Skip to content

Linked IP and DDNS

Plain DNS over IPv4 goes to shared anycast addresses and carries nothing that names your profile. opdns recognises it by the source address: if the query comes from a public IPv4 address linked to your profile, the profile applies. Everything else sent to those addresses is the public path: answered, unfiltered, not logged.

Use this only for devices or routers that cannot do encrypted DNS or IPv6.

  • IPv4 only, public unicast only. Private (192.168.x.x, 10.x.x.x), carrier-grade NAT (100.64.0.0/10) and reserved addresses are refused.
  • An address can be linked to one profile only. Linking an address that another profile holds fails with a conflict; nothing is moved silently.
  • Everyone behind that address shares the profile: housemates, guests, and, on carrier-grade NAT, possibly strangers. If your ISP puts you behind CGNAT, your router’s WAN address is not your public address and linking will not work reliably; use IPv6 or encrypted DNS.
  • No device names. All devices on the network appear without a name.
  1. From a device on the network, open the profile’s Setup page in the dashboard. Under Plain DNS over IPv4, it shows the address it sees you from.

  2. Click Link this network. The dashboard shows a DDNS URL for the link once; copy it now if your address can change.

    The Setup page's Plain DNS over IPv4 section: the resolver address, this network's address (private here, so it cannot be linked), one linked address with its DDNS URL and Unlink actions, and the Link an IPv4 address field.
  3. To link a network you are not on, type its address in Link an IPv4 address instead.

Home IPv4 addresses change. Each link has a secret DDNS URL; calling it from the network moves the link to the caller’s current IPv4 address.

https://ip.opdns.net/link/<ddns-token>

You can also create an empty slot with Create a DDNS link instead and let the first call fill it. Show or regenerate a link’s URL with the DDNS URL button; regenerating stops the old URL at once.

Terminal window
# every 5 minutes; -4 makes sure the call leaves over IPv4
*/5 * * * * curl -4 -fsS https://ip.opdns.net/link/<ddns-token> >/dev/null

The -4 matters on dual-stack networks: over IPv6 the update is refused (badip), since only IPv4 addresses can be linked.

Install ddns-scripts and add a custom service whose update URL is the DDNS URL; the router calls it whenever its WAN address changes. Force IPv4 (option use_ipv6 '0').

The DDNS host answers in plain text, like other dynamic-DNS services:

Answer Meaning
good <ip> the link now points at <ip>
nochg <ip> already <ip>, nothing changed
badip <ip> not a public IPv4 address (called over IPv6, or from a private network)
badauth unknown token (regenerated or unlinked)
conflict <ip> <ip> is linked to another profile; nothing changed
abuse rate limited; call less often

Keep the URL secret: anyone who has it can point your link at their own address and use your profile.