DDNS not working: what dynamic DNS can and cannot fix

Dynamic DNS gives a name to an address. It cannot create a public IPv4 or get you past CGNAT, so the name resolves and the port stays closed. GetAStatic gives you a fixed public IPv4 over WireGuard with the ports you choose, from $2/mo.

Not affiliated with DuckDNS, No-IP or Dynu. DuckDNS and No-IP behavior as described in their own FAQs, checked 2026-10-07.

Instant setup US-based IP

Updated

Facts

Does DDNS help? Does a router port forward work?

Dynamic public IPv4DDNS: yes, it follows each change · Router forwarding: yes
Static public IPv4DDNS: not needed, the IP stays put · Router forwarding: yes
Double NAT (router WAN IP is 10.x, 172.16.x to 172.31.x or 192.168.x)DDNS: yes, if it records the outer box's public IP · Router forwarding: only with bridge mode or a forward on both boxes
CGNAT (router WAN IP in 100.64.0.0/10)DDNS: no, the address it records is shared · Router forwarding: no
Updater runs on a PC with a VPN onDDNS: no, the name points at the VPN's exit address · Router forwarding: never reached through the name
The problem

What a DDNS service actually does

A DDNS service such as DuckDNS, No-IP or Dynu is two small parts: a DNS record (an A record such as myhome.duckdns.org) and an updater that tells the service which address to put in it. The updater runs on your router, a NAS or a PC. It either sends an address it reads locally, or sends nothing and lets the service use the address the request came from. DuckDNS works the second way when you leave its ip parameter blank.

That design works well on a line with a dynamic public IPv4. Your router holds the public address itself, the ISP changes it now and then, the updater reports the new one, and a connection to the name lands on your router. The port forward then passes it to your server. DDNS only solves the changing address. No-IP's own FAQ says it plainly: DDNS points your hostname at your current public IP, "but it does not automatically allow external access."

Behind CGNAT, the updater can only record one of two wrong addresses. If the service reads the address the request came from, it records the ISP's shared public address. Connections to it reach the ISP's NAT, which has no rule for your home and drops them. If your router sends its own WAN address, the name points at something in 100.64.0.0/10, which nobody on the internet can route to.

The core issue is layers. Each NAT layer needs its own rule for an unsolicited inbound connection. Your router's port forward is a rule on your layer. With CGNAT the outer layer belongs to the ISP, and no setting in your home reaches it.

Check

Find out why your DDNS name does not connect

You need three addresses: your router's WAN IP, your public IP, and the address your hostname resolves to.

  1. Find your router's WAN IPv4. Log in to the router (often 192.168.1.1 or 192.168.0.1) and open the status, Internet or WAN page. Use the WAN address, not the router's own LAN address such as 192.168.1.1.
  2. Find your public IPv4 as the internet sees it. Use the free CGNAT check or any what-is-my-IP site, with VPNs and iCloud Private Relay off.
  3. Look up your hostname. Run "nslookup myhome.duckdns.org" (your name) in a terminal on Windows, macOS or Linux and note the address it returns.
  4. Read the WAN address. 100.64.0.0/10 (100.64.0.0 to 100.127.255.255) is the shared address space of RFC 6598, used for CGNAT. 10.0.0.0/8, 172.16.0.0/12 and 192.168.0.0/16 are the private ranges of RFC 1918, so another NAT box sits in front of your router: an ISP gateway, a second router, or, on some mobile ISPs, CGNAT.
  5. If the WAN IP is public but differs from what-is-my-IP, do not call it CGNAT yet. A VPN on the test device, Private Relay, a router with a second Internet link, or a status page that has not refreshed can each cause it. Remove those and compare again.
  6. Compare the hostname with your public IP. If they differ, the updater is the problem: it has stopped, it sends the router's private or 100.64 WAN address, or it runs on a PC whose traffic leaves through a VPN. If all three addresses match, DDNS is doing its job and the block is elsewhere.

All three match: check the forward, the firewall and ISP port blocks. WAN IP in 100.64.0.0/10: no DDNS or router setting will help, and the fix is below.

Your own static IP over WireGuard. No VPS.

Dedicated IPv4 from $2/mo →
Why use GetAStatic?

What GetAStatic changes when DDNS cannot help

  • A public IPv4 that answers on the ports you open, behind CGNAT or double NAT
  • An address that never changes, so a DDNS name only needs setting once
  • No router port forward, no bridge mode, no call to your ISP
  • TCP and UDP ports you choose: 5 open ports on Plus, unlimited open ports on Pro and Ultra
How it works

Where a tunneled static IP fits

With CGNAT, you need a public address on a layer you control. GetAStatic gives your server or router a dedicated public IPv4 in Kansas City, Missouri or San Jose, California. The device connects out over WireGuard on UDP 1194 or 443, which CGNAT lets through like any outbound traffic. Connections to your IP on the ports you open in the dashboard come back down that tunnel. The dashboard rule does the job your router's forward cannot.

If the check showed double NAT and not CGNAT, try bridge mode on the ISP gateway first, so your router gets the public address. DDNS and a normal port forward then work, at no cost. Some ISPs also move a line off CGNAT on request.

Once the IP is fixed, the name only has to be set once. An updater on the device that runs the tunnel reports the dedicated IP, because all of that device's traffic leaves through the tunnel, so it does no harm. An updater on your router still reports the ISP address and will overwrite the record, so turn that one off. For the full case for replacing DDNS, see dynamic DNS alternative.

Setup

Keep your DDNS name, give it a reachable IP

Example: a home server you reach as myhome.duckdns.org.

  1. Choose a plan and sign up. Your dedicated IP shows in the dashboard.
  2. Open the ports your server uses, TCP or UDP. Every new IP starts with all ports closed, and only the ports you open answer.
  3. Download the WireGuard config and import it on the server, or on a router that runs WireGuard (OpenWrt, pfSense, OPNsense, MikroTik, GL.iNet). Turn the tunnel on.
  4. Set the hostname to the new IP once. In DuckDNS, put the IP in the ip field of the update URL; in No-IP or Dynu, edit the record in your account. Disable the DDNS client on your router.
  5. Test from outside your network, such as a phone on mobile data or the free port check, with the hostname and port.

You can delete the old port forward on your router. The tunnel does not need it.

Good to know

Good to know

  • If you have a dynamic public IPv4 and DDNS resolves correctly, you may not need us: fix the forward or the firewall instead.
  • The IP is a datacenter address in Kansas City, Missouri or San Jose, California. Users far from the IP's city see some extra delay.
  • Speed is capped per IP, up and down: 20 Mbps on Plus, 100 Mbps on Pro, 1 Gbps on Ultra.
  • No UPnP and no automatic port mapping. Apps that open their own ports on the router need those ports opened in the dashboard.
  • Each IP is one WireGuard config, active on one device at a time. Run it on a router and every device behind it shares the IP; the plan card's device figure is a guide, not a cap.
Pricing

Choose your plan

Plus for light use, Pro for most people, Ultra for full gigabit.

Plus
$2/mo

 

  • 1 dedicated IP address
  • 10 devices
  • 5 open ports
  • 100 GBbandwidth
  • 20 Mbpsspeed
Ultra
$10/mo

 

  • 2 dedicated IP addresses
  • Unlimited devices
  • Unlimited open ports
  • 5 TBbandwidth
  • 1 Gbpsspeed
  • Inbound + outbound access
  • Instant activation
  • 7-day money-back guarantee
  • Cancel anytime
Add-ons, per IP addressCustom hostname $5·Addtl. IP $2/mo (Ultra $7/mo)·Gigabit Speed (Plus & Pro) $5/mo·SMTP $25
FAQ

Questions, answered.

01My DDNS hostname resolves to a 100.64 address. What does that mean?

Your router's DDNS client is sending its own WAN address, and that address is in 100.64.0.0/10, the CGNAT range. Nobody outside your ISP can reach it. Switching the client to report your public IP does not fix reachability either, because that public IP is shared with other customers.

02Why can't I open my DDNS name from inside my own network?

Connecting from your LAN to your own public address needs NAT loopback (also called hairpin NAT) on the router, and many home routers do not support it. The name can work for everyone outside while failing at home. Test from a phone on mobile data instead.

03My hostname shows the right public IP, but the port is still closed. What now?

Then DDNS is fine. Check that the service listens on that port, that the forward points to the server's current LAN address with the right protocol, that the server's firewall allows it, and that your ISP does not block the port. Port forwarding not working walks through each check.

04Can I keep using DuckDNS or No-IP with a fixed IP?

Yes. Set the record to the fixed IP once. DuckDNS accepts an explicit ip value in its update URL; with the value blank it uses the address your request came from. You can also point your own domain at the DuckDNS name with a CNAME record, as their FAQ describes.

Have more questions? See the full FAQ →