14 ms·
Free DDNS with Cloudflare and a cronjob
- deleted 2y ago[deleted]
- aesopsfable 2y agoIf you too are tired of relying on outdated software from paid services like NoIP and DynDNS, and are in need for a reliable way to manage your home server with your own domain name, try this simple script with a free Cloudflare account. It just gets the job done...
- netsharc 2y ago> restart cronjobs > > sudo systemctl restart cron Hello author, there's no need to restart cron, crontab -e applies changes automatically on exit. And the daemon is called "cron", not "cronjobs".
- aesopsfable 2y agoHello back! thanks I did not know crontab -e auto-restarted it. fixing it now. also 'cronjobs'.
- ocdtrekkie 2y agoThis is a pretty nice option for Cloudflare domains. An alternative I use is DomainConnect, which provides free DDNS but the main backer of it is GoDaddy so I had to leave the domain I use it with registered there.
- rahimnathwani 2y agoI would have thought that most people who need this today (e.g. those who were using Google Domains DDNS) already have ddclient installed. ddclient already works with Cloudflare: https://developers.cloudflare.com/dns/manage-dns-records/how-to/managing-dynamic-ip-addresses/ https://developers.cloudflare.com/dns/manage-dns-records/how...
- kissgyorgy 2y agoI built the exact same thing 5 years ago and I'm using it daily since then. I never have any problems with it. You don't need a config file for it, just a couple of CLI options and you are good to go. You can install it with pip, docker or downloading a binary: https://github.com/kissgyorgy/cloudflare-dyndns https://github.com/kissgyorgy/cloudflare-dyndns
- indigodaddy 2y agoYou’re the redbean-docker guy!
- AndreasBackx 2y agoI guess this is something people have to make? I wrote one 6 years ago in Golang and rewrote it in Rust last year. I have stopped using it, but I had them running for 6 years without issues. https://github.com/AndreasBackx/update-dns https://github.com/AndreasBackx/update-dns
- codetrotter 2y agoSeems to rely on https://api.ipify.org/ https://api.ipify.org/ to determine public IP. Is there any Cloudflare service one can use to determine the IP instead? That way there’s not an extra company in addition to Cloudflare itself that you need to continue existing.
- teamspirit 2y agohttps://www.cloudflare.com/cdn-cgi/trace https://www.cloudflare.com/cdn-cgi/trace will return your ip.
- mxuribe 2y agoThe (above) shared url leveraging the cloudflare.com domain name seems to show ip v6 address, while I've noticed that the following defaults to showing ip v4 address: https://1.1.1.1/cdn-cgi/trace https://1.1.1.1/cdn-cgi/trace Pick your poison as you wish - either is great! :-)
- codetrotter 2y agoI’d pick the one that supports IPv6 and then make two separate requests to it. One request over IPv4 and one over IPv6. curl -4 https://www.cloudflare.com/cdn-cgi/trace curl -6 https://www.cloudflare.com/cdn-cgi/trace Also the reason that the 1.1.1.1 one shows only IPv4 address is because 1.1.1.1 is itself an IPv4 address. So any connection to it will have to be using IPv4.
- tcfhgj 2y agocould you not retrieve your ipv6 directly from the system?
- codetrotter 2y agoYes, but getting it in a response from an external server means I don’t have to be specific about which interface to get the IPv6 address of and so on.
- hirako2000 2y agoNice idea, to note Cloudflare supports tunneling.
- thousand_nights 2y agoInstead of using DDNS, I have been using Cloudflare tunnels to expose my home services to the internet. The setup is much simpler and it seems like it's more secure too You specify a port and point it to a subdomain and it just immediately works, no maintenance necessary. The daemon only needs to be installed once with a simple terminal command
- noname120 2y agoThere are some limitations such as: – TLS termination mandatorily happens at Cloudflare (i.e. your traffic is mitm'ed). That's because this free product is meant as a gateway drug (aka a loss leader) to Cloudflare's WAF/Anti-DDOS products (which require TLS termination to happen on their side for technical reasons). – Other TCP protocols (including SSH) require every client to run the software too. So if you were thinking about bypassing the TLS termination restriction by creating a TCP tunnel instead of an HTTP(S) tunnel you can't. – Max 100 MB uploads for HTTP(S). – No media servers allowed. Otherwise it's a really good service!
- thousand_nights 2y agoSome good points, thanks. FWIW, I have been using it with Plex (just two users, me and my parents) and haven't gotten banned. The ToS are kind of unclear on whether this is allowed if I have to be honest.
- jsheard 2y agoVideo streaming in general is one of their red lines, you're not supposed to shove any kind of video through their CDN unless the origin is another Cloudflare product (e.g. CF Stream or R2).
- thousand_nights 2y agoFrom the discussions I've read, it's not as clear cut, e.g.: https://old.reddit.com/r/PleX/comments/152wfdh/can_i_use_a_cloudflare_tunnel_to_make_my_plex/ https://old.reddit.com/r/PleX/comments/152wfdh/can_i_use_a_c...
- turdistheword 2y ago[dead]
- briHass 2y agoIt's better to do a script on your router, which knows exactly when the ISP's DHCP changes. Mikrotik has an event to capture this, and *sense has built in scripts for various DDNS providers.
- tssva 2y agoI used ddclient with Cloudflare for years with no issues. Recently upgraded my home router and the manufacturer operates a free dynamic dns service enabled with a toggle button. I have a cname record in my domain’s dns records pointing to the dynamic dns entry. I actually don’t even need that anymore. All the services I run at home are only for immediate family so only available remotely via a Wireguard vpn connection. I migrated that to the router also because it can do 900Mbs of Wireguard traffic and has a great vpn server management implementation. By default the client configs it generates points to the dynamic dns name. No real need for the cname but I have it out of habit.
- kukkamario 2y agoMikrotik at least has that DDNS functionality. It is really nice feature.
- tssva 2y agoI didn’t need all the features or complexity of a Mikrotik router so I went simpler. I have a GL.iNet MT-6000. Underneath it runs openwrt and you can access the openwrt luci web interface or ssh to it if you want to do anything more complex than their web ui allows. So far besides enabling sftp so certbot can deploy a ssl cert to replace the default self-signed cert I haven’t needed to. It also runs AdGuard Home so that is another thing I have been able to remove from my home server.
- IgorPartola 2y agoSo does OPNsense. It’s such a joy to use that whole OS.
- sagz 2y agoWow! May I know the router model that does 900+mbps of Wireguard? The dedicated GLinet box I got for tailscale does only about 60-90mbps. Apple TV 4K does a paltry 20-40...
- tssva 2y agoThe GL.iNet MT-6000 Flint2. I have a site to site Wireguard VPN with my brother which I use for offsite backups. It saturates my 500Mbs internet connection when performing backups. I have seen YouTube videos of others successfully testing the 900Mbs throughput claim. I stopped using tailscale myself about a year ago so can’t comment on the performance with it. It uses a user space Wireguard implementation instead of the kernel one so that may impact performance.
- chickenballs 2y agoThis application would suit checking the external IP from multiple external sources before updating the Cloudflare API. Also, if running a home server you’d want that 5min wait time brought down to something like 1 minute.
- jms703 2y agoThere are a lot of these on github. This one seems to be maintained well: https://github.com/zebradil/cloudflare-dynamic-dns https://github.com/zebradil/cloudflare-dynamic-dns
- rogerpeters 2y agoI'm calling out the elephant in the room - you’re putting way too much faith in these IP lookup services without questioning their obvious ability to screw you over with giving the wrong IP. Is no-one in here able to see this is terrible security??
- eddd-ddde 2y agoIf you can't trust cloudflare to give you a correct IP how could you trust it as a name server?
- rogerpeters 2y agoThe script was not using Cloudlfare to grab the IP, it was using iptools website. Plus, it doesn’t even need to be malicious - it can simply hive you the wrong IP. I know this because I ran a script querying 40 different sites which provided the IP address, and I found at least 4 of them giving incorrect IP addresses over the course of 24 hours. This is why you shouldn’t trust any single source, but compare multiple different sources and THEN update cloudflare with the IP. You see?
- Snawoot 2y agoYou can achieve the same on virtually any DNS hosting with RGAP[1]. The trick is to delegate name of your interest to server which runs RGAP DNS server and let it respond to queries for such domain name. Bonus: you can have more than one address running RGAP-agent and exporting its address to DNS. [1]: https://github.com/SenseUnit/rgap https://github.com/SenseUnit/rgap
- trallnag 2y agoMy internet router (Fritzbox) has DDNS built-in, so I just use the domain provided by the Fritzbox / AVM combined with DNAME records.
- efortis 2y agoSince my IP hardly changes, I went from DDNS to an email notifying me when the IP changes with this cron: old_ip=`cat ~/.prev_ip` my_ip=`ifconfig em0 | awk '/inet/ {print $2}' 2>&1` my_email=me@example.com if [ "$my_ip" != "$old_ip" ]; then echo $my_ip > ~/.prev_ip echo $my_ip | mail -r $my_email -s "New IP: $my_ip" $my_email fi
- matrix2003 2y agoI did something similar, but scripted a curl command to update the DNS A/AAAA records that have a short TTL to the hostname. It’s also trivial if you run your own nsd/bind instance.
- WarOnPrivacy 2y ago> Since my IP hardly changes... Same. Our wireline ISPs used to issue new public IPs every 1-12 weeks. Now it's more like 6 mos to never. I'm thinking this is due to pressure from IPv4 exhaustion and the rise of easy DDNS. There's also an overall shift - from using tech to protect profit-generating services to using lobbyists. To share an anecdote from the before times: I was once trying to setup a VPN endpoint on a client's DSL connection. Every time I initiated the connection, their public IP would change. The lease renewal was fairly quick and I could trigger 5 changes a minute.
- stkdump 2y agoFor me it changes reliably on every reconnect, but there are no forced reconnects, and I now have my router not restarting basically ever since I am on openwrt and am done with setting everything up.
- WarOnPrivacy 2y ago> For me it changes reliably on every reconnect, What kind of reconnect?
- tcfhgj 2y ago
- kurokawad 2y agoVery cool! For anyone interested in a bash script instead of installing a Python runtime, I made this tool some time ago for the same purpose: https://github.com/ddries/d2c.sh https://github.com/ddries/d2c.sh
- candiddevmike 2y agoIf only this didn't require an API token with write access to the entire domain. Please Cloudflare, let us grant access to specific (or regexp!) records
- vladvasiliu 2y agoLast I checked AWS has the same limitation. One workaround is creating a separate sub-zone and giving access only to that to whatever you need. But for a "cheap homelab" solution, that's gonna cost you a bit more per month.
- yuvadam 2y agoThis kind of script should ideally run on your main router, and openwrt already has support for Cloudflare DDNS [1] [1] - https://openwrt.org/packages/pkgdata/ddns-scripts-cloudflare https://openwrt.org/packages/pkgdata/ddns-scripts-cloudflare
- js2 2y agoIf for some reason your DDNS client supports dyndns but not Cloudflare (e.g. UniFi OS), you can use this Cloudflare Worker as an adapter: https://github.com/willswire/unifi-ddns https://github.com/willswire/unifi-ddns
- _0xdd 2y agoI did something similar with `curl` and `sh` about a year ago, when the version of `ddclient` on OpenBSD didn't properly support Cloudflare.
- ttul 2y agoI’ve been favoring Tailscale lately for establishing magical access to machines at home. Because it permits two-factor authentication based on Google and other systems, it seems more secure than just having things exposed via public IP. That being said I definitely appreciate that being really on the internet has its uses!
- pdntspa 2y agoNothing that afraid.org hasn't been doing for years at this point.... Which got me into a 4-year exploration of FreeBSD! I'm still a bit sad I had to replace it with Proxmox on Debian to get what I wanted.
- blfr 2y agoI wanted to do this a long time ago but I wouldn't trust my router with a Cloudflare API key. Paranoid or is there a way to limit that key to one domain or, even better, one DNS entry?
- nrabulinski 2y agoYes you can generate a key which, for example, only allows you to edit DNS of a specific domain
- eat_veggies 2y agoAs the other commenter says, you can get pretty granular with the permissions. If you want to go even further, you can build a Cloudflare Worker that performs exactly the request that you want to do, and nothing else. Then you can configure your router to hit that instead of the API directly.
- slt2021 2y agoyou can setup the job on your trusted machine behind the router, could be raspberry pi or your desktop
- kazinator 2y ago"Yeah, but"; do I want to be putting up impossible-to-solve captcha loops in people's faces? Can you do this in a way that people who know your domain can go directly to your actual IP address, rather than a Cloudfare proxy?
- aesopsfable 2y agoIf you set {proxied: false} - it'll resolve to your IP directly.
- arrty88 2y agoI did the same, with Linode dns and their api
- ahmetozer 2y ago[dead]
- KennyBlanken 2y agoWell, these days SDE means "don't bother properly engineering your software, just throw away the entire system environment and re-make it!" aka containers, so...
- clwg 2y agoA bit of a tangent, but something like PowerDNS authoritative server comes with an API[0] that can be leveraged for similar functionality to what Cloudflare provides. Decentralization of the internet has to start with Authoritative DNS. I know it's not free to host an authoritative server like this on a VPS, and there are DDoS considerations. But the flip side is that DNS is a metadata protocol and contains a wealth of information that anybody privacy focused should think twice about. It's also an incredibly powerful and important protocol to understand. [0] https://doc.powerdns.com/authoritative/http-api/index.html https://doc.powerdns.com/authoritative/http-api/index.html
- remram 2y agoIf you're privacy-focused, you should run your own recursive resolver. Running your own authoritative server doesn't help much with privacy if clients still go through centralized recursive resolvers to query your domain.
- clwg 2y agoYou should run both. Consider Cloudflare (and large scale infrastructure providers like TLD operators) point of view on the traffic: If your private resolver is using root hints, it's IP is now correlated with the lookup of that domain even if they don't proxy the website. That's you and your users, and they can do that at scale - So it's important to point queries for your assets directly to your authoritative servers or rewrite inline without ever querying a internet source. dnsdist[0] (also PowerDNS) allows you to load balance and apply rules across upstream resolvers which opens up allot of possibilities on the recursive side. Trusted resolvers with a healthy number of users originating iterative queries from non-descript and changing IP's is probably the best way to anonymize your recursive traffic. [0] https://dnsdist.org/ https://dnsdist.org/
- rglullis 2y ago66 comments and no mention of inadyn? https://github.com/troglobit/inadyn https://github.com/troglobit/inadyn
- dethos 2y agoSome time ago, I built a similar project: https://github.com/dethos/worker-ddns https://github.com/dethos/worker-ddns The main difference is that, for security reasons, it uses a "Cloudflare worker" to change the DNS record. > Since Cloudflare API Token permissions aren't granular enough to limit the token access to a single DNS record, we place a worker in front of it (this way the token with extra priviledges never leaves cloudflare's servers). It works very well, no complaints until now.
- politelemon 2y agoSimilar project which runs in Docker: https://github.com/favonia/cloudflare-ddns https://github.com/favonia/cloudflare-ddns It's cache friendly and respectful of rate limits
- theduality 2y agoI have been using this for a couple of years, ticking away on an RPi. Works perfectly.
- fastily 2y agoNice, there seem to be a lot of these! I personally use https://github.com/qdm12/ddns-updater https://github.com/qdm12/ddns-updater, it’s from the creator of gluetun
- gavinsyancey 2y agoThis is the script I use for this: https://github.com/g-rocket/cloudflare-ddns-updater https://github.com/g-rocket/cloudflare-ddns-updater
- BikiniPrince 2y agoA dhcp lease hook is also useful to keep up with changes instantly.
- ruskyhacker 2y agoI feel ripped off! (kidding, this is commonly "reinvented" by many. Here's my Cloudflare and Google DNS ones: https://github.com/zackoch/easy_cloudflare_dns_updater/tree/master https://github.com/zackoch/easy_cloudflare_dns_updater/tree/... https://github.com/zackoch/easy-dynamic-google-cloud-dns https://github.com/zackoch/easy-dynamic-google-cloud-dns
- wiradikusuma 2y agoFor those who depend on Cloudflare extensively and have some traffic, I have a question: I was researching whether it's worth it to switch my pet project to Cloudflare's various offerings (D2, Workers) instead of AWS/GCP, since Cloudflare has a very generous free tier. But from quick googling (I think it's Reddit), some people said Cloudflare uses bait-and-switch where at some point you will need certain features that are only available in enterprise plan or something, basically significant cost increase. Should I be concerned? EDIT: I want to make it clear that I'm talking about significant cost increase, something that will catch many people by surprise.
- eastdakota 2y agoFor standard, legal web traffic Cloudflare will always be free. If you’re using us for just that and anyone on our sales team ever pressures you to upgrade, email me because it’s an explicit violation of our policies. Sales people are humans, so sometimes they make mistakes, but I can set it straight. Here’s my email: matthewatcloudflaredotcom So what are the cases you may have read about. They fall into two big buckets: 1. Streaming Video A video stream is just a series of image files strung together. So some people have tried to use our free service to serve video. This causes two problems. First, a second of video is often as much as 10x the bandwidth as a typical web page load. We’ve done a lot to make bandwidth costs low, but it can add up fast. Second, the people who tend to do this sort of janky video streaming are often streaming pirated video content. When that happens and we don’t shut it down we get sued. That’s costly. We do offer a service to stream video. It’s creatively named Stream. It’s elegant and not janky and designed to be the least costly way to stream video content. It’s cheap but it’s not free. 2. Illegal Content The site that is in the link you referenced was serving a gambling site to a jurisdiction where gambling is illegal. The problem was, the jurisdiction retaliated by blocking their IPs. If that only blocked the one gambling site, that’s their problem. But we share IPs between customers on our low end plans. So if a customer does something illegal somewhere and it causes an IP to get blocked then it causes harm to a bunch of other customers. The solution is dedicated IP addresses. In a case like this we have a product called BYOIP (which is exactly what you think it is). It’s bespoke and expensive for us to maintain and customers who care about it tend to be customers who have budgets to pay for it, so it’s expensive. We could probably invest engineering resources to make it less bespoke, but there’s really not a ton of demand. This customer was doing something illegal somewhere according to some government. We said — no judgment — but you’re getting our IPs banned and causing harm to other customers and we can’t let that happen. We presented a solution (albeit an expensive one). They balked and wrote a blog post. And now people assume there’s a bait-and-switch sales strategy. There’s not. Turns out people who use our Free plan rarely turn into million dollar customers. And people who are million dollar customers don’t really even consider our Free plan. So the world generally sorts itself correctly. We get stymied by our policy of not talking about the details of customers without their permission, so it makes it hard to respond to blog posts like that one. But enough people have asked me about it and I’m tired enough about it that I’m going to make the decision to revise the policy: we won’t publicly disclose any details about a customer without their permission; but if you write a blog post complaining about us and leave out the salient details, then we’ll reserve the right to fill those details in. Anyway, in 99.99% of cases, and especially if you’re not janky streaming or doing something illegal, our Free plan will work great for you and you’ll never hear from anyone on our Sales team.
- ruskyhacker 2y agoWeird, this project is very similar to this one https://github.com/zackoch/easy_cloudflare_dns_updater/tree/master https://github.com/zackoch/easy_cloudflare_dns_updater/tree/... Did OP kang my project?
- aesopsfable 2y agoHaha, no, I didn’t! Honestly, I didn't put much thought into this project either. I needed it for myself to host a game we're developing (it’s 11GB per download) and was frustrated with the Noip client. I made this in about an hour and thought I’d share it too! Just seeing all the upvotes today :)
- joecool1029 2y agoI use cloudflare with ddclient for a raspberry pi weather station on t-mobile (a regular line, not TMHI). This allows ms to view it anywhere. It just sets the AAAA every 5 minutes via cloudflare's API and their CDN proxies it automatically for the ipv4 only clients. I leave the A record blank. EDIT: Has to he this way because ipv4 is behind CGNAT on their network where ipv6 is fully routed public addresses. The home internet product is setup differently and you can't host stuff on it.
- russfink 2y agoIt feels like this trick would violate the terms of service...? Caveat: I don't use Cloudflare.
- FriendlyMike 2y agoI used duckdns and have for years
- softfalcon 2y agoI wrote one of these in C# years ago after seeing my friend write one in GoLang even more years ago. GoLang: https://github.com/wyattjoh/cloudflare-ddns https://github.com/wyattjoh/cloudflare-ddns C#: https://github.com/nick-funk/dyn-dns https://github.com/nick-funk/dyn-dns Mine is more barebones since I threw it together quickly in an afternoon. I feel like many a HomeLab person fighting their ISP is taking advantage of this Cloudflare API trick
- max-ibel 2y agoDid anyone here here set up a good rsyslogd configuration where the receiving syslog collector limits incoming logs to only known ddns machines ? I think I may be able to stitch something together with periodically reconfigured packet filters, but I'd appreciate an existing solution. Bonus points if running on freebsd.
- djbusby 2y agoPut a filter on syslog-ng, IIRC that runs on the BSDs
- max-ibel 2y agoThat looks good. I'd probably prefer doing this at lower layers like pf, since I know how to reload those configs via cron, and since I want to avoid unwanted or malicious packets to even make it to the syslog code. I was just surprised to find no recipe online, it's apparently more of a niche case than I thought. Worth documenting, probably.
- alanfranz 2y agoPsa: https://freedns.afraid.org/ https://freedns.afraid.org/ still works and it’s free.
- shepherdjerred 2y agoI've used this project which provides a Docker container: https://github.com/timothymiller/cloudflare-ddns https://github.com/timothymiller/cloudflare-ddns
- blahyawnblah 2y agoI've using afraid.org for forever now. Works great
- tzury 2y agoNice. Consider adding fallback services to api.ipify.org, such as ifconfig.me or icanhazip.com
- Havoc 2y agoIf you’re behind a CGNAT then this won’t help you much. For many residential installs that is the case unfortunately
- riobard 2y agoThere's one gotcha tho. For Dynamic DNS you want minimal TTL, ideally less than 60 seconds, otherwise the DNS records will be cached and will not reflect the correct address during the short period of time window it changes. Dedicated DDNS services usually have very short TTL (some offering as low as 5 seconds IIRC), but free Cloudflare accounts have a minimal TTL of 300 seconds (5 minutes), coupled with the crontab running every 5 minutes, your endpoint could be out of contact for 10 minutes if everything aligns right.
- mclion 2y agoThen run the cron every minute. As you can see with his example, it doesn't even run every 5 mins. For unproxied records you can set the TTL to 1 minute as per their documentation.. And normally your IP would change only when reconnecting, so it's not a big deal...
- dilyevsky 2y agoAnother issue is a lot of ISPs will ignore your TTL and cache it for hours or more on their internal resolvers
- sfink 2y agoHuh, I ignored this article because it sounded like such a solved problem, but it stayed on the home page long enough that I thought I might be missing something. Not only was it exactly what I expected from the title, there were 3 obvious but unimportant flaws in the "Ubuntu/Debian" setup section: - a cron line that runs every 60 minutes is commented as running every 5 - unnecessary crond restart. Not just reload, which would already be redundant, but a full restart - unnecessarily restrictive heading. There's nothing specific to Ubuntu/Debian in those instructions I mean, it's a fine solution, like the 100s of others out there. I'm not trying to throw shade on the author; they've made something a little more flexible than most one-offs, without going overboard like the ones that handle dozens of different services. But... why the front page? Why the upvotes? Can't you kids just stay off of the damn lawn?!
- tobi_b 2y agoI created an account just to comment on this: I tell you something, you are "throwing shade" on the author - even if this is a "kid", were you born and immediately started to invent (insert complex tech) from scratch? This guy did a nice job and wanted to share his work with us and appearently many others appreciate it and thus it ended up on the front page. Comments which's only intention is to make some other's work smaller and seemingly "unworthy" are just sad and unnecessary.
- aesopsfable 2y agoHey Tobi, thank you! This is HN, so that is fully expected, but it’s all fun and good. I made this super quickly and just wanted to share in case anyone needed it. I only saw it today—reached the front page and got 444 stars! I’m as surprised as the shade guy :)
- Fatnino 2y agoNoip isn't free? I have 3 domains there for years and I haven't paid them once. Some time ago they started requiring that I mark the domains active each month. I wrote a script that intercepts that email and logs into their site to reup the domains. Recently that script broke and I haven't bothered to fix it because logging in once a month is a nothing burger.
- 1oooqooq 2y agodo they rate limit dns resolution and force you to enable JavaScript and click a captcha for the full cloudflare experience?
- fippi 2y agoI also wrote my own pseudo-DDNS recently! With inspiration from a couple of similar projects on github Mine is a golang executable that runs directly on my OpenWRT-based router on a 30 minute cron job. The beauty of running it on my router directly is that I can simply query the `eth0` interface for my public ip address - no need for a `curl` to determine my public IP. https://github.com/jackphilippi/r53-ddns https://github.com/jackphilippi/r53-ddns
- tracker1 2y agoDid a very similar script with Deno/TS with DigitalOcean's DNS. I also setup a couple domains on a small Linux instance to deliver IP address responses. In order to facilitate IP lookups. ipv4.bbs.land ipv6.bbs.land