Safe DNS record management for Namecheap domains. Fetch, add, remove, backup, and restore DNS records with automatic safety checks and dry-run mode. Prevents accidental DNS record wipeout via the Namecheap API's destructive setHosts method.
Safe DNS record management for Namecheap domains. Fetch, add, remove, backup, and restore DNS records with automatic safety checks and dry-run mode. Prevents accidental DNS record wipeout via the Namecheap API's destructive setHosts method.
Safe wrapper around the Namecheap API for DNS operations. Prevents accidental record wipeout by always fetching existing records first and merging changes.
⚠️ Why This Skill Exists
The Namecheap API's setHosts method replaces ALL DNS records for a domain. One wrong API call = your entire DNS config is gone. This skill:
✅ Always fetches existing records first
✅ Merges new records with existing ones (unless explicitly replacing)
✅ Shows a diff preview before applying changes
✅ Auto-backups before every change
✅ Supports dry-run mode for safe testing
✅ One-command rollback from backups
Setup
1. Install dependencies
cd ~/.openclaw/workspace/skills/namecheap-dns
npm install
export NAMECHEAP_API_KEY="your-api-key-here"export NAMECHEAP_USERNAME="your-username"export NAMECHEAP_API_USER="your-username"# Usually same as username
Usage
Verify DNS and detect ghost records
⚠️ IMPORTANT: Run this first!
./namecheap-dns.js verify example.com
This command compares DNS records visible to the Namecheap API with actual live DNS records (via dig). It will warn you about "ghost records" that exist in DNS but are invisible to the API (email forwarding, URL redirects, etc.).
List current DNS records
./namecheap-dns.js list example.com
Note: This only shows records visible to the API. Use verify to see ALL records including those managed by Namecheap subsystems.
Add records (safe merge)
# Add a single TXT record
./namecheap-dns.js add example.com \
--txt "mail.example.com=v=spf1 include:mailgun.org ~all"# Add multiple records at once
./namecheap-dns.js add example.com \
--txt "mail=v=spf1 include:mailgun.org ~all" \
--cname "email.mail=mailgun.org" \
--mx "mail=10 mxa.mailgun.org"# Dry-run (preview changes without applying)
./namecheap-dns.js add example.com \
--txt "test=hello" \
--dry-run
# Force override safety check (if you know ghost records can be deleted)
./namecheap-dns.js add example.com \
--txt "test=hello" \
--force
Safety: The skill automatically checks for "ghost records" before making changes. If detected, it will refuse to proceed unless you use --force.
Remove records
# Remove by host + type
./namecheap-dns.js remove example.com \
--host "old-record" \
--type"TXT"# Dry-run first
./namecheap-dns.js remove example.com \
--host "old-record" \
--type"TXT" \
--dry-run
Backup & Restore
# Create manual backup
./namecheap-dns.js backup example.com
# List available backups
./namecheap-dns.js backups example.com
# Restore from latest backup
./namecheap-dns.js restore example.com
# Restore from specific backup
./namecheap-dns.js restore example.com \
--backup "example.com-20260213-114500.json"
Review the diff, then run without --dry-run to apply.
Known Limitations
⚠️ The Namecheap API is Destructive
The Namecheap domains.dns.setHosts API method replaces ALL DNS records for a domain. There is no "add one record" or "update one record" endpoint. Every change requires:
Fetch all existing records (getHosts)
Modify the list
Upload the entire list (setHosts)
This skill handles this for you by always fetching first and merging changes.
🔍 Ghost Records: The Hidden Danger
Problem:domains.dns.getHosts does NOT return all DNS records. Records managed by Namecheap subsystems are invisible to the API:
Email Forwarding — MX, SPF, and DKIM records
URL Redirect — A/CNAME records for domain parking/redirects
Third-party integrations — Records added through Namecheap's dashboard for services
Since setHostsreplaces all records, using the API can silently delete these hidden records.
🛡️ How This Skill Protects You
verify command — Compares API records with actual live DNS (via dig) and warns about ghost records
Automatic safety check — Before any add, remove, or restore, the skill checks for ghost records
Refuses to proceed — If ghost records are detected, the operation is blocked (unless --force is used)
Clear warnings — Shows exactly which records will be lost if you proceed
DNS snapshots in backups — Captures actual DNS state via dig, not just API state
When to Use --force
Only use the --force flag when:
You've manually verified the ghost records are no longer needed
You're intentionally removing email forwarding or URL redirects
You understand and accept that those records will be deleted
Never use --force blindly. Always run verify first to see what will be lost.
Example: The Production Incident
This skill was created after adding Mailgun DNS records via the API wiped out Namecheap's email forwarding records. The email forwarding MX/SPF/TXT records were invisible to getHosts, so the fetch-merge-write pattern deleted them.
Now, the skill would have:
Detected the ghost records during verify
Refused to proceed without --force
Shown exactly which email forwarding records would be deleted