername.github.io`). * **AAAA** — points to an IPv6 address. * **MX** — for email routing. * **TXT** — for verification and SPF records. Route 53 supports advanced routing policies: weighted, latency-based, failover, and geolocation. ## SSL configuration Route 53 provides DNS only — SSL certificates must be managed by your hosting provider or AWS services. **For common hosting platforms:** * **Vercel / Netlify** — automatic SSL provisioning. * **GitHub Pages** — automatic SSL after DNS verification. * **AWS services (CloudFront, ALB, API Gateway)** — use AWS Certificate Manager (ACM) for free SSL. * **Custom server** — use Let's Encrypt or a commercial certificate. Most modern hosting platforms provide free automatic SSL once DNS is configured. ACM certificates are free with AWS services and renew automatically. ## Common issues ### Hosted zone not created * Confirm your IAM permissions include Route 53. * Confirm you selected **Public Hosted Zone**. * Confirm the subdomain format is correct. ### DNS not resolving * Confirm nameservers are correct in the Stackryze Domains dashboard. * Wait 10–30 minutes for propagation. * Check DNS records in Route 53. * Verify with [DNS Checker](https://dnschecker.org/). * Confirm all four nameservers are entered. ### High costs * Review Route 53 pricing before use. * Monitor query volume in CloudWatch. * Consider Route 53 only for production domains. * Use free providers for development and testing. ## Advanced features * **Traffic Flow** — visual traffic policy editor. * **Health Checks** — monitor endpoint availability. * **Routing Policies** — weighted, latency, geolocation, failover. * **DNSSEC** — Domain Name System Security Extensions. * **Query Logging** — log DNS queries to CloudWatch. ## Resources * [Route 53 documentation](https://docs.aws.amazon.com/route53/) * [Route 53 pricing](https://aws.amazon.com/route53/pricing/) * [AWS Certificate Manager](https://aws.amazon.com/certificate-manager/) * [DNS propagation checker](https://dnschecker.org/) ## Need help? * [Discord community](https://discord.gg/wr7s97cfM7) * [Email support](mailto:support@stackryze.com) # Vercel DNS Source: https://docs.stackryze.com/docs/guides/domains/dns-providers/vercel-dns Connect a Stackryze Domain to Vercel DNS. Vercel DNS provides automatic SSL and an edge network — perfect for frontend developers using Vercel. This guide is in progress. For the most up-to-date instructions, join the [Discord community](https://discord.gg/wr7s97cfM7) or email [support@stackryze.com](mailto:support@stackryze.com). ## Quick setup 1. Create a Vercel account. 2. Add your subdomain to a Vercel project. 3. Note your Vercel nameservers. 4. Register with Stackryze Domains using your nameservers. For detailed instructions, check back soon, join the Discord community, or contact support. ## Resources * [Vercel Domains documentation](https://vercel.com/docs/projects/domains) ## Need help? * [Discord community](https://discord.gg/wr7s97cfM7) * [Email support](mailto:support@stackryze.com) # FAQ Source: https://docs.stackryze.com/docs/guides/domains/faq Quick answers to the most common Stackryze Domains questions. Quick answers to common questions. For detailed guides, follow the links below. Stackryze Domains is currently in beta and updated daily. If you spot an issue, let us know via the support channels at the bottom of this page. ## Namespaces ### What namespaces are available? Stackryze Domains registers names under four namespaces: | Namespace | Notes | | ------------- | ------------------------------------------------------ | | `indevs.in` | The original namespace. Most existing names live here. | | `sryze.cc` | Short-form namespace, popular for projects. | | `ryzedns.org` | Open-community namespace. | | `nx.kg` | Compact namespace, intended for tooling and services. | Pick the namespace you want when you register. The same quota, lifecycle, and feature set apply to every namespace. ### Can I move a name between namespaces? No. Once registered, the namespace is fixed. To switch, delete the name (subject to the cooling-off period) and re-register under a different namespace. ## General ### How long is my domain valid? One year from registration. You can renew 60 days before expiry. See [Managing domains → Renewing domains](/docs/guides/domains/managing-domains#renewing-domains). ### Is there a cost? No. Stackryze Domains is 100% free, with no hidden fees. ### How many domains can I register? Up to **4 names** per account, with one of each namespace (`indevs.in`, `sryze.cc`, `ryzedns.org`, `nx.kg`). Need more? Email [support@stackryze.com](mailto:support@stackryze.com). See [Managing domains → Domain limits and quotas](/docs/guides/domains/managing-domains#domain-limits-and-quotas). ## Registration ### Can I change my subdomain name after registration? No. Subdomain names are fixed at registration. To rename, delete the domain and register a new one. ### What if I make a mistake during registration? Delete the domain within 15 days and register again. The name becomes available after the 7-day cooling-off period. See the [Getting started guide](/docs/guides/domains/getting-started). ### Why was my domain registration rejected? Common reasons: name too short or long, invalid characters, already taken, or in a cooling-off period. See [Troubleshooting → Domain registration issues](/docs/guides/domains/troubleshooting#domain-registration-issues). ## DNS and nameservers ### What are nameservers? Nameservers tell the internet where to find DNS for your domain. The defaults are `ns1.stackryze.com` and `ns2.stackryze.com`. See [DNS providers](/docs/guides/domains/dns-providers). ### Can I use my own DNS provider? Yes — Cloudflare, Route 53, Google Cloud DNS, DigitalOcean, and more. We document the setup for each. Start with [Cloudflare setup](/docs/guides/domains/dns-providers/cloudflare). ### How long does DNS propagation take? Typically 5–10 minutes, but up to 48 hours globally. See [Troubleshooting → DNS and nameserver issues](/docs/guides/domains/troubleshooting#dns-and-nameserver-issues). ## Domain management ### How do I renew my domain? Open **My Domains**, click **Renew**, confirm. It's free. See [Managing domains → Renewing domains](/docs/guides/domains/managing-domains#renewing-domains). ### What happens if my domain expires? | Timeline | What happens | | ---------- | ---------------------------------- | | Days 1–15 | Grace period — domain still works. | | Day 15 | Deleted, DNS removed. | | Days 15–22 | Cooling-off period. | | Day 22+ | Available for registration again. | See [Managing domains → What if you don't renew?](/docs/guides/domains/managing-domains#what-if-you-dont-renew). ### How do I delete a domain? Open the domain page → **Danger Zone** → **Delete Domain**. DNS is removed immediately. See [Managing domains → Deleting domains](/docs/guides/domains/managing-domains#deleting-domains). ### Can I restore a deleted domain? No. Once deleted, a domain enters a 7-day cooling-off period. After that, anyone can register it again as a new domain. See [Managing domains → Deleting domains](/docs/guides/domains/managing-domains#deleting-domains). ## Account and security ### Why do I need a GitHub account? GitHub OAuth provides secure, accountable authentication. It prevents spam and lets us tie activity to a real identity. ### Can I use a brand-new GitHub account? GitHub accounts must be at least seven days old. See [Troubleshooting → Login issues](/docs/guides/domains/troubleshooting#login-issues). ### How do I change my email address? Your account email is linked to GitHub. Update it in your [GitHub email settings](https://github.com/settings/emails). ## Troubleshooting ### My domain isn't resolving Check nameservers, confirm DNS records exist at your provider, and wait up to 48 hours for propagation. See [Troubleshooting → DNS and nameserver issues](/docs/guides/domains/troubleshooting#dns-and-nameserver-issues). ### I can't renew my domain Renewal opens 60 days before expiry. Check your expiry date. See [Troubleshooting → Domain management issues](/docs/guides/domains/troubleshooting#domain-management-issues). ### I accidentally deleted my domain Deletion is permanent. Wait for the 7-day cooling-off period, then re-register the name. See [Troubleshooting → Domain management issues](/docs/guides/domains/troubleshooting#domain-management-issues). ## Support ### How do I contact support? * **Discord** — [Join the community](https://discord.gg/wr7s97cfM7) (fastest). * **General** — [support@stackryze.com](mailto:support@stackryze.com). * **Security** — [security@stackryze.com](mailto:security@stackryze.com). * **Abuse** — [reportabuse@stackryze.com](mailto:reportabuse@stackryze.com). We only contact you from official `@stackryze.com` addresses. Anything else is not from us. ### How long does support take to respond? Typically 24–48 hours on business days. Discord is faster for live help. ## More help Register your first domain. Renewals, updates, deletions. Setup guides for popular providers. Common issues and fixes. # Getting started Source: https://docs.stackryze.com/docs/guides/domains/getting-started Create your account, register your first Stackryze Domain, and verify it is active. This guide walks you through creating your account and registering your first Stackryze Domain. Stackryze Domains supports four namespaces — `indevs.in`, `sryze.cc`, `ryzedns.org`, and `nx.kg`. The examples below use `yourname.indevs.in`; substitute whichever namespace you registered under. Stackryze Domains is currently in beta and updated daily. If you find an issue, report it via the support channels at the bottom of this page. ## Step 1 — Visit the registration site 1. Go to [domain.stackryze.com](https://domain.stackryze.com/). 2. Click **Get Started** in the top right. Stackryze Domains landing page with Get Started button ## Step 2 — Create an account ### Option A: Email and password (recommended) 1. Click **Get Started** or **Register**. 2. Enter your **Name**, **Email**, and a secure **Password**. 3. Complete the Cloudflare Turnstile check. 4. Click **Create Account**. 5. We email you a six-digit verification code. Enter it to confirm. Didn't receive the code? Click **Resend** on the verification page to get a new one. ### Option B: GitHub New GitHub registrations are paused. To use GitHub login, first create an account with email and password (using the same email as your GitHub account), then link GitHub from the login screen. If you already have an account: 1. Click **Login**. 2. Select the **GitHub** tab. 3. Authenticate with GitHub. ### Account protection * **Email verification** is required for every new account. * After five failed login attempts, the account is locked for 30 minutes. * Passwords must be at least eight characters. ## Step 3 — Open the Register Domain screen After logging in, click **Register Domain** in the sidebar. Stackryze Domains dashboard with Register Domain in the sidebar ## Step 4 — Complete the registration form Stackryze Domains registration form ### 1. Enter your subdomain name Type your desired subdomain in the input field. **Rules:** * **Length:** 3–63 characters. * **Characters:** lowercase letters, numbers, and hyphens only. * **Format:** cannot start or end with a hyphen. **Examples:** * ✅ `myproject` → `myproject.indevs.in` * ✅ `john-portfolio` → `john-portfolio.indevs.in` * ❌ `ab` (too short) * ❌ `-myproject` (starts with a hyphen) ### 2. Check availability The system checks availability as you type: * 🟢 Green checkmark — available. * 🔴 Red X — taken or invalid. ### 3. Accept the terms Check the box to accept the [Terms of Service](https://domain.stackryze.com/terms) and [Privacy Policy](https://domain.stackryze.com/privacy). ### 4. Complete the CAPTCHA Complete the hCaptcha to prove you're human. ### 5. Click Register Domain Click **Register Domain** to complete registration. **What happens next:** * ✅ Your domain is registered immediately. * ✅ Default nameservers (`ns1.stackryze.com`, `ns2.stackryze.com`) are assigned. * ✅ Domain is valid for one year. * ✅ You see a success message. ## Step 5 — You're done Your domain is now active. From here: * View it at **My Domains**. * Set up DNS records with your preferred provider — start with the [Cloudflare guide](/docs/guides/domains/dns-providers/cloudflare). * Learn how to [manage your domain](/docs/guides/domains/managing-domains). ## Domain limits You can register up to five domains by default. Subdomain names must be 3–63 characters long. See the full quotas and how to request a limit increase. ## Need help? * [Troubleshooting](/docs/guides/domains/troubleshooting) — common errors and fixes. * [Discord Community](https://discord.gg/wr7s97cfM7) — fastest support. * [Email Support](mailto:support@stackryze.com). * [GitHub Issues](https://github.com/stackryze/domains-docs/issues) — bug reports. # Managing domains Source: https://docs.stackryze.com/docs/guides/domains/managing-domains Update nameservers, renew, and delete Stackryze Domains from your dashboard. Learn how to manage your registered domains, update nameservers, renew them, and delete them when you're done. ## Accessing your domains 1. Sign in at [domain.stackryze.com](https://domain.stackryze.com/). 2. Click **My Domains** in the sidebar. You'll see every domain you own with its status, expiry date, and nameservers. ## Domain overview Each domain shows: * **Domain name** — your subdomain (for example `yourname.indevs.in`, `yourname.sryze.cc`, `yourname.ryzedns.org`, or `yourname.nx.kg`). * **Status** — Active, Expiring Soon, or Expired. * **Registered on** — registration date. * **Expiry date** — when the domain expires. * **Registration period** — current validity (one year, fixed). * **DNS configuration** — current nameservers. Stackryze Domains dashboard showing domain detail page ## Updating nameservers Every Stackryze Domain keeps the two Stackryze nameservers in the zone (`ns1.stackryze.com` and `ns2.stackryze.com`) and supports up to **4 additional custom nameservers** for redundancy or to point at a third-party provider alongside Stackryze. The maximum number of NS records per domain is **6** — 2 Stackryze (mandatory) plus 4 custom (optional). To add a third-party provider: Create the zone at your new provider first. See the [DNS providers](/docs/guides/domains/dns-providers) list for step-by-step guides. Go to **My Domains** and click **Manage** on your domain. Scroll to **DNS Configuration → Custom nameservers** and click **Add**. Add up to 4 authoritative hostnames: * **Custom 1:** `ns1.example.com` * **Custom 2:** `ns2.example.com` Click **Save**. The 2 Stackryze nameservers stay in place alongside your additions. The Stackryze nameservers cannot be removed through the dashboard. If you need to delegate entirely to a third party, contact [support@stackryze.com](mailto:support@stackryze.com). DNS changes propagate in 5–10 minutes, but can take up to 48 hours globally. ### Verify propagation ```bash theme={null} dig NS yourname.indevs.in ``` Or use [DNS Checker](https://dnschecker.org/) or [What's My DNS](https://www.whatsmydns.net/). ## Renewing domains Domains are valid for one year from registration. ### When you can renew * Renewal opens 60 days before expiry. * Email reminders go out at 60 days and 10 days before expiry. ### How to renew 1. Go to **My Domains**. 2. Find your domain in the list. 3. Click **Renew** (the green button on the right). 4. Confirm. 5. Expiry extends by one year. Domain list with Renew button highlighted Renewal is 100% free — there is no charge to extend a Stackryze Domain. If you click **Renew** before the 60-day window, you'll see a message showing when renewal becomes available. Cannot renew message shown when outside the renewal window ### What if you don't renew? | Timeline | What happens | | ---------- | ------------------------------------------------------------------ | | Day 0 | Domain expires (status moves to Expired automatically). | | Days 1–15 | Grace period — domain still works, DNS remains active. | | Day 15 | Soft-deleted; DNS records removed. | | Days 15–22 | Cooling-off period (7 days) — name cannot be registered by anyone. | | Day 22+ | Name becomes available for registration again. | You can only renew during the 15-day grace period. Once day 15 passes, the domain is deleted and cannot be renewed. ## Deleting domains If you no longer need a domain, delete it from the **Danger Zone**. 1. Scroll to the **Danger Zone** at the bottom of the domain page. 2. Click **Delete Domain**. 3. Confirm. DNS records are removed immediately. Your domain stops working right away. ### Cooling-off period After deletion: * A 7-day cooling-off period begins immediately. * The name cannot be registered by you or anyone else during this time. * Deletion is permanent — domains cannot be restored. Once you delete a domain, it enters a 7-day cooling-off period. After 7 days, the name becomes available for anyone to register. Restoration is not possible. ## Domain status reference | Status | Meaning | | -------------------- | -------------------------------------------------------- | | **Active** | Working normally. | | **Expiring Soon** | Less than 60 days until expiry. | | **Expired** | Past expiry but in the 15-day grace period. | | **Pending Deletion** | Scheduled for deletion. | | **Deleted** | Removed from DNS (cooling off for 7 days). | | **Pending DNS** | Waiting for DNS records to be created (automatic retry). | ## Activity history Every change to your domains is recorded: 1. Click **History** in the sidebar. 2. Review the full audit log: registrations, nameserver updates, renewals, deletions, and login events. ## Domain limits and quotas ### Default limits * **Names per account:** up to 4 — one of each namespace (`indevs.in`, `sryze.cc`, `ryzedns.org`, `nx.kg`). * **Domain length:** 3–63 characters * **Nameservers required:** at least 2 * **Renewal window:** 60 days before expiry * **Grace period:** 15 days after expiry * **Cooling-off period:** 7 days after deletion ### Need more domains? Email [support@stackryze.com](mailto:support@stackryze.com) with: * Your GitHub username. * The reason for the increase. * How many domains you need. We reply within 1–2 business days. ## Public-suffix behavior Every registered Stackryze Domain is submitted to the **Public Suffix List** (PSL), the same list browsers, certificate authorities, and password managers consult to decide where one registrable name ends and the next begins. Once a name is on the list, the boundary is enforced by the consumers — not by Stackryze. What that gives you in practice: * **Browsers scope cookies correctly.** Chrome, Firefox, Safari, and their derivatives treat `yourname.indevs.in` the same way they treat `example.com` — cookies set on the registered label don't leak to sibling names under `indevs.in`. * **Cross-origin isolation holds.** A page on `app.yourname.indevs.in` cannot read cookies or storage set by a sibling name unless that sibling explicitly opts in. The same boundary exists between any two Stackryze Domains. * **Certificate authorities are strict.** When you request a TLS cert for `yourname.indevs.in`, the CA verifies you control the registered label — exactly as they do for `yourname.example.com`. A malicious party cannot register a sibling prefix and trick the CA into issuing them a cert that overlaps yours. * **Password managers segregate credentials.** 1Password, Bitwarden, Chrome's password store, and others treat each registered Stackryze Domain as its own origin for credential scoping. You don't have to do anything special to benefit from this — it follows from your name being on the PSL, and PSL-aware tools already respect the boundary by default. Stackryze submits each registered name to the PSL; it is the PSL consumers (browsers, CAs, password managers) that enforce the boundary. Mainstream browsers, certificate authorities, and password managers all consult the PSL. ## Common issues ### Nameservers not updating 1. Wait 5–10 minutes for propagation. 2. Clear your DNS cache (`sudo dscacheutil -flushcache` on macOS, `ipconfig /flushdns` on Windows). 3. Confirm the nameservers are correct in the dashboard. 4. Check [DNS Checker](https://dnschecker.org/). ### Domain not resolving 1. Verify nameservers in the dashboard. 2. Check DNS records in your DNS provider. 3. Confirm the zone is configured for your subdomain. 4. Wait up to 48 hours for global propagation. ### Can't renew * Renewal opens 60 days before expiry. * Check the expiry date on the domain. * If expired, confirm it is still within the 15-day grace period. ### Accidentally deleted 1. Wait for the 7-day cooling-off period to complete. 2. Re-register the domain once available. 3. Deletions are permanent — support cannot restore. Set a calendar reminder for 60 days before expiry. We also email you at 60 and 10 days out. ## Best practices ### Maintenance * Review your domains monthly. * Set calendar reminders for renewals. * Keep your account email current. * Watch activity history for unexpected changes. ### DNS configuration * Pick a reliable DNS provider. [Cloudflare](/docs/guides/domains/dns-providers/cloudflare) is a good default. * Configure proper DNS records (A, CNAME, MX, TXT). * Test your domain after every change. * Keep a backup of your nameservers. ### Security * Enable two-factor authentication on GitHub. * Review activity history regularly. * Never share account credentials. * Report suspicious activity to [security@stackryze.com](mailto:security@stackryze.com). ## Need help? * [Troubleshooting](/docs/guides/domains/troubleshooting) * [Getting started](/docs/guides/domains/getting-started) * [DNS providers](/docs/guides/domains/dns-providers) * [Discord Community](https://discord.gg/wr7s97cfM7) * [Email Support](mailto:support@stackryze.com) * [GitHub Issues](https://github.com/stackryze/domains-docs/issues) # Troubleshooting Source: https://docs.stackryze.com/docs/guides/domains/troubleshooting Common errors and how to fix them on Stackryze Domains. Common problems and their solutions. Stackryze Domains is currently in beta and updated daily. If you spot an issue, let us know via the support channels at the bottom of this page. ## Login issues ### "GitHub account too new" **Error:** Your GitHub account must be at least 7 days old. **Fix:** * Wait until your GitHub account is 7 days old. * This is a spam-prevention measure. * Email [support@stackryze.com](mailto:support@stackryze.com) if you believe this is an error. ### "No public email on GitHub" **Error:** Your GitHub account does not have a public email address. **Fix:** 1. Go to [GitHub Settings → Emails](https://github.com/settings/emails). 2. Uncheck **Keep my email addresses private**, or add a public email. 3. Try logging in again. ### "Account banned" **Error:** Your account has been banned for violating the terms of service. **Fix:** * Review the [Terms of Service](https://domain.stackryze.com/terms). * Email [support@stackryze.com](mailto:support@stackryze.com) if you think this is a mistake. Include your GitHub username. * Banned accounts are signed out on all devices immediately. ### "Registration closed" **Error:** New registrations are temporarily disabled. **Fix:** * This is rare and usually temporary. * Check the status page for updates. * Try again later or contact support. ### "Login failed / Server error" **Error:** Generic login failure. **Fix:** * Clear browser cookies and cache. * Try a different browser. * Disable browser extensions temporarily. * Check whether GitHub is down: [GitHub Status](https://www.githubstatus.com/). * Email [support@stackryze.com](mailto:support@stackryze.com) if the issue persists. ## Domain registration issues ### "Domain name must be at least 3 characters" **Error:** Your subdomain is too short. **Fix:** * Use at least three characters. * Example: `abc.indevs.in` ✅, `ab.indevs.in` ❌. The same length bounds apply under every namespace. ### "Domain name must be less than 63 characters" **Error:** Your subdomain is too long. **Fix:** * Keep it under 63 characters. * Use a shorter, more memorable name. ### "Domain name can only contain lowercase letters, numbers, and hyphens" **Error:** Invalid characters in subdomain. **Fix:** * Use only `a-z`, `0-9`, and `-`. * No uppercase letters, spaces, or special characters. * Cannot start or end with a hyphen. **Examples:** * ✅ `my-project` * ✅ `api2024` * ❌ `My_Project` (uppercase, underscore) * ❌ `-myproject` (starts with a hyphen) * ❌ `my project` (spaces) ### "Subdomain already exists" **Error:** Someone else has already registered this name. **Fix:** * Try a different name. * Add numbers or hyphens: `myproject2`, `my-project`. * Check availability first (green checkmark in the form). ### "This name is in a cooling-off period" **Error:** The domain was recently deleted and is in a 7-day waiting period. **Fix:** * Wait 7 days after deletion. * Choose a different name. * The error message shows how many days remain. ### "You have reached your domain limit" **Error:** You have registered the maximum number of domains (default: 5). **Fix:** * Delete unused domains from **My Domains**. * Email [support@stackryze.com](mailto:support@stackryze.com) to request an increase. Include your GitHub username and reason. ### "At least 2 nameservers are required" **Error:** You did not provide enough nameservers. **Fix:** * Enter at least two nameservers. * Most providers give you 2–4. ### "Invalid nameserver format" **Error:** Nameserver does not match a valid DNS hostname. **Fix:** * Use a valid hostname: `ns1.example.com`. * Do not include `http://`. * No spaces or special characters. * Maximum 253 characters per nameserver. **Valid formats:** * ✅ `ns1.cloudflare.com` * ✅ `ns-123.awsdns-12.com` * ❌ `http://ns1.example.com` (no protocol) * ❌ `ns1 example com` (no spaces) ### "Duplicate nameservers are not allowed" **Error:** You entered the same nameserver twice. **Fix:** * Use different nameservers. * Each must be unique. ### "CAPTCHA verification failed" **Error:** hCaptcha did not complete successfully. **Fix:** * Complete the CAPTCHA again. * Disable VPNs or proxies temporarily. * Try a different browser. * Disable ad blockers. * Check your internet connection. * Clear browser cache and cookies. ## DNS and nameserver issues ### Nameservers not updating **Problem:** DNS still points to old nameservers. **Fix:** 1. Wait 5–10 minutes for propagation. 2. Clear your DNS cache: * **Linux:** `sudo systemd-resolve --flush-caches` * **macOS:** `sudo dscacheutil -flushcache` * **Windows:** `ipconfig /flushdns` 3. Check with multiple DNS checkers: * [DNS Checker](https://dnschecker.org/) * [What's My DNS](https://www.whatsmydns.net/) 4. Verify nameservers in the dashboard. ### Domain not resolving **Problem:** Domain doesn't load or returns DNS errors. **Fix:** 1. Verify nameservers in the dashboard. 2. Check DNS records in your DNS provider. 3. Confirm the zone is configured for your subdomain. 4. Wait up to 48 hours for global propagation. 5. Test with: `dig yourname.indevs.in` or `nslookup yourname.indevs.in`. ### SSL/HTTPS not working **Problem:** Browser shows "Not Secure" or SSL errors. **Fix:** 1. Configure SSL in your DNS provider (for example Cloudflare). 2. Wait up to 24 hours for the certificate to provision. 3. Confirm your origin server supports HTTPS. 4. Check SSL mode settings in your provider. 5. Verify DNS records point to the correct server. ## Domain management issues ### Can't renew **Problem:** The **Renew** button is disabled. **Fix:** * Renewal opens 60 days before expiry. * Check the expiry date on the domain. * If expired, confirm it is still in the 15-day grace period. * Email [support@stackryze.com](mailto:support@stackryze.com) if you need help. ### Accidentally deleted **Problem:** Deleted a domain by mistake. **Fix:** 1. Deletion is permanent and cannot be undone. 2. Wait for the 7-day cooling-off period. 3. After 7 days, the name becomes available again. 4. Re-register the domain. Support cannot restore deleted domains. Be careful in the Danger Zone. ### Status shows "Expired" but I renewed **Problem:** Status is not updating after renewal. **Fix:** * Refresh the page (`Ctrl+F5` or `Cmd+Shift+R`). * Clear browser cache. * Sign out and sign back in. * Wait a few minutes for the database to update. * Email support if the issue persists. ## General issues ### Dashboard not loading **Problem:** Can't open the dashboard. **Fix:** 1. Check your internet connection. 2. Try a different browser. 3. Clear browser cache and cookies. 4. Disable browser extensions. 5. Check [status.stackryze.com](https://status.stackryze.com/). ### Session expired / logged out automatically **Problem:** Repeated logouts. **Fix:** 1. Enable cookies in your browser. 2. Avoid private or incognito mode. 3. Allow third-party cookies. 4. Try a different browser. 5. Clear cookies and sign in again. ### Changes not saving **Problem:** Updates to nameservers or settings do not save. **Fix:** 1. Read the on-screen error message. 2. Confirm all required fields are filled. 3. Verify the nameserver format. 4. Try again in a few minutes. 5. Clear browser cache and retry. 6. Email support with details of what you tried. ### "Too many requests" / rate limit errors **Error:** You exceeded the rate limit for an action. **Rate limits:** | Action | Limit | | ------------------- | --------------------------- | | Authentication | 15 attempts per 15 minutes | | Domain creation | 2 domains per hour | | Availability checks | 20 per minute | | General API | 100 requests per 15 minutes | | Session checks | 100 requests per 15 minutes | **Fix:** 1. Wait for the time window shown in the error. 2. Slow your request rate. 3. Don't refresh repeatedly. 4. Don't use automated scripts or bots. Rate limits are per IP address and reset automatically after the time window. ## Monitoring issues ### Uptime Kuma / monitor shows "Offline" **Problem:** Your site works, but a monitoring tool reports it as **Down** (403 Forbidden or 503 Service Unavailable). **Cause:** Cloudflare's Under Attack Mode or JavaScript Challenge blocks automated bots, including monitoring tools. **Fix:** Create a WAF exception rule for your monitor. 1. Go to **Cloudflare Dashboard** → **Security** → **WAF**. 2. Click **Create rule** under Custom Rules. 3. Set the following: * **Rule name:** `Allow Monitoring` * **Field:** `User Agent` * **Operator:** `contains` * **Value:** `Uptime-Kuma` (or your monitor's name) * **Action:** `Skip` * **Checkbox:** Select **All remaining custom rules** and **WAF Managed Rules**. 4. Click **Deploy**. ## Still need help? If your issue isn't listed here or the fix didn't work: Fastest way to get help — live debugging with the community. Include your GitHub username, describe the issue, attach screenshots, and list what you tried. For technical bugs — check existing issues first. Step-by-step guides for every common task. **Response time:** We typically reply within 24–48 hours on business days. # Dynamic DNS Source: https://docs.stackryze.com/docs/guides/dynamic-dns Keep a hostname pointed at a changing IP — for homes, VPSes, and game servers. Dynamic DNS (DDNS) keeps a hostname pointed at an IP address that changes. It's perfect for home servers, game servers, surveillance cameras, and anything behind residential internet. ## How it works 1. Your device periodically tells Stackryze its current public IP 2. Stackryze updates the matching `A` / `AAAA` record 3. The world keeps resolving your hostname to the live IP ## Set up dynamic DNS Open Settings → API → **Create token** with the `ddns:write` scope. In the zone where you want DDNS, create an `A` record with the placeholder value `0.0.0.0`. Stackryze will treat it as a DDNS target. The DDNS endpoint is simple: ```bash theme={null} curl https://ddns.stackryze.com/update \ -d "host=home.example.com" \ -d "token=$STACKRYZE_DDNS_TOKEN" ``` Stackryze auto-detects your public IP from the request source if you don't supply one. ## Compatibility The Stackryze DDNS endpoint speaks the de-facto `nic/update` protocol, so the same clients that work with dyndns.org, no-ip.com, and afraid.org work with Stackryze: | Client | URL | | ------------ | --------------------------------------------------------- | | **ddclient** | `protocol=dyndns2 server=ddns.stackryze.com` | | **inadyn** | `--provider dyndns2@ddns.stackryze.com` | | **ddns-go** | Custom provider, URL: `https://ddns.stackryze.com/update` | ## IPv6 Stackryze DDNS supports IPv6 out of the box. Send the `ipv6` parameter: ```bash theme={null} curl https://ddns.stackryze.com/update \ -d "host=home.example.com" \ -d "ipv6=2001:db8::1" \ -d "token=$STACKRYZE_DDNS_TOKEN" ``` # Enable DNSSEC Source: https://docs.stackryze.com/docs/guides/enable-dnssec Cryptographically verify your zone in three steps. DNSSEC lets resolvers verify that answers really came from your zone — defeating the kind of cache poisoning that took down whole registrars in 2024. Stackryze supports it on every zone. ## Prerequisites * A verified Stackryze account (see [Account Verification](/docs/account-verification)) * A domain delegated to Stackryze nameservers ## Steps Open the zone in the dashboard and navigate to **Settings → DNSSEC**. Click **Enable**. Stackryze generates an ECDSA P-256 keypair, signs the zone, and computes a `DS` record. Copy the `DS` record we generate and paste it at your registrar. Example: ```text theme={null} example.com. 3600 IN DS 35221 2 1 ABC123... ``` The exact UI depends on your registrar — most have a "DNSSEC" or "DS records" panel. Run: ```bash theme={null} delv example.com +root ``` You should see `; fully validated`. ## Algorithm support | Algorithm | Supported | | -------------------------- | -------------- | | ECDSA P-256 + SHA-256 (13) | ✅ default | | ECDSA P-384 + SHA-384 (14) | ✅ | | Ed25519 (15) | ✅ | | Ed448 (16) | ✅ | | RSA-SHA256 (8) | ⚠️ legacy only | | RSA-SHA1 (5) | ❌ removed | ## NSEC3 We sign zones with NSEC3 by default to prevent zone-walking. Disable NSEC3 from **Settings → DNSSEC → NSEC mode** if you need NSEC (rare). DNSSEC + DANE + a `CAA` record is the strongest setup possible for a public-facing zone. # FAQ Source: https://docs.stackryze.com/docs/guides/hosting/faq Common questions about Stackryze Hosting — the upcoming application hosting product. Stackryze Hosting is in planning. The answers below describe the product as it is being designed and may evolve before launch. ## When does Hosting launch? Targeting the second half of 2026. The closed beta begins before then — sign up at [hosting.stackryze.com](https://hosting.stackryze.com) to be notified. ## Will Hosting be free? Yes. A usable free tier is part of the design, mirroring the rest of the Stackryze surface. ## How does Hosting relate to Stackryze DNS? Every hosted project gets a Stackryze DNS zone pre-wired. Custom domains, ACME automation, and DNSSEC are first-class on day one. ## Can I bring my own runtime? Yes — bring a container image. The runtime is open source and the build pipeline is documented. ## What won't Hosting be? Not a hyperscaler competitor, not a lock-in platform, not a third-party add-on marketplace. See the [Hosting introduction](/docs/hosting). # Connect a Git repository Source: https://docs.stackryze.com/docs/guides/hosting/getting-started Push to deploy from any Git host — planned for Stackryze Hosting. Stackryze Hosting is in planning. This guide documents the intended workflow and will be filled in once the product launches. When Hosting ships, you will connect a Git repository in three steps: ## Steps Sign in to [hosting.stackryze.com](https://hosting.stackryze.com) and click **Connect Repository**. Choose your host and grant read access. Select the repo and the branch Stackryze should build from. The default branch builds to production. Stackryze performs a starter build to verify access and stores an initial deploy. The branch URL is your project's primary URL. ## What you get * **Preview environments** for every pull request. * **Automatic HTTPS** via Stackryze DNS ACME integration. * **Build logs** streamed in real time, retained for 30 days. ## What this depends on * [Stackryze DNS](/docs/dns) — every hosted project ships with a Stackryze DNS zone, pre-wired. * [Account verification](/docs/account-verification) — required to create production deploys. # Introduction Source: https://docs.stackryze.com/docs/guides/hosting/index Preview guides for Stackryze Hosting — application hosting with the same Stackryze guarantees, currently in planning. Stackryze Hosting is in planning. The guides below document the shape of the product so you can prepare for launch. None of these are usable yet — pages, dashboards, and the platform itself don't exist. When Stackryze Hosting launches, every guide here will be filled out in detail. For now, each page describes the intent of the workflow and the Stackryze DNS feature it depends on. ## Getting started Push to deploy from any Git host (planned). From zero to a running container in five minutes (planned). Bring your own domain or use a free Stackryze Domain. ## Day-to-day operations Per-environment secrets with audit logs (planned). Spin up a per-PR URL that destroys on merge (planned). Revert to any prior deploy with one click (planned). ## Pricing Pricing for Hosting will be announced at launch. As with every Stackryze product, a usable free tier is part of the plan. # Provision your first project Source: https://docs.stackryze.com/docs/guides/hosting/manage-projects From zero to a running container in five minutes — planned for Stackryze Hosting. Stackryze Hosting is in planning. This guide documents the intended workflow and will be filled in once the product launches. When Hosting ships, provisioning a project will follow the same shape as the other Stackryze products: one dashboard, one place to do everything. ## Steps Open [hosting.stackryze.com](https://hosting.stackryze.com) and sign in. Click **New Project**, pick a name, and choose a region. Stackryze provisions a fresh container and a paired Stackryze DNS zone. Push to the connected Git branch or upload a container image. Stackryze builds, signs, and rolls out. Your project is reachable at `.stackryze.run`. Bring your own domain later via [Custom domain](/docs/guides/add-a-custom-domain). ## Pricing | Plan | CPU | RAM | Outbound | Custom domains | | ----- | ------------ | ------------ | ------------- | -------------- | | Free | Shared | 256 MB | 100 GB/month | Yes | | Pro | 1 vCPU | 1 GB | 1 TB/month | Yes | | Scale | Configurable | Configurable | Pay-as-you-go | Yes | Final pricing will be announced at launch. # Point Domain to Stackryze Source: https://docs.stackryze.com/docs/guides/point-domain-to-stackryze Three ways to point an existing domain at a Stackryze-hosted service. There are three ways to point a domain you own at a Stackryze service. This page picks the right one for you. ## Option A — Full delegation (recommended) Delegate the entire zone to Stackryze's nameservers. We host every record type and you manage everything from one dashboard. * **Best for:** most users, full feature set (DNSSEC, modern records, API). * **Trade-off:** you can no longer use your registrar's DNS UI. * **Steps:** see [Add a custom domain](/docs/guides/add-a-custom-domain). ## Option B — Subdomain only (CNAME) Keep the apex at your registrar and point a single subdomain (`app.example.com`) at Stackryze via a `CNAME`. ```dns theme={null} app.example.com. 300 IN CNAME edge.stackryze.net. ``` * **Best for:** only one service needs Stackryze, or you want to keep your registrar's DNS UI for everything else. * **Trade-off:** DNSSEC signing has to happen at your registrar. ## Option C — A-record forwarding Point an `A` record at one of Stackryze's anycast IPs. ```dns theme={null} app.example.com. 300 IN A 192.0.2.10 ``` * **Best for:** static frontends, single-service domains. * **Trade-off:** you manage the IP rotation if we change infrastructure. Pros: full feature set, DNSSEC, modern record types, audit log, API. Cons: leaves your registrar's DNS UI. Pros: surgical, keeps your registrar's DNS UI as source of truth. Cons: no DNSSEC for the subdomain. Pros: works anywhere, no registrar cooperation needed. Cons: you own IP maintenance. Not sure? Start with **full delegation** — it's reversible in two clicks from your registrar, and unlocks every Stackryze feature. # Introduction Source: https://docs.stackryze.com/docs/index Welcome to Stackryze — affordable software for the modern web. Stackryze is a software company on a mission to ship infrastructure people can actually trust — starting with domains and DNS, free for everyone while we build the next wave of products. Whether you're a founder, freelancer, small team, or just curious, this is the place to get reliable infrastructure without enterprise pricing or vendor lock-in. Looking for the products themselves? Stackryze **DNS** is live at [dns.stackryze.com](https://dns.stackryze.com) and Stackryze **Domains** is live at [domain.stackryze.com](https://domain.stackryze.com). ## What's inside Get from zero to a working DNS zone in under five minutes. Free subdomains for founders, freelancers, and small teams. Step-by-step recipes for the most common setup paths. Every release, every fix, every minor improvement. ## Why Stackryze? * **Trustworthy** — software that does what it says, every time. * **Affordable** — fair and upfront pricing, never a surprise. * **Independent** — no investors to please, no lock-in to push. * **Open by default** — free tiers, public roadmaps, transparent decisions. > A domain you can trust. A DNS zone you can debug. No surprises. # Quickstart Source: https://docs.stackryze.com/docs/quickstart Get from zero to a working DNS zone in under five minutes. This quickstart takes you from a fresh Stackryze account to a fully delegated domain with live DNS records. Most people finish in under five minutes. ## Prerequisites Before you begin, you must have: * A free [Stackryze](https://dns.stackryze.com/signup) account * A domain you own (or one of the free subdomains Stackryze Domains provides) * Five minutes ## Get started Sign up at [dns.stackryze.com](https://dns.stackryze.com/signup). You can use email or your existing GitHub account. From the dashboard, click **Add Domain**, then enter the apex (for example `example.com`). Stackryze will create an empty zone and give you the nameservers to delegate to. At your domain registrar, set the nameservers to the four Stackryze nameservers we provide: ```text theme={null} ns1.stackryze.com ns2.stackryze.com ns3.stackryze.com ns4.stackryze.com ``` Propagation typically completes within 30 minutes. Open the zone and add the records you need — `A`, `AAAA`, `CNAME`, `MX`, `TXT`, plus modern record types like `SVCB`, `HTTPS`, and `TLSA`. Save your records as a draft first — Stackryze validates the whole zone before publishing so syntax mistakes never go live. Run `dig example.com @ns1.stackryze.com` (or use the built-in lookup from the dashboard) to confirm the zone is live. ## Where to go next Wire up a domain you already own to a Stackryze-hosted service. The complete reference for every record type Stackryze supports. Turn on cryptographic validation for your zone. Need help? Reach out to us at [support@stackryze.com](mailto:support@stackryze.com) — a real person will reply within one business day.