Comment by ectospheno
Comment by ectospheno 20 hours ago
Why dont providers offer dns api keys restricted to txt records?
Comment by ectospheno 20 hours ago
Why dont providers offer dns api keys restricted to txt records?
desec.io allows you to create (through the api) tightly-scoped tokens that can only update the "_acme-challenge.subdomain.example.com" domain needed for DNS-01 challenges.
I switched to them from cloudflare dns for that specific functionality and it works great.
https://dns.he.net/ does. Each record can have its own secret. You can also use this for things like A records to do dynamic DNS.