Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

DNS-Lexicon is an open-source tool for managing DNS records through supported providers’ APIs. It gives scripts and Python applications a common interface for operations such as listing, creating, updating, and deleting records; it is not a DNS hosting service and does not issue certificates.

What is DNS-Lexicon?

DNS-Lexicon sits between an automation workflow and a DNS provider’s API. Its documentation describes a standardized way to manipulate DNS records across providers. You can use it from the command line or as a Python library, rather than writing separate record-management logic for every integration. The project is MIT-licensed; consult the repository for the license and redistribution details.

The project overview lists 90 supported DNS providers. That is the maintainers’ count, not a guarantee that every DNS host or every operation is supported. The project’s stated basis for support is provider API availability. Check the official overview and provider documentation for the current list.

How do I use DNS-Lexicon with my DNS provider?

Choose the provider integration, configure the credentials it expects, then request the record operation you need. The CLI’s provider, domain, record type, and operation parameters let the same general workflow be used across integrations, but the details are not identical: providers can require different credentials, optional dependencies, or operation-specific behavior.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Sale
TP-Link Deco 7 BE23 Dual-Band BE3600 WiFi 7 Mesh Wi-Fi Router
  • 𝐍𝐞𝐱𝐭-𝐆𝐞𝐧 𝐖𝐢-𝐅𝐢 𝟕 𝐰𝐢𝐭𝐡 𝟒-𝐒𝐭𝐫𝐞𝐚𝐦 𝐃𝐮𝐚𝐥-𝐁𝐚𝐧𝐝 𝐮𝐩 𝐭𝐨 𝟑.𝟔 𝐆?𝐩𝐬 - Designed with the latest Wi-Fi 7 technology, featuring Multi-Link Operation (MLO), Multi-RUs, and 4K-QAM, The Deco 7 BE23 delivers full speeds of up to 2882 Mbps on the 5GHz band, 688 Mbps on the 2.4GHz band with 4 streams and achieve optimized performance on latest WiFi 7 laptops and devices, like the iPhone 16 Pro, and Samsung Galaxy S24 Ultra.
  • 𝐖𝐢𝐝𝐞 𝐂𝐨𝐯𝐞𝐫𝐚𝐠𝐞 𝐰𝐢𝐭𝐡 𝐒𝐭𝐫𝐨𝐧𝐠 𝐂𝐨𝐧𝐧𝐞𝐜𝐭𝐢𝐨𝐧 - Enjoy seamless max Wi-Fi coverage up to 2,500 sq. ft (1-Pack) and 150 devices without compromising performance. 4x high-gain antennas per node and 4x high-power FEMs deliver far-reaching, reliable signals for remote workers, gamers, students, and more.
  • 𝐔𝐥𝐭𝐫𝐚-𝐅𝐚𝐬𝐭 𝟐.𝟓 𝐆𝐛𝐩𝐬 𝐖𝐢𝐫𝐞𝐝 𝐏𝐞𝐫𝐟𝐨𝐫𝐦𝐚𝐧𝐜𝐞 - Each Deco 7 BE23 unit is equipped with two 2.5 Gbps WAN/LAN ports, offering warp-speed connectivity for high-performance wired devices. Integrate with a multi-gig modem for gigplus internet.
  • 𝐎𝐮𝐫 𝐂𝐲𝐛𝐞𝐫𝐬𝐞𝐜𝐮𝐫𝐢𝐭𝐲 𝐂𝐨𝐦𝐦𝐢𝐭𝐦𝐞𝐧𝐭 - TP-Link is a signatory of the U.S. Cybersecurity and Infrastructure Security Agency’s (CISA) Secure-by-Design pledge. This device is designed, built, and maintained, with advanced security as a core requirement.
  • 𝐒𝐭𝐫𝐨𝐧𝐠𝐞𝐫, 𝐌𝐨𝐫𝐞 𝐑𝐞𝐥𝐢𝐚𝐛𝐥𝐞 𝐁𝐚𝐜𝐤𝐡𝐚𝐮𝐥 - The Deco 7 BE23 enhances stability with simultaneous wireless and wired backhaul, leveraging Wi-Fi 7 MLO for stronger, more stable connections.

Check provider fit before automating

  • Confirm that your DNS provider appears in the official provider list and that its API integration covers the record operations your workflow needs.
  • Read that provider’s configuration instructions for required credentials and any provider-specific optional dependency.
  • Choose the interface that suits your workflow: CLI for shell scripts and operational jobs, Python for application code, or Docker for a containerized run.

Use the CLI

The documentation demonstrates listing and creating TXT records, as well as deleting records by name and content or by provider identifier. A typical command specifies a provider, domain, record type, and action; use the exact options and authentication variables documented for the selected integration rather than assuming one universal credential scheme. See the user guide for command syntax and provider configuration.

Let DNS-Lexicon infer a provider when supported

The auto provider can infer a DNS provider from a domain’s authoritative nameservers using an internal mapping. This only identifies a provider when the mapping supports the nameservers; it does not remove the need to configure that provider’s credentials. If inference does not fit your environment, specify the provider directly.

Rank #2
pcWRT PW-AX1800 WiFi 6 Dual-Band Router with VLAN Support, OpenVPN/WireGuard/IPsec VPN Client/Server - Compatible with ExpressVPN/SurfShark etc., Parental Controls, Ad Blocking, Gigabit Ethernet
  • VLAN Network Segregation: This router includes five preconfigured VLANs that isolate IoT devices, guest users, and work systems into separate, secure networks. Each LAN port and every WiFi SSID can be assigned to a VLAN, giving you complete control over how traffic flows inside your home.
  • Dual VPN Client and Server Support: The router works as both a VPN client and a VPN server, supporting OpenVPN, IPsec, and WireGuard. You can route selected VLANs through a VPN while keeping others on your regular ISP connection, giving each device group the exact level of privacy it needs.
  • Full WiFi 6 on Both Bands: With dual-band WiFi 6 support, the router delivers modern wireless performance across 2.4GHz b/g/n/ax and 5GHz a/n/ac/ax. It improves capacity, stability, and speed while remaining compatible with older devices, making it ideal for busy homes with many connections. Wi-Fi Mesh is available after firmware update.
  • High-Performance Hardware Architecture: Powered by the IPQ6000 quad-core ARM processor at 1.2GHz, along with 128MB flash, 256MB RAM, and hardware NAT acceleration, the router handles multitasking, streaming, VPN traffic, and VLAN isolation smoothly without slowing your network.
  • Flexible and Powerful Parental Controls: You can use trusted services like OpenDNS, CleanBrowsing, and Cloudflare for filtering, then add custom block lists, allow lists, and schedules. The router includes defenses against common bypass attempts, letting families create rules that match each user. Best of all, it's subscription free!

How do I install DNS-Lexicon?

The project documents pip and Docker installation. The documentation identifies itself as version 3.25.2, and the project release page lists v3.25.2, released 10 May 2026. Verify the current version and installation guidance in the official documentation before pinning it in a deployment.

Install with pip

  1. Create and activate a Python virtual environment, as the project guide recommends.
  2. Install the base package with pip install dns-lexicon.
  3. If your provider requires an optional dependency, install its documented extra, such as pip install 'dns-lexicon[route53]'. The project also documents a full extra; choose it only if it suits your dependency policy.
  4. Configure the provider-specific credentials and run a low-risk record operation to confirm the integration works before relying on it in automation.

Run the Docker image

The documented official image is ghcr.io/dns-lexicon/dns-lexicon. The guide permits using a version-pinned image and shows 3.20.1 as an example tag; that example is not a recommendation to use that version now. Check the current release documentation, then choose an appropriate tag and provide the credentials required by your selected provider.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Can DNS-Lexicon automate DNS-01 certificate challenges?

Yes. DNS-Lexicon was designed for automation including Let’s Encrypt workflows. In a DNS-01 challenge, the certificate workflow needs a TXT record published in DNS so the certificate authority can verify control of the domain. DNS-Lexicon can connect that record-management step to the workflow through provider API calls; it does not itself request or issue the certificate.

Integrate it with a certificate client

The project guide includes an example hook for dehydrated with a supported provider and describes configuring a Certbot hook. In either case, configure the hook and the provider credentials before running the certificate client. Confirm that the selected provider integration can create and remove the required TXT records, and test the workflow in a controlled way before depending on it for renewal.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

When is DNS-Lexicon a good fit?

It is most useful when you want to automate DNS record changes across one or more API-capable providers through a common CLI or Python interface. It is not a substitute for choosing a DNS host, managing that host’s account, or resolving differences in provider authentication and behavior. Its practical fit comes down to provider coverage, implemented operations, credential and dependency requirements, and the deployment interface you prefer.

Best Value
PUSR USR-TCP232-302 Tiny Size RS232 to TCP IP Converter Serial RS232 to Ethernet Server Module Ethernet Converter Support DHCP/DNS (1)
  • This is a serial RS232 to Ethernet server, used for data transparent transmission. USR-TCP232-302 is a low-cost serial device server,whose function is to realize bidirectional transparent transmission between RS232 and Ethernet. USR-TCP232-302 is internally integrated with TCP/IP protocol. User can apply it to device networking communication.
  • Support DHCP, automatically obtain an IP address and query IP address through serial setting protocol, Support DNS function, Set parameters through webpage, Upgrade firmware via network.
  • Auto-MDI/MDIX, RJ45 port with 10/100Mbps, Serial port baud rate from 600 bps to 230.4 Kbps, Check bit of None, Odd, Even, Mark and Space.
  • Work Mode: TCP Server, TCP Client, UDP Client, UDP Server, HTTPD Client. Support virtual serial port and provide corresponding software USR-VCOM, Heartbeat package mechanism to ensure connection is reliable, put an end to dead link, User-defined registration package mechanism, check connection status and use as custom packet header.
  • Under TCP Server mode, Client number ranges from 1 to 16; default number is 4, The global unique MAC address bought from IEEE, user can define MAC address, Across the gateway, switches, routers, Can work in LAN, also can work in the Internet (external network).

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.