UpdatesExplore the release notes

Private DNS

A familiar name.
One less thing to remember.

Your dashboard. Your database. Your work machine. Get there by name, without looking up an IP address.

Your device names become DNS names automatically. Connect to a machine by name, give internal tools their own addresses, and keep using your existing DNS.

Get Started Free

Private DNS

Your device name is already its address.

Enable private DNS and reach each device by its name. No separate DNS record to create.

Name a device build-01 and it becomes build-01 under your organization’s DNS domain. Baseguard resolves that name to the device’s private IP automatically.

  • Use build-01.acme.internal in SSH and your usual tools.
  • With a search domain configured, the short name build-01 works too.
Terminal
~ ssh build-01.acme.internal
Device name: build-01
DNS name: build-01.acme.internal
Private address: 100.64.0.12
Connected · no custom DNS record needed
❯

Private DNS

Name your internal tools

Create an A or AAAA record for a dashboard, database or other private service.

Share a useful address with your team instead of instructions for finding a server. A custom record points the service name to its address.

  • Create A records for IPv4 or AAAA records for IPv6.
  • Scope record visibility to the node tags you choose.
grafana.corp.internal
Team dashboardPrivate
APIHealthy
DatabaseConnected
WorkersReady

Private DNS

Keep your existing DNS

Send matching internal domains to the nameserver that already knows them.

You do not have to recreate the names your team already uses. A split-DNS match domain sends those queries to your existing internal nameserver.

  • The most specific matching domain takes precedence.
  • Matching queries never fall back to a public resolver.
DNS · internal domain
QUERY

wiki.office.internal

Matches office.internal
Your internal nameserver10.0.0.53 · port 53

Matching queries stay with this resolver, even if it cannot answer.

FREQUENTLY ASKED QUESTIONS

A few things you might be wondering.

What if my internal nameserver is unavailable?

A query matching a split-DNS domain fails if that nameserver cannot answer. It does not fall back to a public resolver.

Does a DNS record grant network access?

No. Resolving a name and being allowed to connect are separate. Network rules still determine whether a node can reach the service.

Which upstream DNS protocols are supported?

Upstream DNS uses plain DNS on port 53. DoH and DoT upstreams are not supported. Each nameserver can have up to eight addresses.

TRY IT ON YOUR OWN NETWORK

Connect your first two machines.

Install Baseguard, join the same organization, and put it to work.