DNSMentor

Supported provider

Hetzner DNS, in the same place as everything else.

Does DNSMentor support Hetzner?

Yes. DNSMentor manages Hetzner DNS through its API, showing its zones alongside the other 25 supported providers in a single estate view. Every Hetzner change goes through the same 56 pre-flight checks, approval policy, independent verification and tamper-evident audit trail as every other provider.

Connecting Hetzner

  1. Create the credential in Hetzner Hetzner Console → open the project holding the DNS zones → Security → API tokens → Generate API token, with Read & Write permission. The token is shown once and never again. Note that it is scoped to the whole project, not to DNS: the same token can create and destroy servers, volumes and networks in that project, so put DNS zones in a project of their own if you can. A Read-only token will connect and list zones successfully and then fail every change with 'token_readonly'.
  2. Add the connection in DNSMentor Go to Admin → Providers & API keys, choose Hetzner, and paste the credential. DNSMentor stores it encrypted and strips it from every log and export.
  3. Sync the estate DNSMentor discovers every zone the Hetzner account holds and imports every record in them. This is a read operation — nothing is written to any zone.
  4. Group by client and start working Assign the imported domains to client portfolios, and the estate view, health scoring, checks and audit trail apply from that point on.

What Hetzner asks you for

The exact fields DNSMentor needs, and where in Hetzner to create them. Every secret is encrypted at rest and stripped by name from logs, exports and the audit trail.

API Token secret

Hetzner Console → open the project holding the DNS zones → Security → API tokens → Generate API token, with Read & Write permission. The token is shown once and never again. Note that it is scoped to the whole project, not to DNS: the same token can create and destroy servers, volumes and networks in that project, so put DNS zones in a project of their own if you can. A Read-only token will connect and list zones successfully and then fail every change with 'token_readonly'.

Project name not secret

Optional label shown against this connection in DNSMentor. The API does not expose the project's name, so without it the connection is identified only as a Hetzner project.

The sharp edge in Hetzner's API

Every provider API has one behaviour that catches integrations out. This is Hetzner's, and DNSMentor's adapter is written around it — the sort of thing you would otherwise discover during a migration.

That the adapter targets the right API at all. Hetzner retired the standalone DNS console in May 2026 and moved DNS into the Cloud API — every older integration guide names `dns.hetzner.com`, which now redirects.

What you get on top of the Hetzner console

One estate, not one provider

Hetzner zones sit beside every other provider your clients came with, grouped by the client who pays for them and searchable in one place.

56 checks before apply

The Hetzner console will accept a second SPF record or an MX pointing at an address without comment. DNSMentor will not.

Approval and audit

A second pair of eyes where policy requires it, and a hash-chained record of who changed what — neither of which a provider console offers.

Hetzner questions

Can I manage Hetzner DNS alongside my other providers?

Yes. DNSMentor connects Hetzner through its API and shows its zones in the same estate view as every other provider you connect — 26 are supported in total. Your engineers work in one interface instead of switching between provider portals, and the same checks, approval policy and audit trail apply regardless of which provider a domain happens to be with.

What credentials does DNSMentor need for Hetzner?

DNSMentor needs API Token, Project name for Hetzner. Hetzner Console → open the project holding the DNS zones → Security → API tokens → Generate API token, with Read & Write permission. The token is shown once and never again. Note that it is scoped to the whole project, not to DNS: the same token can create and destroy servers, volumes and networks in that project, so put DNS zones in a project of their own if you can. A Read-only token will connect and list zones successfully and then fail every change with 'token_readonly'.

Does DNSMentor move my zones away from Hetzner?

No. Your zones stay hosted at Hetzner and remain authoritative there. DNSMentor reads and writes through the Hetzner API, so nothing about your resolution path changes, and if you stop using DNSMentor the zones carry on exactly as they are.

Does DNSMentor validate Hetzner changes before applying them?

Yes. All 56 checks run against the zone as it would exist after the change, whichever provider hosts it. The change is then simulated, routed for approval if policy requires it, written through the Hetzner API after re-reading live state, and independently verified in public DNS afterwards.

Other providers DNSMentor manages

Connect Hetzner in about five minutes.

Paste one credential, sync, and see every zone in that account. It is a read operation — nothing is written until somebody presses apply.

No card. No trial clock. UK-hosted, and we will tell you which providers we have actually proven before you ask.

Last updated