Security
Last reviewed: July 2026
OneDollarDNS asks you to trust it with your domain list and, if you connect a DNS provider, credentials that can read your DNS zone. This page explains how we protect your data.
Encryption
All connections to OneDollarDNS are encrypted in transit (HTTPS).
Sensitive data, including DNS provider credentials, is encrypted at rest.
DNS provider credentials
We recommend connecting your DNS provider with a read-only or otherwise scoped API token rather than a full-access key, wherever your provider supports it. See Provider Sync for the specific permission each supported provider needs.
If you disconnect a provider or delete a stored credential, it is removed immediately — we don't keep a copy around after you remove it.
Authentication and account security
You can sign in with a password, or with Google or GitHub. Two-factor authentication is available and can be turned on from your account settings. Passwords are stored hashed, never in plain text.
Payments
Payments are processed by Stripe. Your card number and other payment details are sent directly to Stripe and never reach OneDollarDNS servers. We store the card brand and last four digits, so you can recognize which card is on file, along with billing history — never your full card number.
Infrastructure and monitoring
We monitor our infrastructure and application for errors and downtime so we can catch and fix problems quickly.
Backups
We perform daily backups of our database and other application data. If you need more detail on our backup and recovery practices, contact us and we'll answer directly.
Reporting a vulnerability
If you believe you've found a security vulnerability in OneDollarDNS, please email us at [email protected] with details. We ask that you give us a reasonable opportunity to investigate and address the issue before disclosing it publicly, and that you avoid accessing or modifying data that isn't yours while testing.
Data deletion and account closure
See our Privacy Policy for how long we retain your data and how to request deletion.