Skip to main content
Connector guides

Connect DNS Made Easy

DNS Made Easy is a managed authoritative DNS service. Your domains' name servers point at it, and everything that answers "where does this name go?" for them lives in one account: the zones, their…

Written By Christopher Scaminaci

Last updated About 3 hours ago

DNS Made Easy is a managed authoritative DNS service. Your domains' name servers point at it, and everything that answers "where does this name go?" for them lives in one account: the zones, their records, the failover that moves a record to a healthy address, and the shared settings that many zones reuse. StackJack talks to it through the DNS Made Easy REST API version 2.0, the same service behind the control panel you already use.

Connecting DNS Made Easy to StackJack gives your AI assistant a family of dme_ MCP tools. MCP (Model Context Protocol) tools are the standardized commands an AI assistant can call through StackJack. With them, your AI can:

  • Look things up - every zone in the account, a zone by its name, and every record in it, filtered by type or by name
  • Work records - create one record or many, replace them, and delete them, including MX priorities, SRV fields, HTTP redirects and dynamic DNS records
  • Run zones - create and delete zones singly or in bulk, apply a record template, vanity name servers, a custom SOA record, a transfer ACL or a folder to one zone or to many at once
  • Watch DNS failover and monitoring - read and change the failover and system monitoring settings of an A record, including which address it answers and which contact list is emailed
  • Check query usage - monthly query counts for the whole account, for one zone, and for one secondary zone
  • Manage secondary DNS - secondary zones, the IP sets they transfer from, and their records
  • Maintain the shared settings - record templates and their records, custom SOA records, vanity name server sets and zone transfer ACLs
  • Keep the housekeeping straight - folders, and the contact lists that failover alerts go to

How StackJack authenticates to DNS Made Easy

DNS Made Easy gives each account one API Key and one Secret Key. You paste both into StackJack. There is no token to renew and no web address to enter.

Every request StackJack sends is signed with the Secret Key and stamped with the current time, so the Secret Key itself never travels. DNS Made Easy refuses a request whose time is more than 30 seconds away from its own clock, and StackJack signs each request at the moment it sends it for that reason.

Two facts about the keys decide whether you can connect at all:

  • API access needs a Business or DNS-25 membership or above. Small Business and DNS-5 accounts have no API keys. They have to upgrade first.
  • Only the account's primary user can see the keys. A sub-user cannot fetch them for themselves.

The keys are the whole credential. DNS Made Easy has no scopes, no roles and no read-only key, so one pair can do everything the API can. The way to limit an assistant is on the StackJack side: turn off the tools it should not have, and keep changes on the confirmation prompt (see "Destructive tools" below).

Steps

  1. Check the plan. The account must be Business, or DNS-25, or above.
  2. Sign in to the DNS Made Easy control panel as the primary user of the account.
  3. Open Config, then Account Information. Tick the checkbox that generates the keys the first time. The API Key and the Secret Key are shown on that page, and you can copy them again later. DNS Made Easy's own article on finding or generating API keys walks through it.
  4. Choose the environment in StackJack. Use Production for a real account. Sandbox is a separate, free test account with its own keys, and its keys only work with the Sandbox choice. A zone you create in the sandbox is not a real zone.
  5. Paste both keys into StackJack. Open Connectors, choose DNS Made Easy, enter the API Key and the Secret Key, choose the environment and save. StackJack asks for both on every save.
  6. Run a Test Connection. A failure here almost always means a key was cut short when it was copied, or the keys came from a different account than the environment you chose.

What is worth knowing before you start

The request budget is shared with everything else that uses your keys

DNS Made Easy allows 150 API requests every 5 minutes for the account's key, and every request counts: StackJack's, a certbot renewal's, Terraform's and your own scripts'. StackJack paces itself under that so the rest keeps working, but an assistant fanning out across many zones can still use up what is left.

When the limit is spent DNS Made Easy answers with an error that says "Rate limit exceeded". StackJack treats that as a pause and not as a bad key, so a busy account never has its connection switched off for it. Wait a few minutes. Ask for one filtered read instead of many broad ones: listing the records of a zone with a type or a name is far cheaper than sweeping every zone. If you need more room, DNS Made Easy sells extra API capacity through its support team.

Changes go live immediately

A record, a template, a custom SOA record, a vanity name server set or a zone transfer ACL is served by DNS Made Easy's name servers as soon as the change is accepted. There is no draft and no apply step.

Shared settings reach every zone that uses them. A record added to a template appears in every zone on that template. A change to a vanity name server set or a custom SOA record changes what every zone using it answers. A zone transfer ACL decides which servers may copy your zones, and dropping an address stops that server's transfers.

Update means replace

DNS Made Easy's update calls replace the object you send. A record update, a template record update, an SOA update, a vanity set update and an ACL update all keep only the fields in the request, and anything you leave out is lost. Read the object first and send it back complete. The same goes for lists inside an object: an ACL or an IP set update sends the complete list of addresses.

Destructive tools

Deleting anything, replacing a record, a template, a set or a list, applying one setting to many zones at once, changing failover and changing which servers a secondary zone transfers from are all marked destructive. So is creating a record, in a zone, a template or a secondary zone, because a record can carry a dynamic DNS password and the tool stores whatever you send. Creating a contact list and adding addresses to one are marked destructive as well: DNS Made Easy appears to send each new address a confirmation message and later failover alerts, which reaches people outside your account, and it does not document that. Whether your AI application asks you to confirm before running one depends on that application's own settings; see Destructive tools and confirmation. Review that setting before you let an assistant near a live zone.

Three of them are worth naming:

  • Deleting a zone takes its name off DNS Made Easy immediately, with every record in it. The vendor warns this is irreversible.
  • Deleting a record, or replacing one, changes live traffic at once. A wrong value is served until you correct it.
  • Changing failover decides which address a name answers and who is emailed. Turning it off is the same call as changing it.

Deleting every record in a zone, or every zone in an account, is deliberately not offered. The delete tools that take a list of IDs refuse an empty list, because DNS Made Easy reads a delete with no IDs as a delete of everything in scope.

Dynamic DNS passwords are secrets

A record can carry a dynamic DNS password: the secret a dynamic DNS client presents to update that one record. DNS Made Easy does not say whether reading a record returns it. StackJack therefore treats every tool that reads or writes records as one that may carry a credential: it never keeps those results as stored examples, and an unusually large record listing is refused rather than parked behind a download link. Creating a record is marked destructive for the same reason, since the record you send can set that password. Ask your assistant not to repeat such a password back to you.

A handful of routes have no worked example

DNS Made Easy's own route table lists a few operations that its documentation never shows being used: reading one record by its ID, the records of a secondary zone, query usage for a secondary zone, replacing a template's whole record set, and deleting one template record by its ID. StackJack includes them, and each says so in its description. If one answers "not found" for something that exists, the route may not be live on your account. Listing the records of a zone or of a template always works.

Plans and limits

Read tools are available on the Free tier. Everything that creates, changes or deletes is Pro. Business reaches the same tools as Pro and differs by monthly call quota.

See the generated DNS Made Easy tool reference for the current inventory, plan assignment, input schemas and destructive-action labels.

Most lists answer the whole collection in one reply because DNS Made Easy documents no page parameters for them. The record lists, a zone's, a secondary zone's and a template's, take a page size and a page number. DNS Made Easy's examples start counting pages at 0 in some places and at 1 in others, so StackJack passes the page number through unchanged and the reply says how many pages there are.

Several accounts, or one

DNS Made Easy has no partner or reseller API, and one key pair reaches exactly one account. There are two common shapes for an MSP:

  • You host your clients' zones in your own account. One connection covers every client. Folders group the zones by client, so ask your assistant to list the folders and filter by them.
  • Each client owns a DNS Made Easy account. Ask each client's primary user for that account's keys, add one connection per client from the connector's card, and name it after the client. Your AI names the connection on each call; omit the name and the call runs against your default connection. Pin an endpoint to one connection when an AI should never reach past a single client. See Several connections of one connector.

Troubleshooting

"Test Connection" fails straight after pasting the keys. The usual causes are a truncated copy, keys from a different account than the environment you picked (a sandbox key only works with Sandbox, a production key only with Production), or a plan below Business. DNS Made Easy answers "forbidden" for an unknown API Key, a wrong Secret Key and a request whose time is more than 30 seconds off, and it does not say which of the three it was, so copy both keys again from Config, then Account Information, and try once more.

Every call is refused though the keys are right. The clock that signs the request may be off. This is rare and it is on StackJack's side to fix, so contact StackJack support. StackJack recognizes this case: when DNS Made Easy's own clock disagrees with the time StackJack signed by more than 30 seconds, it reports the clock instead of a bad key and does not switch your connection off for it.

Calls start failing together for a few minutes. The request budget was used up. Wait for the window to clear instead of retrying, then narrow the read. If a script of your own runs against the same keys, it may be the one spending the budget.

A tool refuses to delete a template, a vanity set, an SOA record or an IP set. DNS Made Easy will not delete one that is still applied to a zone or a secondary zone. Move the zones to something else first.

A tool refuses to delete a zone. DNS Made Easy will not delete a zone that is waiting on a create or delete of its own. Wait for it to finish and try again.

A connection that worked stops working with no change at your end. Check that the keys have not been regenerated and that the account is still on a plan with API access, then paste the current keys again.

DNS Made Easy tools

dme_ · 73 tools · Free 29 · Pro 44

Contact lists

ToolWhat it does
dme_add_contact_list_emails
Pro · Destructive
DESTRUCTIVE: add email addresses to a contact list.
dme_create_contact_list
Pro · Destructive
DESTRUCTIVE: create a contact list.
dme_delete_contact_list
Pro · Destructive
DESTRUCTIVE: delete a contact list.
dme_get_contact_list
Free · Read-only
Get one contact list by its numeric ID.
dme_list_contact_lists
Free · Read-only
List every contact list in the account.

Folders

ToolWhat it does
dme_create_folder
Pro · Write
Create a folder and optionally move domains into it.
dme_delete_folder
Pro · Destructive
DESTRUCTIVE: delete a folder.
dme_get_folder
Free · Read-only
Get one folder by its numeric ID.
dme_list_folders
Free · Read-only
List every folder in the account.
dme_update_folder
Pro · Write
Rename a folder or change its default flag.

DNS failover and monitoring

ToolWhat it does
dme_get_failover
Free · Read-only
Get the DNS failover and monitoring settings of an A record.
dme_update_failover
Pro · Destructive
DESTRUCTIVE: create, change or turn off DNS failover for an A record.

Managed domains

ToolWhat it does
dme_create_domain
Pro · Write
Create one managed domain from its name.
dme_create_domains
Pro · Write
Create several managed domains in one call.
dme_delete_domain
Pro · Destructive
DESTRUCTIVE: delete one managed domain and all of its records.
dme_delete_domains
Pro · Destructive
DESTRUCTIVE: delete several managed domains in one call.
dme_find_domain_by_name
Free · Read-only
Find a managed domain and its numeric ID by domain name.
dme_get_domain
Free · Read-only
Get one managed domain by its numeric domain ID.
dme_get_domain_id_by_name
Free · Read-only
Find a managed domain ID by domain name, using the path form.
dme_list_domains
Free · Read-only
List every managed domain in the account.
dme_update_domain
Pro · Destructive
DESTRUCTIVE: change the settings of one managed domain.
dme_update_domains
Pro · Destructive
DESTRUCTIVE: apply the same settings change to several managed domains.

Query usage

ToolWhat it does
dme_get_domain_query_usage
Free · Read-only
Get DNS query usage for one managed domain for one month.
dme_get_query_usage
Free · Read-only
Get DNS query usage for the account for every month on record.
dme_get_query_usage_month
Free · Read-only
Get DNS query usage for the account for one month.
dme_get_secondary_domain_query_usage
Free · Read-only
Get DNS query usage for one secondary domain for one month.

Records

ToolWhat it does
dme_create_record
Pro · Destructive
DESTRUCTIVE: create one DNS record in a managed domain.
dme_create_records
Pro · Destructive
DESTRUCTIVE: create several DNS records in a managed domain in one call.
dme_delete_record
Pro · Destructive
DESTRUCTIVE: delete one DNS record of a managed domain.
dme_delete_records
Pro · Destructive
DESTRUCTIVE: delete several DNS records of a managed domain in one call.
dme_get_record
Free · Read-only
Get one DNS record of a managed domain by record ID.
dme_list_records
Free · Read-only
List the DNS records of a managed domain.
dme_update_record
Pro · Destructive
DESTRUCTIVE: replace one DNS record of a managed domain.
dme_update_records
Pro · Destructive
DESTRUCTIVE: replace several DNS records of a managed domain in one call.

Secondary DNS domains

ToolWhat it does
dme_create_secondary_domain_records
Pro · Destructive
DESTRUCTIVE: create DNS records on a secondary DNS domain.
dme_create_secondary_domains
Pro · Write
Create secondary DNS domains and assign an IP set.
dme_delete_secondary_domain
Pro · Destructive
DESTRUCTIVE: delete one secondary DNS domain.
dme_delete_secondary_domain_records
Pro · Destructive
DESTRUCTIVE: delete DNS records from a secondary DNS domain.
dme_get_secondary_domain
Free · Read-only
Get one secondary DNS domain by its numeric domain ID.
dme_list_secondary_domain_records
Free · Read-only
List the DNS records of a secondary DNS domain.
dme_list_secondary_domains
Free · Read-only
List every secondary DNS domain in the account.
dme_set_secondary_domains_ip_set
Pro · Destructive
DESTRUCTIVE: change the IP set of several secondary DNS domains.
dme_update_secondary_domain
Pro · Destructive
DESTRUCTIVE: change the IP set or folder of one secondary DNS domain.

Secondary IP sets

ToolWhat it does
dme_create_ip_set
Pro · Write
Create a secondary DNS IP set.
dme_delete_ip_set
Pro · Destructive
DESTRUCTIVE: delete a secondary DNS IP set.
dme_get_ip_set
Free · Read-only
Get one secondary DNS IP set by its numeric ID.
dme_list_ip_sets
Free · Read-only
List every secondary DNS IP set in the account.
dme_update_ip_set
Pro · Destructive
DESTRUCTIVE: replace the name and IP addresses of a secondary DNS IP set.

Custom SOA records

ToolWhat it does
dme_create_soa_record
Pro · Write
Create a custom SOA record.
dme_delete_soa_record
Pro · Destructive
DESTRUCTIVE: delete a custom SOA record.
dme_get_soa_record
Free · Read-only
Get one custom SOA record by its numeric ID.
dme_list_soa_records
Free · Read-only
List every custom SOA record in the account.
dme_update_soa_record
Pro · Destructive
DESTRUCTIVE: replace a custom SOA record.

Record templates

ToolWhat it does
dme_create_template
Pro · Write
Create a record template.
dme_create_template_record
Pro · Destructive
DESTRUCTIVE: add a record to a record template.
dme_delete_template
Pro · Destructive
DESTRUCTIVE: delete a record template.
dme_delete_template_record
Pro · Destructive
DESTRUCTIVE: delete one record from a record template by record ID.
dme_delete_template_records
Pro · Destructive
DESTRUCTIVE: delete several records from a record template in one call.
dme_get_template
Free · Read-only
Get one record template by its numeric ID.
dme_list_template_records
Free · Read-only
List the records of a record template.
dme_list_templates
Free · Read-only
List every record template, system and account.
dme_replace_template_records
Pro · Destructive
DESTRUCTIVE: replace the whole record set of a record template.
dme_update_template_record
Pro · Destructive
DESTRUCTIVE: replace one record of a record template.

Vanity name servers

ToolWhat it does
dme_create_vanity_ns
Pro · Write
Create a vanity name server configuration.
dme_delete_vanity_ns
Pro · Destructive
DESTRUCTIVE: delete a vanity name server configuration.
dme_get_vanity_ns
Free · Read-only
Get one vanity name server configuration by its numeric ID.
dme_list_vanity_ns
Free · Read-only
List every vanity name server configuration in the account.
dme_update_vanity_ns
Pro · Destructive
DESTRUCTIVE: replace a vanity name server configuration.

Zone transfer ACLs

ToolWhat it does
dme_create_transfer_acl
Pro · Write
Create a zone transfer ACL.
dme_delete_transfer_acl
Pro · Destructive
DESTRUCTIVE: delete a zone transfer ACL.
dme_get_transfer_acl
Free · Read-only
Get one zone transfer ACL by its numeric ID.
dme_list_transfer_acls
Free · Read-only
List every zone transfer ACL in the account.
dme_update_transfer_acl
Pro · Destructive
DESTRUCTIVE: replace the name and IP list of a zone transfer ACL.