Learn · Lesson 5 of 7 · 5 min
Names and DNS
Reach a machine by name, give a service a familiar address, or keep using your existing internal DNS.
Your device name is its DNS name.
Enable private DNS. A device named build-01 automatically gets the DNS name build-01.acme.internal. You don’t need to create a separate DNS record for each device.

build-01.acme.internalresolves to100.64.0.12Use your own organization domain. Baseguard resolves the device name to its private address.
ssh build-01.acme.internalWith your organization domain configured as a search domain, you can use the short name too: ssh build-01.
Make the dashboard easy to find.
In DNS → Records, add an A record pointing your service name at the node’s private IPv4 address.
- Domain
- grafana.corp.internal
- Type
- A
- Target
- 100.64.0.12
- TTL
- 300 seconds
A name helps devices find the service. Network rules still decide whether they can connect.
Send internal queries to your resolver.
Add your nameserver with a Match Domain, such as corp.internal.
If that resolver is unavailable, these queries fail. They do not fall back to a public resolver.
A few useful details
Resolution order. Node names → custom records → matching split DNS → default nameservers → system resolver. The most specific split DNS suffix wins.
Local resolver. Each daemon runs its own resolver at the first address of the overlay range, 100.64.0.1 by default. Only the local node can query it.
Records. A and AAAA records are supported. TTL is 60–86400 seconds, with 300 as the default. Scope records to tags to choose which nodes see them.
Wildcards. A single leading wildcard such as *.corp.internal matches one label below that domain.
Upstream nameservers. Plain DNS on port 53, up to 8 addresses per nameserver. DoT and DoH upstream are not supported. Default nameservers are queried in parallel; the first answer wins.
Next, find the record of the changes you’ve made.