> ## Documentation Index
> Fetch the complete documentation index at: https://infisical.com/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# UltraDNS connection

> Learn how to configure an UltraDNS Connection for Infisical.

Infisical connects to UltraDNS with the username and password of an UltraDNS user, and uses that access to manage the DNS records in your zones.

<Note>
  The UltraDNS REST API doesn't support accounts with Two Factor Mobile Authentication enabled. Use a dedicated
  API user, or disable Two Factor Mobile Authentication for the user you connect with.
</Note>

## Prepare an UltraDNS user

<Steps>
  <Step title="Create a user for Infisical">
    Sign in to the [UltraDNS Portal](https://portal.ultradns.com) and go to **Account → Users**, then add a user
    that Infisical will authenticate as. You can then revoke its access without affecting anyone else.
  </Step>

  <Step title="Grant zone and record permissions">
    Assign the user a role that can read zones and read, create, update, and delete resource records in the zones you
    want Infisical to manage. For ACME certificate issuance, Infisical writes a TXT record at
    `_acme-challenge.<your-domain>` and removes it once the certificate authority has validated the domain.
  </Step>

  <Step title="Confirm the zone type">
    Only zones of type **Primary** are available to Infisical, because secondary zones can't accept record changes.
  </Step>

  <Step title="Allow Infisical's IP addresses">
    Skip this step unless your UltraDNS account limits REST API access to allowed IP ranges. With that limit in place,
    UltraDNS rejects every request from an address outside the ranges, including the credential check when you create
    the connection. Add Infisical's outbound IP addresses to the allowed ranges:

    * **Infisical Cloud**: the addresses for your region, listed in [Infisical IP addresses](/docs/documentation/setup/networking).
    * **Self-hosted Infisical**: the public IP address your Infisical server uses for outbound traffic.
  </Step>
</Steps>

## Setup UltraDNS connection in Infisical

<Steps>
  <Step title="Navigate to App Connections">
    In **Certificate Manager**, go to **Settings → App Connections**.

    <img src="https://mintlify.s3.us-west-1.amazonaws.com/infisical/images/app-connections/general/add-connection.png" alt="App Connections Tab" />
  </Step>

  <Step title="Add Connection">
    Select the **UltraDNS Connection** option from the connection options modal.
  </Step>

  <Step title="Input Credentials">
    Enter the username and password of your UltraDNS user, choose the **Environment** to connect to, and select
    **Connect to UltraDNS**. Infisical verifies the credentials against the UltraDNS API before saving the connection.

    Choose **Production** for `api.ultradns.com` and **Test** for the UltraDNS customer test environment at
    `test-api.ultradns.com`. The two environments have separate accounts and separate zones, so a connection is only
    valid against the one its credentials belong to.

    <Warning>
      Keep these credentials secure and don't share them. Anyone with access to them can manage your UltraDNS records.
    </Warning>
  </Step>

  <Step title="Connection Created">
    Your **UltraDNS Connection** is now available for use in Certificate Manager.
  </Step>
</Steps>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.