this post was submitted on 14 Jan 2026
36 points (100.0% liked)

Selfhosted

54680 readers
754 users here now

A place to share alternatives to popular online services that can be self-hosted without giving up privacy or locking you into a service you don't control.

Rules:

  1. Be civil: we're here to support and learn from one another. Insults won't be tolerated. Flame wars are frowned upon.

  2. No spam posting.

  3. Posts have to be centered around self-hosting. There are other communities for discussing hardware or home computing. If it's not obvious why your post topic revolves around selfhosting, please include details to make it clear.

  4. Don't duplicate the full text of your blog or github here. Just post the link for folks to click.

  5. Submission headline should match the article title (don’t cherry-pick information from the title to fit your agenda).

  6. No trolling.

  7. No low-effort posts. This is subjective and will largely be determined by the community member reports.

Resources:

Any issues on the community? Report it using the report flag.

Questions? DM the mods!

founded 2 years ago
MODERATORS
 

Hi!

Maybe someone can help me with a problem I’m having, vaguely related to self hosting.

I want to use a domain with let’s encrypt certificates locally. I realise the only way to do this is a (automated) DNS-01 challenge if I don’t want to expose anything to the outside.

Those DNS challenges require my name server to have some kind of API to automate the process. My registrar/name server doesn’t have a API unfortunately.

I want to use the opportunity to switch my registrar and name server in one go, but I’m pretty picky…

My wish list is:

  • MFA for general account administration
  • scoped tokens or account for API access (don’t need or want to manage everything by API)
  • can handle .at domains
  • not cloudflare
  • registrar and name server should be one entity if possible
  • european if possible
  • supported by ngnix proxy manager if possible

Backup plan would be picking a registrar which supports DNSSEC for .at domains and use desec.io I guess.

But maybe the hive mind has a good recommendation for me? :)

Thank you in advance for reading! I’m aware I’m just a bit extra, but i want to be able to just ignore the whole name server and domain topic for the next ten years again if I can.

Cheers!

top 22 comments
sorted by: hot top controversial new old
[–] DieserTypMatthias@lemmy.ml 2 points 3 days ago
[–] Dirk@lemmy.ml 14 points 5 days ago (1 children)

selfhost.eu offers dynamic DNS which works perfectly fine with my router, using their API access as documented by them. It also works perfectly well with Let’s Encrypt integrated in Nginx Proxy Manager.

  • can handle .at domains
  • is not Cloudflare
  • is registrar and name server
  • is European (Germany)
  • supports Nginx Proxy Manager

They’re in the market since 2001, I use them since ca. 2010 and never had any issues. Their website looks ancient, almost historic. But it’s functional.

[–] frongt@lemmy.zip 9 points 5 days ago

Your registrar should let you specify who is hosting the DNS records. Pick any host compatible with your client. Personally I use Namecheap and haven't had to touch it in years.

[–] slazer2au@lemmy.world 6 points 5 days ago* (last edited 5 days ago) (1 children)

https://www.mythic-beasts.com/ in the UK likely ticks almost all your boxes.

Personally I use Porkbun but they don't support .at domains by the look of it.

[–] AllNewTypeFace@leminal.space 2 points 5 days ago

I can vouch for Mythic Beasts

[–] Appoxo@lemmy.dbzer0.com 3 points 4 days ago* (last edited 3 days ago) (1 children)

Using INWX for my .de and ~~.com~~ .eu domain
Cloudflare as my DNS server.

Works great. And INWX is reasonable with their fees.

[–] Rizilia@lemmy.zip 3 points 4 days ago (1 children)

How do you handle WHOIS Privacy at INWX?

[–] Appoxo@lemmy.dbzer0.com 2 points 3 days ago

Personally: I don't.
But my domain also holds my real last name so privacy is kinda moot.

[–] mhzawadi@lemmy.horwood.cloud 4 points 5 days ago

OVH have both an API that use and will register a .at domain

[–] poVoq@slrpnk.net 4 points 5 days ago

Ovh should work.

[–] Esjott@feddit.org 3 points 5 days ago* (last edited 5 days ago) (1 children)

Not sure if https://www.inwx.de/en ticks all your boxes but it handles .at (Renewal: €15.47 / 1 Year) is located in the EU (Germany) and maybe worth a look. I have all my domains there, works flawlessly.

[–] Rizilia@lemmy.zip 3 points 4 days ago (1 children)

How are you handling the WHOIS entries ant INWX? Are you paying for the privacy extension? I am looking for another registrar EU based who offers some sort of free whois privacy or respecting the GDPR and not publishing my data online.

[–] Esjott@feddit.org 1 points 3 days ago

No I don’t pay extra for the privacy stuff, I think 🤔

[–] mbirth@lemmy.ml 2 points 5 days ago

INWX seems to offer .at Domains as well as an API.

[–] fatcat@discuss.tchncs.de 1 points 4 days ago

Thank you all so much for your answers, I have a few more options to go through now!

[–] talkingpumpkin@lemmy.world 2 points 5 days ago (1 children)

I moved to infomaniak because registering domains come with a free mailbox (or at least they used to - IDK if it's still like this).

It works fine with lego (as should any other supported one).

[–] dieTasse@feddit.org 1 points 2 days ago (1 children)

Yeah, I tried infomaniak and they were doing kyc on me. I aint uploading my id to a domain company. Apparently they do this often (not always) and they can do it any time and take your access if you dont comply.

[–] talkingpumpkin@lemmy.world 1 points 1 day ago (1 children)

I don't remember them asking for any ID. Then again I gave them my real name/address and I payed with my credit card so... it's not like they can't confirm it's me.

[–] dieTasse@feddit.org 2 points 1 day ago

I did the same. I was not hiding any details. After I asked them about it, they said that they have to do it by law. After I told them I won't give them my id they returned my money and that was that. I don't see why there has to be kyc on normal domain...

[–] antsu@discuss.tchncs.de 2 points 5 days ago

I don't have a registrar to recommend, but for the nameservers (which would already solve your problem) I had a good experience in the past with Hurricane Electric (dns.he.net). AFAIK the only requirement from your list it doesn't satisfy is being European (not 100% sure about MFA and scoped tokens).

[–] ikidd@lemmy.world 0 points 4 days ago

Create a cloud flare accounts and change the name servers at you current registrars to what cloudflare gives you when you try to migrate. Its best practice to split up registrar and DNS anyway. then create an API token so your reverse proxy can build records and certbot a new cert.