GitHub Pages custom domain stuck on "DNS Check in Progress" for ~36 hours — DNS health check cannot resolve valid DNS #208857
🏷️ Discussion TypeQuestion 💬 Feature/Topic AreaPages BodyHello, I'm having an issue with a GitHub Pages custom domain that has been stuck on "DNS Check in Progress" for about 36 hours. Repository: The Pages deployment itself is working and the site is accessible over HTTP. DNS configurationThe domain uses REG.RU authoritative nameservers:
The apex domain returns exactly the four GitHub Pages A records: I checked the records using:
The authoritative servers consistently return the same four GitHub Pages IP addresses. There are no additional A records or AAAA records for the apex domain. I also checked for a wildcard record using a random subdomain; no wildcard response was returned. GitHub Pages health checkThe GitHub Pages health endpoint reports: "dns_resolves": false,
"is_valid_domain": true,
"is_apex_domain": true,
"should_be_a_record": true,
"is_pointed_to_github_pages_ip": false,
"is_valid": false,
"reason": "Domain's DNS record could not be retrieved. ... (InvalidDNSError)",
"responds_to_https": false,
"enforces_https": false,
"https_error": "peer_failed_verification",
"is_https_eligible": false,
"caa_error": "Dnsruby::ResolvTimeout"This is confusing because the DNS records are publicly resolvable, and both authoritative REG.RU nameservers consistently return the correct GitHub Pages A records. The HTTPSHTTP works and returns A normal HTTPS request fails certificate verification with: Using This appears consistent with the custom domain not yet having a valid GitHub Pages certificate provisioned. What I have already tried
The DNS configuration itself has not changed. QuestionsCould someone help determine why GitHub's Pages DNS health check cannot retrieve the DNS records even though both authoritative REG.RU nameservers consistently return the correct GitHub Pages A records? In particular:
Any help identifying what GitHub's DNS checker is actually timing out on would be appreciated. Thanks! |
Replies: 3 comments 2 replies
|
Your apex A records are correct, and the health-check output already names the layer that is failing: The usual causes, in the order worth checking:
If
If the second hangs and the first returns instantly, that is the failure mode, and it is worth a ticket with REG.RU rather than a change on your side.
Pages needs After any change, the health check is cached. Remove the custom domain under Settings -> Pages, save, then re-add it and save again to force a fresh check instead of waiting the cache out. Propagation alone will not re-trigger it. To verify from a resolver that is independent of your ISP: If clearing DNSSEC or fixing the CAA record unblocks the check, marking this as the answer will save the next person hitting the same |
|
All possible checks showed no problems with the configuration. A support ticket was submitted to technical support, which confirmed that everything was configured correctly and also confirmed that there was an issue with certificate issuance. They promised to look into it and keep me updated. Meanwhile, the "DNS Check in Progress" message has been there for more than 6 days. |
|
I re-checked Public resolvers still return the four GitHub Pages A records and HTTP serves What stands out from here: a direct CAA query to the authoritative nameserver times out: That matches the You already have a support ticket, which is the right call. While that is open, the workaround that got another .ru Pages domain (#209098) past the same reg.ru CAA timeout this week was: leave REG.RU as registrar, move DNS hosting to Cloudflare (free, records DNS-only — not proxied), recreate the four A records + www CNAME, wait until Happy to dig again if you try that path. |

I re-checked
heart-of-the-zone.ruthis morning (~08:20 UTC).Public resolvers still return the four GitHub Pages A records and HTTP serves
Server: GitHub.comwith 200. The Pages API still hashttps_certificate.state: "new".What stands out from here: a direct CAA query to the authoritative nameserver times out:
That matches the
caa_error: Dnsruby::ResolvTimeoutin your health output. A records can look fine on Google/Cloudflare while GitHub's checker fails on the CAA lookup against reg.ru.You already have a support ticket, which is the right call. While that is open, the workaround that got ano…