Few Servers

Home›Blog›Self-hosting

sslip.io vs nip.io: free wildcard DNS for test servers, checked

sslip.io and nip.io turn any IP address into a hostname with no DNS setup. We ran the lookups: both are now one service with the same nameservers and formats.

You have a fresh server with an IP address and no domain, and the tool you just installed wants a hostname. That is the gap sslip.io and nip.io fill. Coolify uses sslip.io for the URL it gives every new app, which is how we ran into it.

What they do

A normal hostname needs a DNS record that somebody created. These services skip that step: the answer is computed from the name itself. Put an IP address in the hostname, and the DNS server returns it.

$ dig +short 203.0.113.10.sslip.io @1.1.1.1
203.0.113.10
$ dig +short 203-0-113-10.sslip.io @1.1.1.1
203.0.113.10
$ dig +short app.203.0.113.10.nip.io @1.1.1.1
203.0.113.10
$ dig +short cb00710a.nip.io @1.1.1.1
203.0.113.10
$ dig +short AAAA 2001-db8--1.sslip.io @1.1.1.1
2001:db8::1

Anything in front of the IP is ignored, so every subdomain works. That is the "wildcard" part: api., staging. and pr-42. all land on the same server, and a reverse proxy such as Traefik or Caddy routes them by hostname.

The formats that work

FormatExampleResolves to
Dots203.0.113.10.nip.io203.0.113.10
Dashes203-0-113-10.nip.io203.0.113.10
Subdomain in frontapp.203.0.113.10.nip.io203.0.113.10
Hexadecimalcb00710a.nip.io203.0.113.10
IPv6, dashes only2001-db8--1.nip.io2001:db8::1

We ran every row against both domains and got the same answers. Private addresses work too: 192.168.1.10.sslip.io and 10.0.0.5.sslip.io returned the private IP, which is handy for a home lab.

sslip.io vs nip.io: is there a difference?

Not any more. They started as separate projects: nip.io in 2012, sslip.io in 2015. According to the nip.io site, the nip.io domain was transferred to the sslip.io maintainers in July 2025 after its creator died, and both are now run by the same two people on the same software.

Our lookups agree. Both domains returned the same nameserver set:

$ dig +short NS sslip.io @1.1.1.1
ns-01.nip.io.
ns-ovh.sslip.io.
ns-00.nip.io.
$ dig +short NS nip.io @1.1.1.1
ns-ovh.sslip.io.
ns-00.nip.io.
ns-01.nip.io.

And https://sslip.io/ answered with a 301 redirect to https://nip.io. Pick whichever name you find easier to type. The site suggests one practical use for having two: if a certificate request for one domain is rate-limited, try the other.

How fast is it?

LookupTime
First lookup of a new name, sslip.io (5 runs)98 to 178 ms
First lookup of a new name, nip.io (5 runs)175 to 181 ms
Repeat lookup of the same name (3 runs)20 to 21 ms

Answers carry a TTL of 3600 seconds, so a resolver asks once an hour per hostname. The first visit to a fresh preview URL pays the extra tenth of a second; after that it is cached like any other name.

HTTPS works, one hostname at a time

You can get a normal Let's Encrypt certificate for a sslip.io or nip.io hostname with the HTTP-01 challenge, which is what Traefik and Caddy do automatically. Two limits from the service's documentation:

  • "nip.io & sslip.io do not support wildcard certificates." Each hostname needs its own certificate.
  • Everyone using the domain shares one Let's Encrypt rate limit. The site says it has been raised from 50 to 250,000 certificates over the years.

When not to use it

  • Production. Your site's DNS would depend on a free service run by two people. A domain costs about a dollar a month.
  • Anything that trusts the hostname. Anyone can create a name under these domains that points at any IP, including yours or their own. Do not scope cookies or logins to it.
  • Networks that filter private answers. Some routers and company resolvers drop DNS answers that point at private addresses (rebinding protection). 1.1.1.1 returned ours without complaint; a home router may not.

One thing from our own bench: the sslip.io address Coolify gave our first app resolved with curl and dig, but one browser on the same machine refused to open it. We have not pinned down the cause. If a preview URL does not load, check it with dig first, then try another browser or resolver before blaming the server.

Where you will meet it

Coolify builds its default app URL as http://<app-id>.<server-ip>.sslip.io, so an app is reachable seconds after its first deploy, before you own a domain. That step is in our timed Coolify install. Before you put a real domain on the server, read which ports Coolify needs open.

FAQ

What is the difference between sslip.io and nip.io?

In 2026, only the name. Both are run by the same maintainers on the same nameservers and support the same hostname formats. The sslip.io website redirects to nip.io.

Is sslip.io safe to use?

For test servers and previews, yes: it only returns the IP address that is already written in the hostname. Do not rely on it for production, and do not treat a sslip.io hostname as proof of who runs the server, because anyone can create one for any IP.

Can I get an SSL certificate for a sslip.io address?

Yes, a regular Let's Encrypt certificate per hostname through the HTTP-01 challenge. Wildcard certificates are not supported.

Does sslip.io work with private IP addresses?

Yes. A name such as 192.168.1.10.sslip.io resolves to the private address. Some routers and corporate DNS resolvers block answers that point at private ranges, so it may fail on those networks.