Connect DNS Made Easy
DNS Made Easy is a managed authoritative DNS service. Your domains' name servers point at it, and everything that answers "where does this name go?" for them lives in one account: the zones, their…
Written By Christopher Scaminaci
Last updated About 2 hours ago
DNS Made Easy is a managed authoritative DNS service. Your domains' name servers point at it, and everything that answers "where does this name go?" for them lives in one account: the zones, their records, the failover that moves a record to a healthy address, and the shared settings that many zones reuse. StackJack talks to it through the DNS Made Easy REST API version 2.0, the same service behind the control panel you already use.
Connecting DNS Made Easy to StackJack gives your AI assistant a family of dme_ MCP tools. MCP (Model Context Protocol) tools are the standardized commands an AI assistant can call through StackJack. With them, your AI can:
- Look things up - every zone in the account, a zone by its name, and every record in it, filtered by type or by name
- Work records - create one record or many, replace them, and delete them, including MX priorities, SRV fields, HTTP redirects and dynamic DNS records
- Run zones - create and delete zones singly or in bulk, apply a record template, vanity name servers, a custom SOA record, a transfer ACL or a folder to one zone or to many at once
- Watch DNS failover and monitoring - read and change the failover and system monitoring settings of an A record, including which address it answers and which contact list is emailed
- Check query usage - monthly query counts for the whole account, for one zone, and for one secondary zone
- Manage secondary DNS - secondary zones, the IP sets they transfer from, and their records
- Maintain the shared settings - record templates and their records, custom SOA records, vanity name server sets and zone transfer ACLs
- Keep the housekeeping straight - folders, and the contact lists that failover alerts go to
How StackJack authenticates to DNS Made Easy
DNS Made Easy gives each account one API Key and one Secret Key. You paste both into StackJack. There is no token to renew and no web address to enter.
Every request StackJack sends is signed with the Secret Key and stamped with the current time, so the Secret Key itself never travels. DNS Made Easy refuses a request whose time is more than 30 seconds away from its own clock, and StackJack signs each request at the moment it sends it for that reason.
Two facts about the keys decide whether you can connect at all:
- API access needs a Business or DNS-25 membership or above. Small Business and DNS-5 accounts have no API keys. They have to upgrade first.
- Only the account's primary user can see the keys. A sub-user cannot fetch them for themselves.
The keys are the whole credential. DNS Made Easy has no scopes, no roles and no read-only key, so one pair can do everything the API can. The way to limit an assistant is on the StackJack side: turn off the tools it should not have, and keep changes on the confirmation prompt (see "Destructive tools" below).
Steps
- Check the plan. The account must be Business, or DNS-25, or above.
- Sign in to the DNS Made Easy control panel as the primary user of the account.
- Open Config, then Account Information. Tick the checkbox that generates the keys the first time. The API Key and the Secret Key are shown on that page, and you can copy them again later. DNS Made Easy's own article on finding or generating API keys walks through it.
- Choose the environment in StackJack. Use Production for a real account. Sandbox is a separate, free test account with its own keys, and its keys only work with the Sandbox choice. A zone you create in the sandbox is not a real zone.
- Paste both keys into StackJack. Open Connectors, choose DNS Made Easy, enter the API Key and the Secret Key, choose the environment and save. StackJack asks for both on every save.
- Run a Test Connection. A failure here almost always means a key was cut short when it was copied, or the keys came from a different account than the environment you chose.
What is worth knowing before you start
The request budget is shared with everything else that uses your keys
DNS Made Easy allows 150 API requests every 5 minutes for the account's key, and every request counts: StackJack's, a certbot renewal's, Terraform's and your own scripts'. StackJack paces itself under that so the rest keeps working, but an assistant fanning out across many zones can still use up what is left.
When the limit is spent DNS Made Easy answers with an error that says "Rate limit exceeded". StackJack treats that as a pause and not as a bad key, so a busy account never has its connection switched off for it. Wait a few minutes. Ask for one filtered read instead of many broad ones: listing the records of a zone with a type or a name is far cheaper than sweeping every zone. If you need more room, DNS Made Easy sells extra API capacity through its support team.
Changes go live immediately
A record, a template, a custom SOA record, a vanity name server set or a zone transfer ACL is served by DNS Made Easy's name servers as soon as the change is accepted. There is no draft and no apply step.
Shared settings reach every zone that uses them. A record added to a template appears in every zone on that template. A change to a vanity name server set or a custom SOA record changes what every zone using it answers. A zone transfer ACL decides which servers may copy your zones, and dropping an address stops that server's transfers.
Update means replace
DNS Made Easy's update calls replace the object you send. A record update, a template record update, an SOA update, a vanity set update and an ACL update all keep only the fields in the request, and anything you leave out is lost. Read the object first and send it back complete. The same goes for lists inside an object: an ACL or an IP set update sends the complete list of addresses.
Destructive tools
Deleting anything, replacing a record, a template, a set or a list, applying one setting to many zones at once, changing failover and changing which servers a secondary zone transfers from are all marked destructive. So is creating a record, in a zone, a template or a secondary zone, because a record can carry a dynamic DNS password and the tool stores whatever you send. Creating a contact list and adding addresses to one are marked destructive as well: DNS Made Easy appears to send each new address a confirmation message and later failover alerts, which reaches people outside your account, and it does not document that. Whether your AI application asks you to confirm before running one depends on that application's own settings; see Destructive tools and confirmation. Review that setting before you let an assistant near a live zone.
Three of them are worth naming:
- Deleting a zone takes its name off DNS Made Easy immediately, with every record in it. The vendor warns this is irreversible.
- Deleting a record, or replacing one, changes live traffic at once. A wrong value is served until you correct it.
- Changing failover decides which address a name answers and who is emailed. Turning it off is the same call as changing it.
Deleting every record in a zone, or every zone in an account, is deliberately not offered. The delete tools that take a list of IDs refuse an empty list, because DNS Made Easy reads a delete with no IDs as a delete of everything in scope.
Dynamic DNS passwords are secrets
A record can carry a dynamic DNS password: the secret a dynamic DNS client presents to update that one record. DNS Made Easy does not say whether reading a record returns it. StackJack therefore treats every tool that reads or writes records as one that may carry a credential: it never keeps those results as stored examples, and an unusually large record listing is refused rather than parked behind a download link. Creating a record is marked destructive for the same reason, since the record you send can set that password. Ask your assistant not to repeat such a password back to you.
A handful of routes have no worked example
DNS Made Easy's own route table lists a few operations that its documentation never shows being used: reading one record by its ID, the records of a secondary zone, query usage for a secondary zone, replacing a template's whole record set, and deleting one template record by its ID. StackJack includes them, and each says so in its description. If one answers "not found" for something that exists, the route may not be live on your account. Listing the records of a zone or of a template always works.
Plans and limits
Read tools are available on the Free tier. Everything that creates, changes or deletes is Pro. Business reaches the same tools as Pro and differs by monthly call quota.
See the generated DNS Made Easy tool reference for the current inventory, plan assignment, input schemas and destructive-action labels.
Most lists answer the whole collection in one reply because DNS Made Easy documents no page parameters for them. The record lists, a zone's, a secondary zone's and a template's, take a page size and a page number. DNS Made Easy's examples start counting pages at 0 in some places and at 1 in others, so StackJack passes the page number through unchanged and the reply says how many pages there are.
Several accounts, or one
DNS Made Easy has no partner or reseller API, and one key pair reaches exactly one account. There are two common shapes for an MSP:
- You host your clients' zones in your own account. One connection covers every client. Folders group the zones by client, so ask your assistant to list the folders and filter by them.
- Each client owns a DNS Made Easy account. Ask each client's primary user for that account's keys, add one connection per client from the connector's card, and name it after the client. Your AI names the connection on each call; omit the name and the call runs against your default connection. Pin an endpoint to one connection when an AI should never reach past a single client. See Several connections of one connector.
Troubleshooting
"Test Connection" fails straight after pasting the keys. The usual causes are a truncated copy, keys from a different account than the environment you picked (a sandbox key only works with Sandbox, a production key only with Production), or a plan below Business. DNS Made Easy answers "forbidden" for an unknown API Key, a wrong Secret Key and a request whose time is more than 30 seconds off, and it does not say which of the three it was, so copy both keys again from Config, then Account Information, and try once more.
Every call is refused though the keys are right. The clock that signs the request may be off. This is rare and it is on StackJack's side to fix, so contact StackJack support. StackJack recognizes this case: when DNS Made Easy's own clock disagrees with the time StackJack signed by more than 30 seconds, it reports the clock instead of a bad key and does not switch your connection off for it.
Calls start failing together for a few minutes. The request budget was used up. Wait for the window to clear instead of retrying, then narrow the read. If a script of your own runs against the same keys, it may be the one spending the budget.
A tool refuses to delete a template, a vanity set, an SOA record or an IP set. DNS Made Easy will not delete one that is still applied to a zone or a secondary zone. Move the zones to something else first.
A tool refuses to delete a zone. DNS Made Easy will not delete a zone that is waiting on a create or delete of its own. Wait for it to finish and try again.
A connection that worked stops working with no change at your end. Check that the keys have not been regenerated and that the account is still on a plan with API access, then paste the current keys again.
DNS Made Easy tools
dme_ · 73 tools · Free 29 · Pro 44
Contact lists
Folders
DNS failover and monitoring
Managed domains
Query usage
Records
Secondary DNS domains
Secondary IP sets
Custom SOA records
Record templates
Vanity name servers
Zone transfer ACLs
Was this helpful?
More in Connector guides
Connect Acronis Cyber Protect CloudConnect Action1Connect AddigyConnect AlertOpsStill need help? Ask the team