1"use strict";(self.webpackChunk_N_E=self.webpackChunk_N_E||[]).push([[4402,10883,80065,70448],{10883:function(e,n,i){i.r(n),n.default={src:"/_next/static/media/magic-dns-naming.d6fd44e4.png",height:356,width:1280,blurDataURL:"data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAgAAAACCAMAAABSSm3fAAAACVBMVEVEfIRFd2NNd87erxANAAAAA3RSTlMLGRh+TxpxAAAACXBIWXMAAAsTAAALEwEAmpwYAAAAF0lEQVR4nGNgYGJiZGRkZGBgYGJiANEAAKMAD207z/EAAAAASUVORK5CYII=",blurWidth:8,blurHeight:2}},80065:function(e,n,i){i.r(n),n.default={src:"/_next/static/media/magic-dns-toggle.a34b50f9.png",height:324,width:1136,blurDataURL:"data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAgAAAACCAMAAABSSm3fAAAAFVBMVEX5+fj+/v7I1O/o6ezj6PXi4+e4x+mLwlXOAAAACXBIWXMAAAsTAAALEwEAmpwYAAAAFUlEQVR4nGNgZWaAACY2FkYGRkZGAAD0ABll1jM0AAAAAElFTkSuQmCC",blurWidth:8,blurHeight:2}},70448:function(e,n,i){i.r(n),n.default={src:"/_next/static/media/magic-dns.791ba793.png",height:538,width:1140,blurDataURL:"data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAgAAAAECAMAAACEE47CAAAAG1BMVEUaGho3Nzn///8kJSjFxcbIyMnMzM5FRUW4uLkKtM00AAAACXBIWXMAAAsTAAALEwEAmpwYAAAAIElEQVR4nGNggANGRkZGZmZmBkY2DhZWFhZWBnYmCAAAA5YASMtohJ0AAAAASUVORK5CYII=",blurWidth:8,blurHeight:4}},4402:function(e,n,i){i.d(n,{default:function(){return o}});var s=i(57437),a=i(95396),t=i(70448),r=i(80065),l=i(10883);function c(e){let n={a:"a",code:"code",em:"em",h2:"h2",li:"li",ol:"ol",p:"p",pre:"pre",strong:"strong",ul:"ul",...(0,a.a)(),...e.components},{ConsoleLink:i,Figure:c,Icon:o,Note:h,PricingPlanNote:m,Role:g}=n;return i||d("ConsoleLink",!0),c||d("Figure",!0),o||d("Icon",!0),h||d("Note",!0),m||d("PricingPlanNote",!0),g||d("Role",!0),(0,s.jsxs)(s.Fragment,{children:[(0,s.jsx)(n.p,{children:"MagicDNS automatically registers DNS names for devices in your network."}),"\n",(0,s.jsx)(m,{feature:"MagicDNS",plan:"all plans"}),"\n",(0,s.jsxs)(n.p,{children:["If you add a new web server called ",(0,s.jsx)(n.code,{children:"my-server"})," to your network, you no longer need to use its Tailscale IP: using the name ",(0,s.jsx)(n.code,{children:"my-server"})," in your browser's address bar or on the command line will work."]}),"\n",(0,s.jsx)(c,{src:t.default,alt:"Example of a browser window with 'my-server' and a port number in the address bar."}),"\n",(0,s.jsx)(h,{children:(0,s.jsxs)(n.p,{children:["MagicDNS does not require a ",(0,s.jsx)(n.a,{href:"/docs/reference/dns-in-tailscale#tailscale-dns-settings",children:"DNS nameserver"})," if running Tailscale v1.20 or later. Otherwise, your network must have ",(0,s.jsx)(n.strong,{children:"at least one DNS nameserver set"})," in the ",(0,s.jsx)(i,{id:"dns-page"})," page of the admin console. These nameservers will receive all DNS queries not handled by MagicDNS."]})}),"\n",(0,s.jsx)(n.h2,{id:"enabling-magicdns",children:"Enabling MagicDNS"}),"\n",(0,s.jsx)(n.p,{children:"Tailnets created on or after October 20, 2022 have MagicDNS enabled by default."}),"\n",(0,s.jsxs)(n.p,{children:["If not already enabled, you can enable MagicDNS in the ",(0,s.jsx)(i,{id:"dns-page"})," page of the admin console:"]}),"\n",(0,s.jsx)(c,{src:r.default,className:"bordered",width:"600",alt:"The 'Enable MagicDNS' button on the admin console."}),"\n",(0,s.jsx)(n.h2,{id:"accessing-devices-over-magicdns",children:"Accessing devices over MagicDNS"}),"\n",(0,s.jsxs)(n.p,{children:["Once MagicDNS is enabled, any device signed in to your network can access other devices by using their ",(0,s.jsx)(n.a,{href:"/docs/concepts/machine-names",children:"machine name"}),'. For example, if you have a server named "monitoring":']}),"\n",(0,s.jsxs)(n.ul,{children:["\n",(0,s.jsxs)(n.li,{children:["To SSH into it, run ",(0,s.jsx)(n.code,{children:"ssh username@monitoring"})]}),"\n",(0,s.jsxs)(n.li,{children:["To ping it, run ",(0,s.jsx)(n.code,{children:"ping monitoring"})]}),"\n",(0,s.jsxs)(n.li,{children:["To open it in your browser, type ",(0,s.jsx)(n.code,{children:"monitoring"})," in your address bar."]}),"\n"]}),"\n",(0,s.jsx)(h,{children:(0,s.jsxs)(n.p,{children:["Some CLI tools on macOS such as ",(0,s.jsx)(n.code,{children:"host"})," or ",(0,s.jsx)(n.code,{children:"nslookup"})," circumvent system DNS resolution, and will not work with MagicDNS. For example, ",(0,s.jsx)(n.code,{children:"host johns-iphone-6s"})," will not work on macOS, even if ",(0,s.jsx)(n.code,{children:"ping johns-iphone-6s"})," will."]})}),"\n",(0,s.jsx)(h,{children:(0,s.jsxs)(n.p,{children:["Devices that are ",(0,s.jsx)(n.a,{href:"/docs/features/sharing",children:"shared with you"})," are only accessible via MagicDNS on Tailscale v1.4 or later. You must also use the shared device's ",(0,s.jsx)(n.a,{href:"#fully-qualified-domain-names-vs-machine-names",children:"full domain name"}),". For example, ",(0,s.jsx)(n.code,{children:"ping webserver.example2.ts.net"}),"."]})}),"\n",(0,s.jsx)(n.h2,{id:"assigning-and-editing-machine-names",children:"Assigning and editing machine names"}),"\n",(0,s.jsxs)(n.p,{children:["MagicDNS automatically uses a device's ",(0,s.jsx)(n.a,{href:"/docs/concepts/machine-names",children:"machine name"})," as part of the DNS entry. If you change your device's name, the MagicDNS entry will automatically change."]}),"\n",(0,s.jsxs)(n.p,{children:["If you have a specific name you'd like to use to reference your device, then ",(0,s.jsx)(n.a,{href:"/docs/concepts/machine-names#renaming-a-machine",children:"edit the machine name"})," of the device."]}),"\n",(0,s.jsx)(n.h2,{id:"fully-qualified-domain-names-vs-machine-names",children:"Fully qualified domain names vs. machine names"}),"\n",(0,s.jsxs)(n.p,{children:["Under the hood, MagicDNS generates a ",(0,s.jsx)(n.strong,{children:"fully qualified domain name"})," for every device on your Tailscale network (known as a tailnet). The fully qualified domain name is made up of two parts:"]}),"\n",(0,s.jsxs)(n.ol,{children:["\n",(0,s.jsxs)(n.li,{children:["A ",(0,s.jsx)(n.a,{href:"/docs/concepts/machine-names",children:(0,s.jsx)(n.strong,{children:"machine name"})}),", which you can change."]}),"\n",(0,s.jsxs)(n.li,{children:["Your ",(0,s.jsx)(n.a,{href:"/docs/concepts/tailnet-name#tailnet-dns-name",children:(0,s.jsx)(n.strong,{children:"tailnet DNS name"})}),". You can find your tailnet DNS name in the ",(0,s.jsx)(i,{id:"dns-page"})," page of the admin console."]}),"\n"]}),"\n",(0,s.jsx)(c,{src:l.default,alt:"An example of 'monitoring.yak-bebop.ts.net' as a fully qualified domain name. The 'monitoring' segment is identified as the machine name. The 'yak-bebop.ts.net' segment is identified as the tailnet name."}),"\n",(0,s.jsx)(h,{children:(0,s.jsxs)(n.p,{children:["Previously, you might have used a ",(0,s.jsx)(n.a,{href:"/docs/concepts/tailnet-name",children:"tailnet name"})," ending in ",(0,s.jsx)(n.code,{children:".beta.tailscale.net"}),". If so, migrate to the new tailnet name ending in ",(0,s.jsx)(n.code,{children:".ts.net"}),". Support for the existing ",(0,s.jsx)(n.code,{children:"beta.tailscale.net"})," name ended on ",(0,s.jsx)(n.strong,{children:"September 13, 2024"}),"."]})}),"\n",(0,s.jsx)(n.p,{children:"The table below shows how some example machine names and domains combine to create the full domain name."}),"\n",(0,s.jsxs)("table",{children:[(0,s.jsx)("thead",{children:(0,s.jsxs)("tr",{children:[(0,s.jsx)("th",{children:"Machine Name"}),(0,s.jsx)("th",{children:"Tailnet Name"}),(0,s.jsx)("th",{children:"Fully Qualified Domain Name"})]})}),(0,s.jsxs)("tbody",{className:"text-xs md:text-sm",children:[(0,s.jsxs)("tr",{children:[(0,s.jsx)("td",{children:"monitoring"}),(0,s.jsx)("td",{children:"yak-bebop.ts.net"}),(0,s.jsx)("td",{children:(0,s.jsxs)("code",{children:[(0,s.jsx)(n.p,{children:"monitoring.yak-bebop."}),(0,s.jsx)("wbr",{}),(0,s.jsx)(n.p,{children:"ts.net"})]})})]}),(0,s.jsxs)("tr",{children:[(0,s.jsx)("td",{children:"johns-iphone-6s"}),(0,s.jsx)("td",{children:"tailab12.ts.net"}),(0,s.jsx)("td",{children:(0,s.jsxs)("code",{children:[(0,s.jsx)(n.p,{children:"johns-iphone-6s.tailab12."}),(0,s.jsx)("wbr",{}),(0,s.jsx)(n.p,{children:"ts.net"})]})})]}),(0,s.jsxs)("tr",{children:[(0,s.jsx)("td",{children:"free-form"}),(0,s.jsx)("td",{children:"example.ts.net"}),(0,s.jsx)("td",{children:(0,s.jsxs)("code",{children:[(0,s.jsx)(n.p,{children:"free-form.example."}),(0,s.jsx)("wbr",{}),(0,s.jsx)(n.p,{children:"ts.net"})]})})]})]})]}),"\n",(0,s.jsxs)(n.p,{children:["Full domain names can be cumbersome to type, so when you enable MagicDNS, Tailscale automatically adds ",(0,s.jsx)(n.a,{href:"/docs/reference/dns-in-tailscale#tailscale-dns-settings",children:"search domains"})," to your network. With these search domains you only need to type the machine name to access a device."]}),"\n",(0,s.jsxs)(n.p,{children:["For the ",(0,s.jsx)(n.em,{children:"yak-bebop"})," network, ",(0,s.jsx)(n.strong,{children:"the following two commands are equivalent"}),":"]}),"\n",(0,s.jsx)(n.pre,{children:(0,s.jsx)(n.code,{className:"language-shell",children:"ping monitoring\nping monitoring.yak-bebop.ts.net\n"})}),"\n",(0,s.jsxs)(n.p,{children:["In most situations, you'll want to use the machine name. But for security reasons, accessing ",(0,s.jsx)(n.a,{href:"/docs/features/sharing",children:"devices shared with you"})," requires using the full domain name."]}),"\n",(0,s.jsxs)(n.p,{children:["You can find the full domain name of any device in your network by opening its page from the ",(0,s.jsx)(i,{id:"machines-page"})," page of the admin console."]}),"\n",(0,s.jsx)(n.h2,{id:"disabling-magicdns",children:"Disabling MagicDNS"}),"\n",(0,s.jsxs)(n.p,{children:["MagicDNS can be disabled for your whole network by toggling the same button you used to enable it in the ",(0,s.jsx)(i,{id:"dns-page"})," page of the admin console."]}),"\n",(0,s.jsx)(n.p,{children:"If you are experiencing trouble with MagicDNS on a particular device and wish to disable it only there, the current solution is to stop accepting network DNS settings in general."}),"\n",(0,s.jsxs)(n.p,{children:[(0,s.jsx)(n.strong,{children:"On Linux"}),", stop accepting DNS with:"]}),"\n",(0,s.jsx)(n.pre,{children:(0,s.jsx)(n.code,{className:"language-shell",children:"tailscale set --accept-dns=false\n"})}),"\n",(0,s.jsxs)(n.p,{children:[(0,s.jsx)(n.strong,{children:"On macOS"}),", stop accepting DNS by selecting the Tailscale menu bar icon. From here, select ",(0,s.jsx)(n.strong,{children:"Preferences"}),", and then you can uncheck ",(0,s.jsx)(n.strong,{children:"Use Tailscale DNS settings"})," from the menu."]}),"\n",(0,s.jsxs)(n.p,{children:[(0,s.jsx)(n.strong,{children:"On Windows"}),", stop accepting DNS by holding ",(0,s.jsx)(n.code,{children:"SHIFT"})," while right-clicking on the Tailscale system tray icon, and deselecting ",(0,s.jsx)(n.strong,{children:"Use Tailscale DNS"})," from the menu."]}),"\n",(0,s.jsx)(n.p,{children:"In the future, we will have robust enough DNS configuration and resolution logic that disabling MagicDNS separately will never be necessary. At this point, the toggle will disappear."}),"\n",(0,s.jsxs)(n.h2,{id:"removing-the-betatailscalenet-nameserver",children:["Removing the ",(0,s.jsx)(n.code,{children:"beta.tailscale.net"})," nameserver"]}),"\n",(0,s.jsxs)(n.p,{children:["Support for the legacy ",(0,s.jsx)(n.code,{children:"*.beta.tailscale.net"})," nameserver ended on ",(0,s.jsx)(n.strong,{children:"September 13, 2024"}),". If you haven't already, migrate your tailnet to use the ",(0,s.jsx)(n.a,{href:"/docs/concepts/tailnet-name#tailnet-dns-name",children:"tailnet DNS name"})," format nameserver. If you are no longer using the ",(0,s.jsx)(n.code,{children:"beta.tailscale.net"})," nameserver, you can delete it. Once deleted, you cannot recover it."]}),"\n",(0,s.jsxs)(n.p,{children:["You need to be an ",(0,s.jsx)(g,{children:"Owner, Admin, or IT admin"})," of a tailnet to remove the ",(0,s.jsx)(n.code,{children:"beta.tailscale.net"})," nameserver."]}),"\n",(0,s.jsxs)(n.ol,{children:["\n",(0,s.jsxs)(n.li,{children:["Open the ",(0,s.jsx)(i,{id:"dns-page"})," page of the admin console."]}),"\n",(0,s.jsxs)(n.li,{children:["Under ",(0,s.jsx)(n.strong,{children:"Nameservers"}),", look for the nameserver whose name ends in ",(0,s.jsx)(n.code,{children:".beta.tailscale.net"}),", for example, ",(0,s.jsx)(n.code,{children:"yak-bebop.beta.tailscale.net"}),". (If you don't find a ",(0,s.jsx)(n.code,{children:".beta.tailscale.net"})," nameserver, there is nothing to delete.)"]}),"\n",(0,s.jsxs)(n.li,{children:["Select the ",(0,s.jsx)(o,{name:"ellipsis"})," menu and then select ",(0,s.jsx)(n.strong,{children:"Delete"}),"."]}),"\n",(0,s.jsxs)(n.li,{children:["Confirm that you want to delete the ",(0,s.jsx)(n.code,{children:"beta.tailscale.net"})," nameserver and then select ",(0,s.jsx)(n.strong,{children:"Delete"}),"."]}),"\n"]})]})}function o(e={}){let{wrapper:n}={...(0,a.a)(),...e.components};return n?(0,s.jsx)(n,{...e,children:(0,s.jsx)(c,{...e})}):c(e)}function d(e,n){throw Error("Expected "+(n?"component":"object")+" `"+e+"` to be defined: you likely forgot to import, pass, or provide it.")}}}]);
Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.