- 1 dedicated IP address
- 10 devices
- 5 open ports
- 100 GBbandwidth
- 20 Mbpsspeed
Dynamic DNS can only follow the address your ISP gives you; it cannot give you a reachable one. GetAStatic gives you a fixed public IPv4 over WireGuard, so one normal DNS record is enough.
Updated
You set up DuckDNS, No-IP or the DDNS page in your router. The name updates, it resolves to an address, and you forwarded the port. Still, nothing outside your home can connect. (Step-by-step diagnosis.)
Dynamic DNS only keeps a name pointed at whatever public address your connection has. It cannot create a public address. Behind CGNAT, the address it records belongs to your ISP and is shared by many homes. A connection to it arrives at the ISP's equipment, which has no idea it is meant for you and drops it. Your router's port forward is never reached.
Even without CGNAT, DDNS has rough edges. When your IP changes, the name points at the old address until the updater runs and caches expire. Some ISPs also block common inbound ports such as 80 on home plans.
Plus for light use, Pro for most people, Ultra for full gigabit.
5× speed · 10× bandwidth · 2 IPs — only $2/mo more
GetAStatic gives you a dedicated public IPv4 that does not depend on your ISP. The device running your service connects out to our node in Kansas City, Missouri or San Jose, California over WireGuard, which CGNAT allows. Connections to your IP on the ports you open come back down that tunnel.
Because the IP never changes, you set a normal DNS A record once, or just use the IP. Your ISP address can change as often as it likes; nobody outside sees it.
If you want to keep your DuckDNS or No-IP name, point it at the fixed IP once and stop the updater. An updater left running on your router would write the ISP address back.
Example: a home server with a website, SSH, and your own WireGuard server for remote access.
| Port | Protocol | Used for |
|---|---|---|
| 443 | TCP | Website (HTTPS) |
| 22 | TCP | SSH |
| 51820 | UDP | Your own WireGuard server |
Plus allows 5 open ports; Pro and Ultra have unlimited open ports.
No. The IP does not change, so a plain A record at any DNS provider does the job. You can keep an existing DDNS name pointed at the fixed IP, but you no longer need an updater.
Inbound traffic reaches you through the tunnel, so your ISP's inbound blocks do not apply. You can open 80 like any other port.
Compare the WAN address on your router's status page with what a what-is-my-IP site shows. If they differ, or the WAN address starts with 100.64 to 100.127 (the 100.64.0.0/10 range), you are behind CGNAT or another NAT layer, and port forwarding cannot work.
Yes. Point any domain you own at the IP with an A record. Reverse DNS defaults to a getastatic.com name; a custom reverse DNS hostname is optional, $5 one-time.
Have more questions? See the full FAQ →