Help & installation
From your first hostname to an automatic updater, customer support and service reporting.
Your first hostname
- Read the service policies and register through Public. Your account starts as an external, DDNS-only customer.
- Choose Add hostname and select A for IPv4 or AAAA for IPv6.
- Save the one-time token. Download settings.conf while the token is shown, or paste the token into the installer. Never send it in a support message.
- Install a client and test an update. The DNS record appears after the first successful update.
- Check your router and firewall if you need inbound access. DDNS does not solve CGNAT.
Windows
- Download the EXE from Downloads. It contains Python and opens a console installer.
- Choose the default %USERPROFILE%\HostiDDNS folder or an empty custom NTFS folder.
- Enter the endpoint, full hostname and hidden API token. Default interval: five minutes.
- Choose whether to start at sign-in, test now and run in the background. It runs as your Windows user, without administrator credentials.
- Read updater.log in the install folder. Reopen HostiDDNS.exe with --configure to change settings.
.\HostiDDNS.exe --configure .\HostiDDNS.exe --once .\HostiDDNS.exe --uninstall
Windows protects the saved token with user-scoped DPAPI. Uninstall stops updates and removes automatic startup, retaining settings/program files for manual removal. The unsigned EXE must be tested on your Windows system before wider distribution.
Linux
Install Python 3.10+ using your distribution package manager. Extract the Linux ZIP, then run the installer as your ordinary user:
python3 install_linux.py
Choose ~/HostiDDNS or an empty custom folder, configure the hostname, and choose whether to enable a user-level systemd timer. The scheduler uses the interval chosen during installation. Rerun the platform installer if you change that interval.
systemctl --user status hosti-ddns-TASKID.timer journalctl --user -u hosti-ddns-TASKID.service python3 ~/HostiDDNS/hosti_ddns.py --once
The installer prints the actual TASKID and uninstall command. Timers normally run while the user session is available. An administrator can choose to enable lingering; the installer does not do it automatically. On systems without systemd, use --daemon or your own scheduler.
macOS
Install Python 3.10+ from python.org or your normal package manager. Extract the macOS ZIP:
python3 install_macos.py
Choose a folder, configure your hostname, then choose whether to enable a LaunchAgent. It runs once at load and every five minutes while you are signed in. The installer prints the exact label and removal command.
Keep the selected Python interpreter installed. After replacing/removing Python, rerun the platform installer to refresh its interpreter path. Linux/macOS protect settings with file permissions; the token is plaintext within the private file.
Your complete service guide
Use this guide to understand your account, connect a device, manage access, contact support and report a concern. Screens and availability depend on your account role and the operator’s configuration. Times in the workspace are UTC.
1. Your account and workspace
Choose the right entrance
The public homepage describes the service without requiring sign-in. Public / external is for people who operate their own destination services and need a stable hostname. Business / internal is for customers with separately agreed services, potentially including hosting, web proxying, remote access and technical support. Engineers is the management area for authorised staff. The same account can be upgraded by an engineer; an internal account does not automatically grant remote-access credentials.
Register and sign in
- Open Public, review the current policies and use the registration form if registration is available. Choose an email you can maintain and a strong unique password.
- After sign-in, start at Overview. Use the workspace navigation to open Hostnames, Messages & support, Required actions, Update clients or Account settings.
- Review Required actions before creating or changing services. Registration may be closed while the operator prepares legal details or changes service availability.
- Use Account settings to change your password. If you cannot sign in or no longer have access to your email, contact technology@kai-young.co.uk. The current service does not offer a self-service password-reset email flow.
Sessions expire after inactivity. Refresh the page if a form says the session changed. A page left open for a long time can contain an old form token. Sign out on shared computers. Your engineering privileges come from the server-provisioned role, not the text after the @ in your email.
Interface choices
Choose light, dark or system theme in the header. On small screens, Menu opens navigation. Workspace links show one focused view at a time. Without JavaScript, server-rendered workspace sections remain visible. The Skip to content link appears when reached by keyboard. Your browser’s normal zoom controls remain available.
2. Hostnames, addresses and DNS
What DDNS actually changes
Your allocated name, such as home.ddns.hosti.me, stays constant. A client sends the public IP address and a private hostname token to Hosti over HTTPS. Hosti updates the DNS record through its configured provider. This is the DuckDNS / No-IP model: customers keep their existing nameservers and do not install a public DNS server. A DDNS name is an address-book entry; it does not start your web server or open a firewall.
Create your first name
- Open Hostnames and choose Add hostname. Enter a label using letters, numbers and hyphens. Names must be available and comply with service rules.
- Choose A for IPv4 or AAAA for IPv6. Choose a record type matching the public address your destination actually uses.
- Save the token displayed once. If available, download settings.conf while that token is still shown. The token is the updater’s API key for that hostname.
- Configure a client with the full allocated name and run one test update. A newly reserved name may have no published DNS record until the first successful update.
- Check the last update and recorded address in Hostnames. Allow for DNS caching when testing from another device.
Default quotas differ between external and internal accounts and are set by the operator. A quota is not a promise of extra hosting capacity. If a label is rejected, check its syntax, availability, reserved-name rules and any domain restriction. Do not keep trying variations to evade a ban.
Use your own subdomain
If you already own example.com, you can usually create a DNS-only CNAME for home.example.com pointing to your allocated Hosti hostname at your existing provider. The updater still uses the Hosti name and its token. Your website server must accept the custom name and present a certificate matching it. Apex / root-domain aliases depend on your DNS provider; ask before replacing existing website or mail records. The service does not import or manage your whole domain zone.
Token rotation and deletion
A lost token cannot be recovered: rotate it and update every client that used the old token. Treat the new token as a password. Deleting a hostname removes its service entry and may remove its provider record; cached answers elsewhere can persist. Do not delete a working name simply to resolve a local client configuration problem. Keep configuration backups private and never paste a real token into a report or screenshot.
3. Installing and managing updater clients
The platform instructions above cover Windows, Linux and macOS. Use Downloads to obtain the relevant package or the standalone Python / PowerShell client. The Python client needs Python 3.10 or later. The Windows installer includes its runtime. Check the published SHA-256 checksums when distributing installers internally.
Understand settings.conf
| Setting | Meaning |
|---|---|
| endpoint | The HTTPS update endpoint, normally https://ddns.hosti.me/DNS-Endpoint/update. |
| hostname | The full name allocated by Hosti, rather than a custom CNAME alias. |
| api_key | Your hostname-specific update token. Never a Cloudflare API token or account password. |
| interval_seconds | How often the updater checks. Five minutes is a reasonable starting interval. |
| address | Automatic source detection where suitable, or an explicit valid public address for special routing. |
Choose your home folder or an empty custom install folder. Avoid public shares and folders other users can write to. On Windows the installer protects its saved token with user-scoped DPAPI. Copying that protected configuration to a different Windows user or machine will require reconfiguration. Linux and macOS use private file permissions; the token remains plaintext inside the private file.
Test before scheduling
Run once and inspect the result. Confirm that the resulting address is the connection you want people to reach. A VPN or outbound proxy may cause automatic detection to report a different public address. Set an explicit address if needed. IPv6 requires a reachable public IPv6 address and matching record; do not paste a private, loopback or example address.
Automatic startup
The Windows per-user client can start at sign-in. Linux uses the printed user-level systemd task name where available; timers normally depend on the user session unless an administrator enables lingering. macOS uses a user LaunchAgent while signed in. If the computer is asleep, shut down or offline, its updater cannot report changes. Reconfigure or reinstall the scheduler if you change interpreters, install paths or the interval used by the platform installer.
Uninstall or move a client
Use the installer’s documented removal command to stop automatic startup before deleting files. Retained settings may still contain an update credential, so remove them securely when no longer needed. Moving a client does not delete the hostname. Rotate the token if an old installation or backup is no longer trusted. For several hostnames use separate configurations or installations supported by your chosen client; do not assume one token updates every name on an account.
4. Routers, firewalls and reachability
The updater needs outbound HTTPS access on TCP port 443. It does not require inbound DNS port 53. To expose a destination service, configure the inbound ports that service needs, such as HTTPS for a website, and allow them in the router and destination firewall. Check your local network first, then test from a genuinely separate connection such as mobile data. Some routers do not support connecting to their own public address from inside the LAN.
CGNAT and changing networks
With carrier-grade NAT, your router may not have a directly reachable public IPv4 address. DDNS cannot fix that. Compare the WAN address shown by your router with the public address observed externally and ask your ISP about public addressing or supported alternatives. Mobile and shared broadband connections can also restrict inbound traffic. IPv6 can offer another route where available, but firewall rules and client IPv6 support still matter.
Ports and HTTPS certificates
DNS maps a name to an address; an A / AAAA record does not include the service port. If your service runs on a nonstandard port, users may need to include it in the URL or application settings. TLS certificates must match the hostname used by visitors. Updating DNS does not create or renew a certificate, and a certificate problem is different from a DNS problem.
DNS caching
Resolvers and applications cache answers according to DNS behaviour and record TTLs. Different networks may briefly show different answers after an update. Confirm the portal’s recorded address, compare DNS results and wait before rotating credentials or recreating records. A successful update means the provider accepted the operation; it does not prove the destination application is healthy.
5. Internal services and the web proxy
External accounts use DDNS only. If you want Hosti to host part of a service, help with technology or provide an approved IIS web proxy, open a support conversation with the upgrade topic. Explain your application, intended audience, connectivity, requirements and support needs. The engineer agrees scope and pricing before changing the service level.
For an approved proxy hostname, DNS points to the Hosti edge rather than directly to your origin. The updater changes the stored origin address. IIS forwards supported web traffic to that origin using the approved scheme and port. Confirm that the origin accepts the expected host name and remains reachable from the proxy. The proxy is not a general TCP/UDP tunnel, global CDN, WAF or blanket DDoS protection product.
Remote access at remaccess.kai-young.co.uk is separately provisioned. The DDNS login or an account upgrade does not automatically create a remote-access account. Ask your engineer for the right credentials and support boundaries. Any hostnames already in proxy mode must be moved to DNS-only before an engineer downgrades the customer to external.
6. Support conversations from start to finish
- Sign in and open Messages & support. Choose New conversation.
- Select Service support, Becoming an internal customer, or Abuse report / policy concern. Give the conversation a short subject describing the actual issue.
- Explain the expected result, what happened instead, the affected allocated hostname, approximate time and timezone, client platform and any error text. Redact tokens, passwords, personal data and secret URL parameters.
- Add permitted documents or screenshots if useful. Send the message and note its conversation number.
- Open that same conversation for further replies. Keep related follow-ups in the existing case so its history stays together.
- Check the stage and unread count. Mark the conversation read after reviewing it. Close it when the issue is resolved, or reopen it if the same issue returns.
Conversation stages
New means the conversation has just been created. Waiting for engineer normally follows a customer reply; waiting for customer normally follows an engineer reply. An engineer can set In progress while investigating, assign the case to a colleague and choose a priority. Resolved or Closed stops replies until reopened. Priority helps organise work and is not a guaranteed response-time commitment.
Find older conversations and messages
Filter by subject or conversation number and open/closed status. Conversation lists are paginated. Each thread displays a page of messages with links to earlier history and the latest page. Conversation history records stage changes and reopen/close events. Unread tracking is per signed-in user and based on messages from other people after that user’s last explicit mark-read action.
What support does and does not send
Messages are stored in the portal. Support replies and public report updates do not automatically send email in this release; check your case for replies. Policy-update notices use the separately configured service-notice email worker. The email link opens your own email application and does not send a message by itself. If you cannot sign in, use technology@kai-young.co.uk or the public reporting form for an appropriate service concern.
7. Documents, images and attachment review
Support accepts TXT, RTF, PDF, DOC, DOCX, PNG, JPEG / JPG and WebP. Audio, video, executables, arbitrary archives and macro-enabled Office formats are not accepted. A message can contain up to three files, with each file up to 5 MiB and the combined upload up to 10 MiB. The operator also sets a total database storage budget.
Filename extensions and basic file structure are checked. DOCX requires the PHP ZIP extension and is checked for expected document entries, excessive expansion and VBA project entries. These checks are not a malware scan and cannot guarantee a document is harmless. Legacy DOC, PDF and RTF can contain dangerous active content. Never enable macros, run embedded objects or open an untrusted document on a production server.
New attachments are pending review. Authorised engineers can download a pending file for review using a suitable isolated environment, then release it or reject it. Customers and reporters can only download released files belonging to their own case. Rejecting erases the stored bytes while leaving a minimal rejected-attachment record. Downloads are forced attachments; this portal does not render uploaded PDFs or images inline.
File bytes and metadata are stored as BLOBs in the SQLite database outside the public web root. The application does not save permanent attachment files. PHP / IIS may use temporary upload files during a request; the runtime manages those temporary files. Database backups contain the attachment bytes too. Closed-case retention removes associated attachment rows, but older backups may retain previous data until the operator’s backup retention expires.
Use a text message when a file is unnecessary. Send redacted log excerpts rather than complete configuration folders. Illegal-content and child-safety reports accept no attachments: supply exact URLs, dates and descriptions without downloading or reproducing the content.
8. Report a site, rights concern or restriction
Anyone can open Report a concern without a customer account. Categories include service rules, suspected illegal content, safety, malware/phishing, US DMCA, UK Copyright, Designs and Patents Act 1988 concerns, other intellectual-property / court-order matters and appeals. Reports are not visible to the affected customer through their ordinary workspace.
- Choose the closest category. Give the exact allocated hostname or page URL and explain what is wrong, when you saw it and which rule or right is involved.
- Provide a contact email. The form does not verify ownership of that email and does not send a confirmation email.
- For rights concerns identify the work, allegedly infringing locations, rights holder, your authority to act and the relevant legal basis. Use lawful documents where needed.
- For a DMCA notice complete the signature and rights declarations, plus contact details requested by the form. An engineer reviews completeness and applicability; selecting DMCA does not itself establish that statutory procedures apply.
- Submit and save the reference and one-time tracking key. Open Track your report to return later. The key is the case password; do not share it or put it in a URL.
- Read engineer replies and use the case for additional information. Lock access on a shared browser when finished.
Safe reporting and emergencies
For immediate danger contact emergency services. Report suspected online child sexual abuse imagery to the Internet Watch Foundation using the exact URL. Do not download, copy, screenshot or upload illegal imagery. Hosti’s report form is not an emergency response channel and has no promised monitoring interval.
Review, enforcement and appeals
Engineers can assign a report, record a priority, ask for information, post a reporter-visible update and maintain private internal notes. Reports move through Received, Under review, More information required, Action taken, No action at present or Closed. A report does not automatically ban a site. An engineer separately reviews the evidence, identifies the managed service and uses the moderation tools if justified. Service restrictions are not findings of criminal guilt.
To appeal, identify the restricted hostname and case reference and explain your grounds. A US statutory counter-notification has additional requirements; use the US Copyright Office resources and obtain advice where needed. Hosti does not automatically restore material on a statutory timetable through this form. The UK CDPA is a separate legal framework; do not treat every patent, design or trademark dispute as identical to a copyright notice.
Relevant information may need to be shared with an affected owner, professional advisers or authorities where necessary. Engineers should disclose only what is needed. Report references are not secrets; the tracking key is. Losing the key requires contacting the technology inbox and a proportionate identity check. Knowing the reference alone does not grant access.
9. Policies, required actions and restrictions
Read the policies before using the service. Your acceptance history records the particular immutable policy version you accepted. When engineers publish a new required version, an essential service email is queued. The 14-day acceptance period begins after that notice is submitted to the configured mail server, rather than when an attempted send fails. Submission does not guarantee arrival in your inbox; keep your contact details current and check Required actions.
If an acceptance deadline passes, hostnames can be parked on the configured notice edge. Web visitors see the owner-action page, and non-web connectivity may be interrupted. Sign in, read and accept all outstanding versions, then allow the maintenance and proxy-sync tasks and DNS caches to catch up. Accepting terms does not remove an independent ban or fix an unreachable origin.
Engineers can restrict accounts, source/origin IPs and domains. Domain notices can be generic, copyright-related or security-related. Approved proxy visitor bans apply to the scoped service; direct DDNS traffic cannot be observed or blocked at the Hosti web proxy. Optional browser identifiers can be cleared or spoofed and are not proof of identity. Appeal through a private case or the technology inbox.
Where proxy access tracking is configured, owners see their own service’s daily IP request/error counts, not a universal advertising ID or cross-site profile. Collection, retention and any optional browser matching depend on operator review and configuration. Use the privacy policy and contact team for data-access, correction or deletion requests.
10. Troubleshooting in a useful order
| Symptom | Check first | What to send support |
|---|---|---|
| Cannot sign in | Correct email, current password, session refresh and account status. | Email used and error text, never the password. |
| badauth | Full allocated hostname, current token and restrictions. Rotate only if needed. | Hostname, client version and redacted response. |
| Wrong public address | VPN/proxy routing, IPv4 versus IPv6 and explicit-address settings. | Expected and observed public addresses with no secrets. |
| Successful update, site unavailable | DNS answer, destination process, firewall, router, CGNAT, origin port and certificate. | Which tests passed, external test network and exact error. |
| 429 | Too many requests. Back off and check for duplicate running clients. | Interval and approximate retry rate. |
| 503 / 911 | Temporary service/provider issue. Retry later without a tight loop. | Time, hostname and response. |
| Upload rejected | Allowed extension, actual file format, 3-file and size limits, DOCX ZIP support. | Filename extension and size, not sensitive file contents. |
| Attachment unavailable | Pending/rejected review state, your case access and your session. | Case and message number. |
| Owner-action notice | Required actions, accepted versions and maintenance/proxy-sync completion. | Hostname and acceptance time. |
| Proxy gateway failure | Origin reachability from edge, stored address, permitted port and certificate. | Hostname and redacted origin diagnostics. |
On Windows, use Resolve-DnsName for a DNS check and Test-NetConnection for a relevant service port. On Linux/macOS, use your usual DNS lookup and connectivity tools. A successful ping does not prove HTTPS works; a failed ping does not prove the website is unavailable. Prefer testing the protocol you actually use.
A helpful support message says: “Expected X; got Y; last worked at Z; these checks passed; here is the redacted error.” Include your timezone when giving timestamps. Avoid repeating the same message in several new conversations: it fragments the history and does not raise priority automatically.
11. Engineer operating guide
Deploy and maintain
Keep the IIS public root at the package’s public folder. Store config, database and backups outside the public tree. Run the documented migration after upgrades using the same configuration as IIS. The application pool needs appropriate write permissions on the configured data directory; the PHP CLI user and IIS pool may have different permissions. Use the documented setup tools rather than exposing setup.php as a web installer.
Continue the maintenance, policy-mail and proxy-sync scheduled tasks, plus access-log import if configured. Confirm operator details, policy review, SMTP and notice-edge settings before using their related features. Back up the database and verify restoration; attachment BLOBs increase its size. Limit upload requests in PHP and IIS and set the database attachment budget. Do not open untrusted files directly on the production host.
Publish policies from Word
- Open Policies in the engineer workspace. Download the Word sources of the current version, then edit them locally. Update any version labels inside the documents and remove obsolete publication-record text before uploading.
- Create a version with a unique label and a clear change summary. Upload the Terms, Privacy and combined Acceptable Use and Misuse DOCX documents. Additional policies can be included with their own key, title and acceptance or acknowledgement type. Existing additional policies carry forward into new drafts.
- Choose Convert preview PDFs, wait for the scheduled conversion worker, then read every generated PDF from the draft preview. Only engineers can view drafts and download source Word files.
- Choose Publish and confirm the notice workflow. Publication uses the prepared PDFs unchanged, or generates them if no preview exists. All documents must succeed before the release becomes public. A failed conversion leaves the previous version current and sends no notices for the failed draft.
- The mail worker sends notices after successful publication. Each account has 14 days from SMTP submission. Required actions and acceptance history link to the exact archived PDF release. The engineer CSV includes each document hash, record type and permanent PDF URL.
Published PDFs and source DOCX files are held as database BLOBs, not editable files in the public folder. Do not replace the historical static PDFs to publish a policy change. Database backups contain the policy documents and acceptance evidence; preserve them together. Historical text-based versions remain available with their original evidence.
Work the support queue
- Open Messages & support and filter open conversations. Read the history and mark it read using your own account.
- Assign an engineer, set a sensible priority and stage, and reply with a clear next step.
- Review pending attachments in a suitable isolated environment. Release only after review, or reject to erase stored bytes.
- Use the existing thread for further exchanges. Resolve or close it once the outcome is clear; document the reason in a message.
- Use Customers to change a service level only after agreement. Provision remote access and hosting separately.
Review reports fairly
Inspect reporter-supplied details without automatically visiting or fetching dangerous URLs. Confirm that the target is a managed service and that evidence matches the alleged violation. For rights cases, verify authority, location, legal basis and notice completeness. Private notes are available in the report queue; reporter-visible case decisions must avoid unnecessary confidential data.
Apply any required ban separately in Bans & moderation with a clear reason and the report reference. Check scope, shared-IP impact, notice-edge readiness and appeal options. A case status of Action taken is a record of your decision, not an automatic enforcement command. Revoking one ban does not remove others. Before restoring service, check outstanding policy actions and all applicable restrictions.
Retention
Closed support cases are removed according to the configured closed-ticket retention; report cases closed by an engineer use the report-retention setting. Attachment rows follow their messages. Rejected attachment bytes are erased immediately. Existing backup copies require their own retention schedule. Open cases remain until closed or separately handled by the operator; do not assume a storage budget replaces a retention policy.
12. More common questions
Can I register several devices?
You can allocate hostnames within your account quota and configure an updater for each. Use the token belonging to the exact hostname. Different devices can share a network address, but one hostname should have one intended update source to avoid competing updates.
Is my account password the API key?
No. The updater uses the one-time hostname token. Your account password is for signing in to the portal. A Cloudflare credential belongs only to the operator’s server configuration.
Can I run two updaters for one name?
Only if you intend them to report the same address. Clients on different networks can repeatedly overwrite the record. Stop duplicate schedulers before investigating unexplained address changes.
Does DDNS keep my service running during a power cut?
No. It provides a stable name for the current address. It cannot power your device, keep broadband online or automatically migrate your application to another server.
Can I use it for a game server or other non-web service?
DNS-only hostnames can name a reachable service. Configure the actual service port and network access. The IIS web proxy and visitor restrictions are for supported web traffic, not arbitrary TCP/UDP services.
Does a custom CNAME give Hosti control of all my DNS?
No. Your existing DNS provider remains responsible for your domain. A CNAME points that one subdomain at the allocated name. Keep mail and other records intact.
Why is a new hostname missing from DNS?
Reserve the hostname, then run an authenticated first update. Confirm the update succeeded. Registration of a label alone does not necessarily publish a record.
Can support see my API token?
Tokens are stored as hashes and cannot be recovered from the portal. Engineers can rotate a token but should never ask you to send the existing token in a message.
Who can read my support conversation?
The owning customer and authorised engineers. Another customer cannot read it or download its attachments. Report cases use a separate private tracking key and engineer access.
Why does my upload show pending?
All new files are held for engineer review. The uploader and other case participants cannot download them through the portal until released. Engineers can review pending bytes; rejected bytes are erased.
Why do uploads not appear in a folder?
Permanent bytes live inside the SQLite database as BLOBs. Include the database in backups. PHP may still create temporary upload files while processing the request.
Can I upload a video, voice note, ZIP or macro-enabled Word file?
No. Use a concise text explanation or a permitted document/still image. DOCX is checked as an Office document; arbitrary ZIPs and macro-enabled formats are rejected.
Is a released file guaranteed safe?
No. Release records an engineer review, not a universal safety guarantee. Basic format checks do not replace malware scanning, protected viewers or careful handling.
Does unread mean the engineer has never seen my message?
Unread is per-user portal tracking. It changes when that user explicitly marks the case read. It is not a delivery receipt, proof of attention or an email-open indicator.
Can I report a site without signing up?
Yes. Open Report a concern, save the reference and one-time tracking key, then use Track your report for follow-up. Contact email ownership is not verified automatically.
Will a report instantly take a site down?
No. Engineers review the information and separately apply service restrictions when appropriate. Hosti cannot erase customer-hosted material from unrelated infrastructure.
What if my report concerns illegal images?
Send the exact location and a factual description without downloading or uploading the images. Child-safety and illegal-content cases accept text/URLs only. Use the IWF for suspected child sexual abuse imagery and emergency services for immediate danger.
Is the reporting form a registered DMCA agent?
No. A form and a contact inbox do not themselves establish designated-agent registration or safe-harbour eligibility. The operator must determine applicable legal obligations and agent arrangements separately.
Can I challenge a ban?
Yes. Use the appeal category, identify the affected service/reference and provide your grounds. Statutory counter-notices may require additional information and legal review. Do not create replacement accounts to evade restrictions.
I lost my report key. Can I recover it from the reference?
No. The key is stored as a hash and shown once. Contact the technology inbox for a proportionate recovery/identity process; knowing the reference alone does not grant access.
Why have I received a terms email but no support email?
Policy notices and support messages are different mechanisms. The policy worker sends essential notices; this release keeps support/report replies in their portal threads.
Can I request deletion of messages or my account?
Contact the technology inbox from your registered email or established report channel. The operator verifies the request and considers applicable retention, legal obligations and third-party rights.
Can an engineer guarantee a response by marking urgent?
Priority helps triage. It does not create a response-time promise or make the service an emergency channel. Agreed business support commitments must be documented separately.
What should I do before contacting support?
Check the relevant section above, run a single client update if appropriate and collect the hostname, time, platform and redacted error. Stop if continued testing risks exposing data or worsening an incident.
Frequently asked questions
Do I change my domain nameservers?
No. Like DuckDNS or No-IP, Hosti gives you a hostname such as home.ddns.hosti.me. Keep your existing nameservers. Your updater sends your public IP and hostname token to our HTTPS API, and Hosti updates the DNS record through its DNS provider.
Can I use a name on my own domain?
For a subdomain such as home.example.com, add a DNS-only CNAME at your existing DNS provider pointing to your allocated Hosti hostname. Use the full Hosti hostname and its token in the updater. For a website, configure your destination server to accept your custom name and obtain a matching TLS certificate. Root-domain alias support varies by provider; ask an engineer before changing it.
Do I need to forward DNS port 53?
No. Updater clients use outbound HTTPS on port 443. Open or forward only the inbound ports required by the services you operate. Hosti DDNS does not run a public DNS server on your device.
What is the difference between external and internal?
External accounts use DDNS only and operate their own destination services. Internal customers may have hosting, proxying, remote access and support agreed with Hosti. Engineers can upgrade the same account. Remote-access credentials are provisioned separately.
How do I ask about becoming an internal customer?
Open Messages & support, create a conversation, and choose Becoming an internal customer. Tell us about your technologies, hosting and support needs. We will discuss scope and pricing before anything is agreed.
Where does my API key come from?
It is the hostname token shown once when you create a hostname or rotate its token. Lost tokens cannot be recovered: rotate, then update every affected client.
Why does my updater say badauth?
Check the full hostname and current token. Account suspension, bans, disabled updates or token rotation can stop requests. Contact the technology inbox to appeal an enforcement decision.
Why is the detected address wrong?
Automatic detection uses the IP seen by the endpoint. VPNs and reverse proxies can change that address. Use an explicit public IP for IPv6 or special routing. Never use a private address.
Does this open ports or bypass CGNAT?
No. Your origin must already accept inbound connections through its network. Remote-access or hosting alternatives can be discussed with an engineer.
What does the reverse proxy do?
For approved internal customers, DNS points to the Hosti edge and IIS forwards web traffic to the stored public origin. It is not a general TCP/UDP tunnel, global CDN, WAF or DDoS protection service.
What content is prohibited?
Pornography, piracy/copyright infringement, illegal material or services, malware, phishing, harassment and attempts to evade bans are prohibited. Lawful educational, medical or support content is not pornography merely because it discusses sexual health.
How do bans work?
Engineers can restrict accounts, IP addresses/ranges or domains. Access/updates are blocked; affected DNS records are removed by maintenance when the DNS provider responds. Cached DNS and customer-hosted content may remain elsewhere. Shared IPs can affect other users, so decisions can be appealed.
How do I report abuse or a privacy concern?
Email technology@kai-young.co.uk or open a private abuse conversation. Give the hostname and relevant facts. Do not attach illegal imagery, passwords or update tokens.
Can I see visitors and block access?
Approved proxy owners can view daily IP request/error counts imported from IIS and review a scoped IPv4 visitor ban. Engineers manage domain/copyright/security restrictions. Browser matching is optional and requires site integration and privacy review; identifiers can be cleared or spoofed. We do not receive a universal advertising ID, observe direct DDNS traffic or track non-web services.
What happens when policies change?
Engineers publish an immutable version and queue a service email. Sign in to Required actions to read and accept it. You get 14 days from submission of your notice to the mail server. Failed submissions do not start a countdown. After the deadline your hostnames point to a notice edge, web traffic redirects to the owner-action page and non-web services are interrupted. Complete all outstanding acceptances to restore service on the next maintenance and proxy sync. DNS caches may delay recovery.
Will support replies email me?
No. Conversations are stored in the portal; check your workspace for replies. The email link opens your own mail application. It does not automatically send a message.
Can I delete my account or request my data?
Contact the technology inbox from your registered email. We verify requests proportionately and handle access, correction, erasure or other applicable rights under the privacy policy.
What if updates stop?
Run the client once, inspect its log, confirm HTTPS connectivity and verify the token. A server 429 means rate limiting; 503/911 means retry later or ask support. Do not repeatedly retry in a tight loop.
Are the policies final?
Policy documents are supplied as drafts until the operator details and review are confirmed in the service configuration. New public registration stays closed until that preparation is complete.