GitHub Pages: InvalidDNSError and stalled TLS provisioning for a custom domain #209487
Replies: 3 comments
|
InvalidDNSError with clean dig results usually means one of these: Extra records: the apex should have only GitHub's four A records (and GitHub's AAAA, if any), and www should be one CNAME to .github.io. Any stale A/AAAA elsewhere fails the check. Then click Check again in Settings → Pages. If it still fails, open a ticket at support.github.com (Pages) with the domain, the repo, your authoritative dig output, and gh api repos/OWNER/REPO/pages. Share the domain here and I can run the outside checks. |
|
First thing I'd verify is whether you have CAA records on your domain. If you do and letsencrypt.org isn't explicitly listed, Pages can't provision the cert at all — it fails silently without giving you a useful error. Run dig CAA yourdomain.com and see what comes back. Second, if the domain is proxied through Cloudflare, the orange cloud needs to be grey while GitHub does its ownership check. Proxied mode returns Cloudflare IPs instead of GitHub's, so their provisioner sees the wrong thing even though your own lookups look fine. After re-adding the custom domain GitHub starts provisioning fresh but it genuinely can take the full 24 hours. If you're past that window and CAA records and proxying aren't the issue, there's no further self-serve troubleshooting available — you'd need to raise it directly at support.github.com since provisioning state isn't something that can be touched from the community side. |
|
Hi @FoxySonne, Thanks in advance! |
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
Hello,
GitHub Pages reports InvalidDNSError for a custom domain. TLS provisioning remains at “Certificate Requested”, and Enforce HTTPS is unavailable.
The documented DNS configuration and troubleshooting steps have been checked. Removing and re-adding the custom domain once did not resolve the issue.
What supported checks or escalation options are available when independent DNS lookups succeed but the Pages DNS check fails?
Project identifiers, detailed diagnostics and attachments have been removed for privacy.
Thank you.
All reactions