Set Up Dynamic DNS on Namecheap with ddclient on Ubuntu

by Fahim

Most residential ISP lines and budget office connections don’t come with a static public IP. When your ISP resets your modem or rotates your WAN lease at 3 AM, your WireGuard tunnel drops, remote SSH access breaks, and any self-hosted staging sites go dark.

You don’t need to pay your ISP $15/month for a static IP or sign up for some clunky third-party DDNS service with annoying monthly confirmation emails. If your domain is on Namecheap, you can turn it into your own dynamic DNS endpoint using ddclient on Ubuntu (tested across 20.04, 22.04, and 24.04 LTS).

Mini server running ddclient on Ubuntu for Namecheap Dynamic DNS updates
Mini server running ddclient on Ubuntu for Namecheap Dynamic DNS updates

1. Generate Your Namecheap Dynamic DNS Password

Namecheap separates Dynamic DNS access from your account password. It generates a single dedicated token per domain, which lets ddclient update DNS records without having full API access or permission to mess with your billing.

Here is how to grab that password:

  1. Log in to Namecheap and open your Domain List.
  2. Hit Manage next to your domain.
  3. Click the Advanced DNS tab.
  4. Scroll down to the Dynamic DNS section and flip the toggle to ON.
  5. Copy the long alphanumeric string in the Dynamic DNS Password field.

Keep this string in a temporary scratchpad. We’ll drop it straight into our ddclient config in a moment.

2. Configure Host Records in Namecheap BasicDNS

Here is a quirk that catches almost everyone: Namecheap’s DDNS API will fail silently or throw auth errors if the record doesn’t already exist in your DNS table. ddclient updates records—it does not create them from scratch.

Under the Host Records section in Advanced DNS, add whatever records you plan to update:

  • Subdomain (e.g., home.example.com): Add an A + Dynamic DNS Record with Host set to home and Value set to a dummy IP like 127.0.0.1. Set TTL to Automatic or 1 min.
  • Apex/Root domain (e.g., example.com): Add an A + Dynamic DNS Record with Host set to @ and Value set to 127.0.0.1. (If you want a breakdown of how apex routing behaves versus standard subdomains, check our guide on configuring root domains in Namecheap DNS).
  • Wildcard: Add an A + Dynamic DNS Record with Host set to *.

Save changes in the dashboard. The dummy IP will get overwritten with your real public IP the second ddclient runs.

3. Install ddclient and Required SSL Packages on Ubuntu

Ubuntu ships ddclient in its standard apt repositories. However, it often skips the Perl SSL libraries by default. Without those, ddclient won’t be able to talk to Namecheap over HTTPS and will fail cryptically.

Install the package alongside the required SSL dependencies:

sudo apt update
sudo apt install -y ddclient libio-socket-ssl-perl ca-certificates

During installation, debconf will pop up an interactive ncurses configuration wizard. Choose Other for the service provider, or hit Cancel / accept the defaults to blast past it. We’re going to overwrite the config file manually anyway.

4. Configure /etc/ddclient.conf for Namecheap

The default /etc/ddclient.conf is bloated with outdated examples. Open the file with root permissions:

sudo nano /etc/ddclient.conf

Wipe the contents and paste in this clean configuration:

# Configuration file for ddclient on Ubuntu
# Check IP every 5 minutes (300 seconds)
daemon=300
syslog=yes
pid=/run/ddclient/ddclient.pid
ssl=yes # IP detection method using external service
use=web
web=https://api.ipify.org
web-skip='' # Namecheap Dynamic DNS API settings
protocol=namecheap
server=dynamicdns.park-your-domain.com
login=example.com
password=your_namecheap_ddns_password_here
home,vpn,@

Here’s what each key directive actually does:

  • use=web and web=https://api.ipify.org: Fetches your actual public WAN IP from ipify.org over HTTPS. This is critical—if you don’t use this, ddclient might grab your local LAN IP (like 192.168.1.50) from your network card.
  • protocol=namecheap: Formats the HTTP GET payload to match the Namecheap Dynamic DNS specification.
  • login=example.com: Your root apex domain. Don’t add www or https:// here.
  • password=...: The Dynamic DNS password you copied from the Advanced DNS tab.
  • home,vpn,@: Comma-separated list of host records to update. Use @ for root and the prefix (like home) for subdomains.

Since this config contains your plain-text token, lock down file permissions so non-root users on the box can’t read it:

sudo chown root:ddclient /etc/ddclient.conf
sudo chmod 600 /etc/ddclient.conf

5. Test ddclient and Force an IP Update

Before leaving the daemon to run in the background, run it once in the foreground with verbose debugging so you can see the raw API exchange:

sudo ddclient -daemon=0 -debug -verbose -noquiet -force

You’ll see ddclient hit api.ipify.org, discover your WAN IP, and send an update request to dynamicdns.park-your-domain.com. Near the end of the output, look for Namecheap’s XML response:

CONNECT: dynamicdns.park-your-domain.com
CONNECTED: using SSL
SEND: GET /update?domain=example.com&password=xxxx&host=home&ip=203.0.113.45 HTTP/1.0
RECEIVE: 
RECEIVE: SETDNSHOST
RECEIVE: eng
RECEIVE: 0
RECEIVE: 0
RECEIVE: true
RECEIVE: 
RECEIVE: 
SUCCESS: updating home: OS status: 200, HTTP status: 200, ...

As long as you see 0 and true, the record is synced.

Confirm the update propagated by querying a public resolver like Google or Cloudflare:

dig @8.8.8.8 home.example.com +short

If you’re running mail servers or other sensitive records on the same zone, take a look at our guide on configuring SPF, DKIM, and DMARC in Namecheap to make sure your dynamic records don’t conflict with your mail flow.

6. Enable and Secure the ddclient Systemd Service

Now we want ddclient running continuously as a systemd service so it boots automatically and checks for IP changes every 5 minutes.

First, verify the Ubuntu package daemon settings in /etc/default/ddclient:

sudo nano /etc/default/ddclient

Make sure it’s set to run as a daemon:

run_daemon="true"
daemon_interval="300"

Enable and start the service via systemd:

sudo systemctl restart ddclient
sudo systemctl enable ddclient

Check that it’s running without errors:

sudo systemctl status ddclient

You should see Active: active (running) in the status block.

7. Common Gotchas and Debugging Logs

I’ve run into a few edge cases over the years setting this up on client servers. Here is how to fix them quickly:

Gotcha 1: IP Caching Prevents Updates

ddclient caches your last known public IP in /var/cache/ddclient/ddclient.cache. If your IP hasn’t changed, ddclient won’t ping Namecheap (which prevents them from rate-limiting you). But if you changed your config or records and need to test an immediate force-update, blow away the cache:

sudo rm -f /var/cache/ddclient/ddclient.cache
sudo systemctl restart ddclient

Gotcha 2: Invalid Password or Domain ErrCount

If your debug run spits out 1 with messages like Domain name not found or Passwords do not match:

  • Make sure login in ddclient.conf is strictly your base zone (mydomain.com), never a subdomain.
  • Make sure the hostnames on the bottom line match the Host column in Namecheap BasicDNS exactly.
  • Double-check that the Dynamic DNS toggle in your Namecheap dashboard didn’t switch back to OFF.

Gotcha 3: Missing SSL Module Causing Silent Failures

If ddclient crashes with cannot load IO::Socket::SSL, you skipped the Perl SSL library during installation. Fix it with:

sudo apt install -y libio-socket-ssl-perl libnet-ssleay-perl

To inspect logs live as IP updates trigger, tail the journal:

sudo journalctl -u ddclient -f

For more CLI switches and syntax details, check the Ubuntu ddclient manpage.

Frequently Asked Questions

Can I update multiple subdomains with a single ddclient configuration?

Yes. Just list them on the last line of /etc/ddclient.conf separated by commas (for instance: @,home,vpn,staging). ddclient will cycle through and make an API request for each record.

Will ddclient work if my Ubuntu server is behind CGNAT?

If your ISP puts you behind Carrier-Grade NAT (CGNAT), use=web will detect the ISP gateway’s public IP, but inbound connections to your server will still be blocked by the carrier. You’ll need a reverse proxy or VPN tunnel (like Tailscale or a cheap VPS relay) instead of pure DDNS.

How frequently should ddclient check for IP changes?

Setting daemon=300 (every 5 minutes) strikes the right balance. It detects IP shifts quickly without burning unnecessary bandwidth or triggering Namecheap’s rate limiting.

Can I issue Let’s Encrypt certificates for a Dynamic DNS host?

Yes. Once your Namecheap DDNS record resolves to your server, Certbot HTTP-01 challenges work right out of the box. If you’re looking to generate wildcard certs, follow our guide on setting up Let’s Encrypt Wildcard SSL with Certbot DNS-01 on Nginx.

all_in_one_marketing_tool