← Docs

Webhooks push events to your own endpoint in real time (record changes, DynDNS updates, SSL expiry). Alert Rules watch DNS traffic and resolver health and fire when thresholds are crossed. Both live under Notifications in the panel, as tabs.

Notifications view with Webhooks, Alert Rules and SSL Monitors tabs

Webhooks

In the Webhooks tab, fill in a Name, the target URL, and tick which Events should trigger it:

  • record.created, record.updated, record.deleted — DNS record changes
  • ddns.updated — a DynDNS client pushed a new IP
  • alert.fired — one of your Alert Rules triggered
  • ssl.expiring — a monitored SSL certificate is approaching expiry

Leave Secret empty and PrimeDNS generates one for you — you'll need it to verify deliveries (see below). Click + Add webhook to save.

Add webhook endpoint form with Name, URL, Events checkboxes and Secret field

Use Send test on an existing webhook to fire a sample delivery without waiting for a real event.

Verifying delivery signatures

Every delivery is signed with HMAC-SHA256 over {timestamp}.{json_body}, sent in these headers:

X-Webhook-Event: record.updated
X-Webhook-Signature: sha256=<hex digest>
X-Webhook-Timestamp: 1758500000
X-Webhook-Delivery: <delivery id>

Verify it on your endpoint before trusting the payload:

// Node.js
const crypto = require('crypto');

function isValid(rawBody, timestamp, signatureHeader, secret) {
  const expected = 'sha256=' + crypto
    .createHmac('sha256', secret)
    .update(`${timestamp}.${rawBody}`)
    .digest('hex');
  return crypto.timingSafeEqual(Buffer.from(expected), Buffer.from(signatureHeader));
}
# PHP
$sigPayload = $timestamp . '.' . $rawBody;
$expected   = 'sha256=' . hash_hmac('sha256', $sigPayload, $secret);
if (!hash_equals($expected, $signatureHeader)) {
    http_response_code(401);
    exit;
}
Note: hash over the raw request body, not a re-serialized/ re-parsed version of it — re-encoding JSON can reorder keys or change whitespace and break the signature check.

Failed deliveries retry with backoff, up to 5 attempts.

Alert Rules

In the Alert Rules tab, pick a Type:

  • servfail_pct — SERVFAIL response rate
  • nxdomain_pct — NXDOMAIN response rate
  • spike_event — sudden traffic spike
  • no_queries — a zone has gone quiet (no queries at all)
  • ssl_expiring — a monitored certificate is close to expiry

Optionally scope the rule to one Zone, set the Threshold and the evaluation Window (minutes), then + Add rule. Triggered rules appear under Recent incidents, and fire the alert.fired webhook event if you have a webhook subscribed to it.

Create alert rule form with Type, Zone, Threshold and Window fields

Next steps

  • Wire an alert's alert.fired event to a webhook pointed at Slack, PagerDuty, or your own on-call tool.
  • Combine ssl_expiring alerts with SSL Monitors (third tab) to get notified before a certificate lapses, not after.