Someone installs a CCTV recorder in their shop, opens a port on the router, and notes the public IP so they can watch the cameras from home. It works for a week. Then one morning the app won't connect, even though nobody changed any settings.
What changed is the IP address. Most home and small-business plans use dynamic IPs: the provider can assign a new address at any time, for example after the router restarts or the power goes out. DDNS was made for exactly this.
How it works
DNS translates names like example.com into IP addresses; the basics are in what DNS is and how it works. DDNS (Dynamic DNS) is DNS whose record is updated automatically.
- You register a name, say myshop.ddns.net, with a DDNS provider.
- The router, CCTV recorder, or NAS on site runs a DDNS client. Every few minutes, or whenever the public address changes, it reports to the provider: "this is my address now".
- The provider updates the record for that name.
- From outside, you simply connect to myshop.ddns.net, and the name always points to the latest address.
Many routers have a built-in DDNS menu, usually under Advanced, Network, or WAN. Some brands even give a free name on their own domain, so all you do is flip one switch.
The requirement that often isn't met
DDNS only provides a name. It doesn't make your location reachable. For that, the router must hold a genuine public IP.
In Indonesia, many home plans sit behind CGNAT: the provider places many customers behind one shared public address. Your router only gets something like 100.64.x.x or 10.x.x.x on its WAN side. DDNS can still report an address, but that address is shared and can't be pointed at your device. The full explanation is in what NAT and CGNAT are.
A quick check: compare the WAN address on the router's status page with the address an IP-checking site shows. If they match, you have a public IP and DDNS will be useful. If they differ, ask the provider for a public IP; some give it free on request, others as a paid add-on. The comparison for businesses is in static vs dynamic IP for business.
The second requirement is port forwarding: the router needs to know which device inside receives connections from outside. The steps are in how to set up port forwarding.
Common uses
| Purpose | Note |
|---|---|
| Viewing a CCTV recorder remotely | Often safer through the manufacturer's cloud app or a VPN than opening ports directly |
| Accessing a NAS or office files | Use an encrypted connection; see choosing a NAS |
| VPN into the home or office network | The most recommended use of DDNS: only one port is open |
| A game server or small website | Check the provider's terms; some home plans forbid servers |
| Logging into the router admin page from outside | Best avoided |
Risks that come with it
A DDNS name makes your device easier to find, for you and for everyone else. A port open to the internet will be scanned by automated programs within hours. If behind it is a CCTV recorder with a default password or old firmware, DDNS just makes it easier for an intruder to find it again after the address changes.
- Change the default password on every device exposed to the outside.
- Update that device's firmware regularly.
- Open as few ports as possible. One VPN port is safer than five ports for five devices.
- Disable router admin access from the WAN side.
- Check the list of automatically opened ports; UPnP sometimes adds ports without you noticing.
Cameras are the devices that most often go wrong here; see Wi-Fi CCTV camera security.
If you can't get a public IP
There are ways to reach devices at home without a public IP or DDNS. The built-in cloud apps of cameras and NAS units connect out to the manufacturer's server, and you connect through that server. Mesh-based VPN services and tunnel services work similarly: the device at home starts an outgoing connection, so CGNAT is no obstacle. These are often easier and safer for households and small businesses than opening ports, provided you trust the service provider.
Frequently asked questions
Is DDNS the same as a static IP?
No. A static IP means the address genuinely never changes. DDNS still uses a changing address, but updates a domain name every time the address changes, so from outside it looks fixed.
Why is DDNS enabled but still unreachable from outside?
The most common cause is CGNAT: your router doesn't hold a public IP, so the address DDNS reports isn't one that can be reached from the internet. Other causes are a missing port forward or a port blocked by the provider.
Do DDNS services have to be paid for?
Not always. Many router brands give owners a free DDNS name, and some DDNS providers are free with periodic confirmation. Paid tiers usually offer your own domain name and no confirmation requirement.