Public launch 13 October 2026. Every plan opens that day.

See the plans

Put a reverse proxy in front of anything on your network

A website can answer its name here and pass every request to an address you give. It is how something that was never meant to be public gets a domain, a certificate and a front door, without being moved.

The name, the certificate and the renewal live here. What is behind the reverse proxy keeps speaking plain HTTP on whatever port it already uses.

What it is good for

Things that already work, and need a front door.

An appliance on your network

A device or a service with a web interface, no certificate of its own and no intention of getting one. It gets a name and HTTPS without being touched.

Software you did not write

Something that listens on a port and expects to be reached directly. Give it a domain instead of a port number people have to remember.

A service on another machine

A second server on the same network that should answer a name on this one, without moving the application or splitting the DNS.

Something mid-migration

Point the name here while the real move happens behind it, and change the address when you are ready.

A long-lived connection

WebSocket upgrades are passed through and the connection is kept open, so a live dashboard or a chat service behaves as it would directly.

HTTPS for something that has none

The certificate is issued and renewed here. What is behind the reverse proxy never needs to know TLS exists.

What the website sends on

The headers an application behind a proxy expects.

  • The original host, so an application that builds links from the request builds the right ones.
  • The visitor's address, as both X-Real-IP and X-Forwarded-For, so logs and rate limits see a visitor rather than this server.
  • The scheme, as X-Forwarded-Proto, so an application knows the visitor arrived over HTTPS even though it was spoken to in plain HTTP.
  • Upgrade requests, with the hop-by-hop headers rewritten per request rather than passed blindly, which is what makes WebSockets work.
  • Responses as they come, with buffering off, so an application that streams keeps streaming.

The restrictions, and why

An administrator sets it, and it points at an address.

This is the one runtime a customer cannot choose, because the thing it can be pointed at is the thing that makes it useful.

A reverse proxy forwards requests from the public internet to somewhere this server can reach. That includes things on this machine that were never meant to be public, and things inside a private network that are only safe because nothing outside can reach them. Letting a customer type an address into that field would be letting a customer decide what the server exposes.

  • Administrators only. Creating a proxy website, or changing where one points, is refused for anybody else.
  • A numeric address and an explicit port, over http or https. Hostnames are deliberately not accepted: a name resolved later could silently move an approved proxy to another host the day somebody edits a DNS record.
  • An origin, and nothing else. No credentials, no path, no query, no fragment. What is approved is a destination, not a request.
  • A routable address. Unspecified, multicast and link-local addresses are refused rather than written into a configuration file.

Those rules are narrow on purpose. The value of this field is that it reaches things, so the only safe version of it is one where what it reaches was written down exactly, by somebody entitled to write it.

What it is not

It does not make the thing behind it yours to manage.

A proxy website is a name, a certificate and a destination. Whatever answers at that destination is still somebody else's program on somebody else's schedule: this panel does not start it, back it up, monitor it or keep it running, and a reverse proxy pointing at something switched off is a website that returns an error.

If you want the thing itself managed here, a Node.js application or a container website is the runtime that does that, and the runtimes page compares all five.

Every feature

Your servers, with nothing on them counted.

Dashmox launches 13 October 2026: the whole panel free on one server, and Pro for up to five. Neither counts websites, mailboxes, DNS zones or customer accounts.