RegistrarDNS hostingRegistrarCapabilities verified
Openprovider
Migrate DNS to or from Openprovider, and switch nameservers at Openprovider as a registrar.
See how a domain's records would land at Openprovider. Free and read-only.
Access we need
- Credentials
- Contact person username and password with API access enabled
- Permissions
- Openprovider API access is switched on per contact person and uses that contact's login; it can't be limited to read-only or to DNS only. Create a dedicated contact person for DNSMigrator and turn its API access off when you're done.
What Openprovider supports
The same data the translation engine uses when it plans a migration.
- Create zones through the API
- List zones through the API
- Turn on DNSSEC through the API
- Apex CNAME (flattening)
- Apex ALIAS record
- Aliases to cloud resources
- CDN proxy on records
- Routing policies
- Minimum TTL
- 900s
Record types
- A
- AAAA
- CNAME
- MX
- TXT
- SRV
- CAA
- TLSA
- SSHFP
Good to know
- Openprovider only accepts TTLs of 900, 3600, 10800, 21600, 43200 and 86400 seconds; other TTLs are rounded up to the next accepted value.
- Apex NS and SOA records are managed by Openprovider. NS records can't be added for subdomains and a CNAME can't sit at the zone apex (no ALIAS/ANAME).
- Null MX records (target ".") aren't supported. Legacy SPF-type records can be read and removed but not created; use TXT.
- Sectigo Premium DNS zones aren't listed or changed through this connection.
- Zones on Openprovider nameservers are signed automatically. For domains on other nameservers, Openprovider registers DNSSEC from the DNSKEY public key, not the DS digest.
- Identical API calls are limited to 300 per 5 minutes and failed logins to 100 per hour; going over can block the contact's API access until it's unblocked in the control panel.