A dynamic DNS alternative: one fixed IPv4 instead of an updater

Dynamic DNS can only follow the address your ISP gives you; it cannot give you a reachable one. GetAStatic gives you a fixed public IPv4 over WireGuard, so one normal DNS record is enough.

Instant setup US-based IP

Updated

The problem

Why the name resolves but the port stays closed

You set up DuckDNS, No-IP or the DDNS page in your router. The name updates, it resolves to an address, and you forwarded the port. Still, nothing outside your home can connect. (Step-by-step diagnosis.)

Dynamic DNS only keeps a name pointed at whatever public address your connection has. It cannot create a public address. Behind CGNAT, the address it records belongs to your ISP and is shared by many homes. A connection to it arrives at the ISP's equipment, which has no idea it is meant for you and drops it. Your router's port forward is never reached.

Even without CGNAT, DDNS has rough edges. When your IP changes, the name points at the old address until the updater runs and caches expire. Some ISPs also block common inbound ports such as 80 on home plans.

Pricing

Choose your plan

Plus for light use, Pro for most people, Ultra for full gigabit.

Plus
$2/mo

 

  • 1 dedicated IP address
  • 10 devices
  • 5 open ports
  • 100 GBbandwidth
  • 20 Mbpsspeed
Ultra
$10/mo

 

  • 2 dedicated IP addresses
  • Unlimited devices
  • Unlimited open ports
  • 5 TBbandwidth
  • 1 Gbpsspeed
  • Inbound + outbound access
  • Instant activation
  • 7-day money-back guarantee
  • Cancel anytime
Add-ons, per IP addressCustom hostname $5·Addtl. IP $2/mo (Ultra $7/mo)·Gigabit Speed (Plus & Pro) $5/mo·SMTP $25
Why use GetAStatic?

Why swap DDNS for GetAStatic

  • An address that never changes, so there is no updater to run and no lag after a change
  • Reachable behind CGNAT, Starlink and 5G home internet
  • Open TCP or UDP ports in the dashboard instead of on the router
  • Use the IP directly or point your own domain at it once
How it works

A fixed IP removes the need for DDNS

GetAStatic gives you a dedicated public IPv4 that does not depend on your ISP. The device running your service connects out to our node in Kansas City, Missouri or San Jose, California over WireGuard, which CGNAT allows. Connections to your IP on the ports you open come back down that tunnel.

Because the IP never changes, you set a normal DNS A record once, or just use the IP. Your ISP address can change as often as it likes; nobody outside sees it.

If you want to keep your DuckDNS or No-IP name, point it at the fixed IP once and stop the updater. An updater left running on your router would write the ISP address back.

Setup

Set it up

Example: a home server with a website, SSH, and your own WireGuard server for remote access.

  1. Sign up for GetAStatic and note your fixed IP.
  2. In the dashboard, open the ports your services use on that IP.
  3. Download the WireGuard config and import it into WireGuard on the device that runs the services, or on your router.
  4. Turn the tunnel on and check that a what-is-my-IP site shows the new address.
  5. Create an A record for your domain pointing at the IP, or connect to YOUR-IP:port directly.
PortProtocolUsed for
443TCPWebsite (HTTPS)
22TCPSSH
51820UDPYour own WireGuard server

Plus allows 5 open ports; Pro and Ultra have unlimited open ports.

Good to know

Before you switch

  • The IP is a datacenter address in Kansas City, Missouri or San Jose, California, not a home address from your ISP. Users far from the IP's city see more delay.
  • Speed and bandwidth are capped by plan: 20 Mbps and 100 GB on Plus, 100 Mbps and 1 TB on Pro, 1 Gbps and 5 TB on Ultra.
  • Only the device running WireGuard uses the IP, and all of its traffic goes through the tunnel. Run WireGuard on your router to cover more of your network.
FAQ

Questions, answered.

01Do I still need DuckDNS or No-IP?

No. The IP does not change, so a plain A record at any DNS provider does the job. You can keep an existing DDNS name pointed at the fixed IP, but you no longer need an updater.

02What if my ISP blocks port 80?

Inbound traffic reaches you through the tunnel, so your ISP's inbound blocks do not apply. You can open 80 like any other port.

03How do I know CGNAT is my problem?

Compare the WAN address on your router's status page with what a what-is-my-IP site shows. If they differ, or the WAN address starts with 100.64 to 100.127 (the 100.64.0.0/10 range), you are behind CGNAT or another NAT layer, and port forwarding cannot work.

04Can I use a nice hostname?

Yes. Point any domain you own at the IP with an A record. Reverse DNS defaults to a getastatic.com name; a custom reverse DNS hostname is optional, $5 one-time.

Have more questions? See the full FAQ →