Connecting Your DNS Provider to DNS Spy
DNS Spy can connect directly to your DNS provider and import your zones, so you never have to enter records by hand. This guide covers what provider sync does and how to create the right credential for each of the seven supported providers.
What Provider Sync Does
Import – reads every zone in your provider account and creates the matching domains and records in DNS Spy.
Recurring sync – periodically re-reads your zones so records you add at the provider start being monitored automatically. Sync never deletes records in DNS Spy — records that disappear from your provider are flagged, not removed.
Resolver-based monitoring – once imported, records are monitored by querying your authoritative nameservers from multiple regions, exactly as the public internet sees them. The provider API is only used to know what to monitor.
Every connection uses a read-only credential wherever the provider supports one. Tokens are stored encrypted and are never displayed again after you save them.
Cloudflare
In your Cloudflare dashboard, go to Manage Account → Account API Tokens and create a token whose policy is scoped to "All Domains" (access to all domains within the account), using the "DNS & Zones" permission group with only "DNS: Read" and "Zone: Read".
DNSimple
In DNSimple, go to Account → Automation and create an account access token. DNSimple tokens grant account-wide access.
DigitalOcean
In DigitalOcean, go to API → Tokens and generate a personal access token with read-only custom scopes (domain: read is all DNS Spy needs).
Bunny
In the bunny.net dashboard, go to Account Settings → API and copy your API key. Note: bunny.net API keys grant full account access — there is no read-only scope.
Linode (Akamai)
In Linode/Akamai Cloud Manager, go to My Profile → API Tokens and create a personal access token with only "Domains: Read Only" access.
Vultr
In your Vultr account, go to Account → API and enable a personal access token. Vultr tokens grant account-wide access; you can restrict them by source IP on that page.
Amazon Route 53
Route 53 connects with IAM access keys instead of an API token: create a dedicated IAM user with a least-privilege read-only policy, then create an access key for it. Never use root account keys. See the dedicated guide: Connect Amazon Route 53 to DNS Spy.
Connecting in DNS Spy
Once you have the credential, go to Team Settings → DNS Providers in DNS Spy, click Add, choose your provider, paste the credential, and use Test Connection to verify it before importing your domains.
Common Troubleshooting
Invalid token – the test connection fails immediately. Double-check you copied the full credential with no extra whitespace, that it has not expired or been revoked, and that it carries the scope listed above for your provider.
Zero zones found – the credential is valid but the account it belongs to has no zones DNS Spy can read. Make sure the token was created in the account that actually holds your DNS zones, and that its scope is not limited to specific zones you did not intend.
Paused connections – if a sync fails repeatedly (for example, after a token is revoked), DNS Spy pauses the connection and emails your team. Fix the credential and resume the connection from Team Settings → DNS Providers.
Replacing credentials – when you rotate a token or access key, edit the existing connection and paste the new credential. Your imported domains, records, and history stay intact; there is no need to delete and re-add the connection.
Amazon Route 53 is a trademark of Amazon.com, Inc. DNS Spy is not affiliated with or endorsed by Amazon.