Integrates with
account required
RFC 2136 / TSIG
RFC 2136 DNS UPDATE with TSIG authenticates to your hidden primary, adds the TXT, queries it back from that nameserver, polls public resolvers, then deletes the same owner/value. Other RRsets are not in the UPDATE packet.
Verification: test_verified. Connection: unknown. Credentials: none. Live E2E: no.
No disposable BIND/PowerDNS primary with a TSIG update-policy is configured.
What sslcertificates.io can do
RFC 2136 DNS UPDATE with TSIG authenticates to your hidden primary, adds the TXT, queries it back from that nameserver, polls public resolvers, then deletes the same owner/value. Other RRsets are not in the UPDATE packet. Capabilities: update, tsig, read_back, delete_owned. Authentication uses tsig.
Required permissions
A TSIG key allowed to UPDATE only the challenge name, ideally via BIND update-policy.
Setup
Open Dashboard → Integrations → RFC 2136 / TSIG. Enter the credentials described on this page. Values are encrypted at rest and never shown again. Run Test connection. Discovery runs only after authentication succeeds. Select a discovered resource. Do not paste opaque IDs unless the provider cannot enumerate them. Perform the certificate or notification action, then confirm the external system matches. Disconnect removes stored credentials and owned test resources created by sslcertificates.io.
Known limitations
The connector sends UPDATE for the exact owner name. It never issues a zone-wide delete. hmac-sha256 is the default algorithm.
Official sources
Fact checked 2026-09-20. https://datatracker.ietf.org/doc/html/rfc2136 https://datatracker.ietf.org/doc/html/rfc2845 RFC 2136 / TSIG is a trademark of its owner. sslcertificates.io is not a partner or certified reseller unless a written agreement exists.
Capabilities
Connect
RFC 2136 / TSIG is a trademark of its owner. sslcertificates.io is not a partner or certified reseller unless a written agreement exists.