Webhooks & Alerts
Webhooks push events to your own endpoint in real time (record changes, DynDNS updates, SSL expiry). Alert Rules watch DNS traffic and resolver health and fire when thresholds are crossed. Both live under Notifications in the panel, as tabs.

Webhooks
In the Webhooks tab, fill in a Name, the target URL, and tick which Events should trigger it:
record.created,record.updated,record.deleted— DNS record changesddns.updated— a DynDNS client pushed a new IPalert.fired— one of your Alert Rules triggeredssl.expiring— a monitored SSL certificate is approaching expiry
Leave Secret empty and PrimeDNS generates one for you — you'll need it to verify deliveries (see below). Click + Add webhook to save.

Use Send test on an existing webhook to fire a sample delivery without waiting for a real event.
Verifying delivery signatures
Every delivery is signed with HMAC-SHA256 over
{timestamp}.{json_body}, sent in these headers:
X-Webhook-Event: record.updated
X-Webhook-Signature: sha256=<hex digest>
X-Webhook-Timestamp: 1758500000
X-Webhook-Delivery: <delivery id>
Verify it on your endpoint before trusting the payload:
// Node.js
const crypto = require('crypto');
function isValid(rawBody, timestamp, signatureHeader, secret) {
const expected = 'sha256=' + crypto
.createHmac('sha256', secret)
.update(`${timestamp}.${rawBody}`)
.digest('hex');
return crypto.timingSafeEqual(Buffer.from(expected), Buffer.from(signatureHeader));
}
# PHP
$sigPayload = $timestamp . '.' . $rawBody;
$expected = 'sha256=' . hash_hmac('sha256', $sigPayload, $secret);
if (!hash_equals($expected, $signatureHeader)) {
http_response_code(401);
exit;
}
Failed deliveries retry with backoff, up to 5 attempts.
Alert Rules
In the Alert Rules tab, pick a Type:
servfail_pct— SERVFAIL response ratenxdomain_pct— NXDOMAIN response ratespike_event— sudden traffic spikeno_queries— a zone has gone quiet (no queries at all)ssl_expiring— a monitored certificate is close to expiry
Optionally scope the rule to one Zone, set the
Threshold and the evaluation Window (minutes),
then + Add rule. Triggered rules appear under
Recent incidents, and fire the alert.fired
webhook event if you have a webhook subscribed to it.

Next steps
- Wire an alert's
alert.firedevent to a webhook pointed at Slack, PagerDuty, or your own on-call tool. - Combine
ssl_expiringalerts with SSL Monitors (third tab) to get notified before a certificate lapses, not after.