Guide

Home Assistant remote access with your own domain

Home Assistant Cloud is the easiest way in, and it funds the project. If you would rather run it yourself, this guide gets you to https://ha.yourname.uk.app with a reverse proxy, dynamic DNS kept up to date by Home Assistant itself, and a proper certificate.

Updated · Checked against Home Assistant 2026.9 (OS and Container) · 6 min read

Home Assistant port
80 on HA OS (2026.8+), 8123 on Container
Port to forward
443 to your reverse proxy
Settings page
Settings → System → Network
Time
30–45 minutes

Pick your route first

RouteWorks behind CGNATVoice assistants and cloud webhooksCost
Home Assistant Cloud (Nabu Casa)YesYes, built inMonthly subscription
VPN (WireGuard, Tailscale)Tailscale: yesNoFree
Reverse proxy + your own name (this guide)No – needs a public IPYes, with extra set‑upA domain

If only you and your household use the phone app, a VPN is simpler and exposes nothing. Carry on here if you want a public HTTPS address – for family members who won’t run a VPN, for webhooks from other services, or because you like having your own name. Check first that your connection isn’t behind CGNAT.

Which port Home Assistant listens on

From Home Assistant 2026.8 the web server settings moved from configuration.yaml into the interface, under Settings → System → Network → HTTP server. At the same time, new Home Assistant OS installs started listening on port 80 instead of 8123. Container installs still use 8123, and upgraded systems keep the port they had. Check the Server port field on that page and use that number wherever this guide says “HA port”.

Upgraded from an older version?

If you still have an http: block in configuration.yaml, Home Assistant imported it on upgrade and raised a repair asking you to remove it. Do that before changing anything here, or you will be editing settings that are ignored.

1. Put a reverse proxy in front

You have two common choices:

  • A proxy elsewhere on your network – Caddy or Nginx Proxy Manager on another machine, a NAS or a Proxmox container. The HTTPS guide covers both. Point ha.yourname.uk.app at http://<HA address>:<HA port> and make sure WebSockets are allowed (automatic in Caddy; tick Websockets Support in Nginx Proxy Manager).
  • A proxy app on Home Assistant OS itself – the Nginx Proxy Manager or NGINX SSL proxy apps (add‑ons have been called apps since Home Assistant 2026.2). Handy if HA is your only server.

Then tell Home Assistant to trust the proxy, or it will block every request that comes through it with 400: Bad Request:

  1. Go to Settings → System → Network and find HTTP server.
  2. Turn on Trust X‑Forwarded‑For.
  3. In Trusted proxies, add the proxy’s LAN address, for example 192.168.1.30. For a proxy app running on Home Assistant OS itself, add 172.30.33.0/24, the network HA’s apps use.
  4. Save. Home Assistant restarts, and an administrator has to confirm the new settings within five minutes or it rolls them back – so keep the page open.

Watch out

When you enter a range, use the network address (192.168.1.0/24), not a host address with a mask (192.168.1.30/24). Home Assistant’s documentation is explicit about this.

2. Forward the port on your router

Forward TCP 443 – and 80 if your proxy uses the HTTP‑01 certificate method – to the proxy’s LAN address. Do not forward Home Assistant’s own port. Router steps: BT, Virgin Media, Sky, TP‑Link, OpenWrt.

3. Let Home Assistant keep your name up to date

Home Assistant is always on, so it can run the dynamic DNS updater itself with the built‑in RESTful Command integration. In the uk.app dashboard, create a DDNS token for your name (My names → your name → Dynamic DNS), then add it to secrets.yaml:

secrets.yaml
ukapp_ddns_token: "paste-your-64-character-ddns-token"
configuration.yaml
rest_command:
  ukapp_ddns:
    url: "https://ddns.uk.app/nic/update?hostname=home.yourname.uk.app"
    username: "yourname.uk.app"
    password: !secret ukapp_ddns_token
    timeout: 20

Restart Home Assistant, then create an automation (Settings → Automations & scenes → Create automation, then Edit in YAML) that calls it every five minutes and at start‑up:

Automation (YAML mode)
alias: Update uk.app dynamic DNS
triggers:
  - trigger: time_pattern
    minutes: "/5"
  - trigger: homeassistant
    event: start
actions:
  - action: rest_command.ukapp_ddns
mode: single

The request leaves your house through your broadband, so the service records your public IP. Each call returns good <ip> when it changed the record and nochg <ip> otherwise. Test it from Developer tools → Actions by running rest_command.ukapp_ddns; the response appears below.

In the uk.app DNS settings, add a CNAME record ha → home.yourname.uk.app, so the proxy name follows the same address.

Tip

If you run Home Assistant behind a commercial VPN for outbound traffic, don’t use this method – it would publish the VPN’s address. Run the updater on your router instead.

4. Tell Home Assistant its external address

  1. In Settings → System → Network, under Home Assistant URL, set Internet to https://ha.yourname.uk.app.
  2. Leave Local network on automatic, or set it to http://<HA address>:<HA port>.
  3. In the Companion app on your phone, open the app’s settings, choose your server, and set its external (internet) URL to the same address. Add your home Wi‑Fi name so the app uses the local address at home.

5. Lock it down

  • Turn on multi‑factor authentication for every user who signs in from outside: click your name at the bottom of the sidebar, open Security, and enable Authenticator app.
  • In Settings → System → Network → HTTP server, turn on Enable IP banning and set a low number of Login attempts before ban, such as 5. Banned addresses land in ip_bans.yaml; delete a line there to lift a ban. This only works properly once trusted proxies are set, or HA would ban the proxy itself.
  • Don’t put anything private in the www folder: files served under /local/ need no login.
  • Keep Home Assistant and its apps updated; security fixes arrive in regular releases.

6. Check it from outside

  1. Does the name point home? Look up ha.yourname.uk.app with the DNS lookup and compare the A record with the address on ip.uk.app. After a change, the propagation checker shows which resolvers still have the old one.
  2. Is the port open from the internet? Run the open port checker against port 443. “Open” means your router forwards it and something answers. “Closed” or “timed out” means the forward, the device’s own firewall or CGNAT is in the way.
  3. Is the certificate right? The SSL checker shows whether the certificate covers the exact name, who issued it and when it expires.
  4. Test from outside for real. Turn Wi‑Fi off on your phone and open the address over mobile data. Testing from inside your own network can give misleading results.

If it doesn’t work

  • 400: Bad Request – the proxy isn’t in Trusted proxies, or Trust X‑Forwarded‑For is off. Check the Home Assistant log: it names the address it refused.
  • The page loads but stays on “Connection lost” – WebSockets aren’t passing through the proxy.
  • Works on mobile data, not at home – your router doesn’t do NAT loopback. Let the Companion app use the internal URL on your home Wi‑Fi.
  • Certificate warnings – the proxy hasn’t got a certificate for the exact name. Check with the SSL checker.
  • Port shows as closed – check double NAT and CGNAT.

A name for your next idea

Give your website, home server or next project a memorable address: yourname.uk.app. Choose your name and check availability before registering.

Find your name

Questions people ask

Is it safe to expose Home Assistant to the internet?

Behind an HTTPS reverse proxy, kept updated, with multi‑factor authentication and IP banning turned on, it is a common and reasonable set‑up. Exposing its HTTP port directly without HTTPS is not.

Do I still need DuckDNS?

No. Any dynamic DNS service that speaks the dyndns2 protocol works with a RESTful command. DuckDNS remains a free option if you don’t want your own name.

Can Alexa or Google Assistant use this instead of Nabu Casa?

Yes, but it needs manual set‑up of the Alexa or Google integration, including developer accounts, and a publicly reachable HTTPS address like the one in this guide. Home Assistant Cloud does it for you.

Why did my port change to 80?

New Home Assistant OS installs listen on port 80 from 2026.8. Container installs still use 8123. The value is under Settings → System → Network → HTTP server.

Sources and further reading

We check each guide against the vendor’s own documentation and support forums. If something has changed on your firmware, tell us.

Partners