PowerDNS underneath
Standard zone transfers, dynamic updates and the PowerDNS API work as documented. Bring the automation you already trust.
Authoritative DNS for operators
PTRDNS is managed authoritative DNS built on PowerDNS. Run primary or secondary zones, enable DNSSEC, use ALIAS records and update zones dynamically. The service runs across a redundant network in Europe and North America and supports the PowerDNS API.
No commitment required. Monthly plans start at €5.
Why PTRDNS
PTRDNS runs PowerDNS, not a proprietary DNS engine. Your existing tools, APIs and protocols keep working, and your zones remain portable if you ever move providers.
Standard zone transfers, dynamic updates and the PowerDNS API work as documented. Bring the automation you already trust.
Nameservers run on independent networks in different regions, TLDs (.net, .org, .eu) and registrars. A problem in one place does not take down the whole service.
Use Terraform, OctoDNS, acme.sh or nsupdate (RFC 2136). There is also a
web editor if you'd rather manage zones by hand.
Who it's for
If you care about open standards, interoperability and automation, PTRDNS gives you authoritative DNS without locking your zones into a provider-specific setup.
Features
All common record types supported (A, AAAA, TXT, MX and CNAME), along with ALIAS, HTTPS and TLSA. Wildcards are supported, and TTLs can be as low as 30 seconds.
Sign your zones so resolvers can verify that responses are authentic. Turn on DNSSEC with one click.
Serve zones that originate elsewhere. If your other provider has a problem, PTRDNS can keep answering for the zone.
Update records with standard DNS update tools such as nsupdate. Secure updates
with TSIG keys.
Automate changes across your zones through the PowerDNS API. Existing acme.sh, Terraform and OctoDNS integrations need no provider-specific rewrite.
Send and receive zones with any provider that supports standard AXFR transfers. Use TSIG keys when transfers need authentication.
Point an apex domain such as example.com to an external hostname.
Use cases
Keep the master server private. PTRDNS serves the public nameservers and receives the zone over authenticated AXFR.
Handle DNS-01 challenges from Certbot, acme.sh or lego. Add the required TXT record
through the API or with nsupdate, then let the ACME client finish.
Keep zone definitions in source control and apply record changes through the PowerDNS provider and API.
Keep one source of truth for your records and synchronize them to PTRDNS and other providers.
Connect existing PowerDNS tooling and scripts. The supported endpoints cover zones, cryptokeys, TSIG keys, notify, export and AXFR retrieval.
Run PTRDNS alongside another DNS provider and synchronize the zones with standard zone transfers. Either provider can continue serving if the other has an outage.
At a glance
Pricing
Try any plan for 14 days. Pay monthly with no commitment, or save by paying yearly.
€5 /month
For a few personal domains or a small DNS setup.
€20 /month
For several zones and more traffic.
€50 /month
For busy domains with hundreds of millions of queries.
FAQ
Sign in to your registrar's control panel and set the nameservers to the ones listed on your zone's page. You can delegate to PTRDNS only, or to PTRDNS together with another provider when a zone transfer (AXFR) is configured between them.
Yes. It works with native, primary and secondary zones, and you can enable it with one click.
Yes. ALIAS records point an apex domain at an external hostname. They are similar to CNAME records, but can be used at the zone apex.
Add a TSIG key to both your primary nameserver and PTRDNS, then configure PTRDNS to
accept transfers with that key. Configure your primary to send NOTIFY to
intake.ns.ptrdns.net and to accept AXFR authenticated with the TSIG key.
Create a TSIG key and attach it to the zone you want to update. Configure an RFC
2136-compatible client, such as nsupdate, with that key and send record
updates to intake.ns.ptrdns.net.
Yes. PTRDNS implements the zone, cryptokey and TSIG key endpoints, as well as export, notify and AXFR retrieval. Existing PowerDNS tooling should work with none or minimal changes.
Yes. All nameservers are DDoS-protected. Accounts also include query quotas sized to handle peak usage.
Yes. Yearly plans cost less than paying month to month. Select “Yearly” above to compare the rates.
Start a 14-day trial. Use open standards, keep your existing tools and add redundancy as your setup grows.