title | intro | product | versions | topics | shortTitle | |||||
---|---|---|---|---|---|---|---|---|---|---|
Verifying your custom domain for GitHub Pages |
You can increase the security of your custom domain and avoid takeover attacks by verifying your domain. |
{% data reusables.gated-features.pages %} |
|
|
Verify a custom domain |
When you verify a custom domain for your personal account, only repositories owned by your personal account may be used to publish a {% data variables.product.prodname_pages %} site to the verified custom domain or the domain's immediate subdomains. Similarly, when you verify a custom domain for your organization, only repositories owned by that organization may be used to publish a {% data variables.product.prodname_pages %} site to the verified custom domain or the domain's immediate subdomains.
Verifying your domain stops other GitHub users from taking over your custom domain and using it to publish their own {% data variables.product.prodname_pages %} site. Domain takeovers can happen when you delete your repository, when your billing plan is downgraded, or after any other change which unlinks the custom domain or disables {% data variables.product.prodname_pages %} while the domain remains configured for {% data variables.product.prodname_pages %} and is not verified.
When you verify a domain, any immediate subdomains are also included in the verification. For example, if the github.com
custom domain is verified, docs.github.com
, support.github.com
, and any other immediate subdomains will also be protected from takeovers.
{% data reusables.pages.wildcard-dns-warning %}
It's also possible to verify a domain for your organization{% ifversion ghec %} or enterprise{% endif %}, which displays a "Verified" badge on the organization {% ifversion ghec %}or enterprise{% endif %} profile{% ifversion ghec %} and, on {% data variables.product.prodname_ghe_cloud %}, allows you to restrict notifications to email addresses using the verified domain{% endif %}. For more information, see "AUTOTITLE{% ifversion ghec %}" and "AUTOTITLE{% endif %}."
You may be verifying a domain you own, which is currently in use by another user or organization, to make it available for your {% data variables.product.prodname_pages %} website. In this case, the domain will be immediately released from {% data variables.product.prodname_pages %} websites which are owned by other users or organizations. If you are attempting to verify an already verified domain (verified by another user or organization), the release process will not be successful.
{% data reusables.user-settings.access_settings %}
-
In the "Code, planning, and automation" section of the sidebar, click {% octicon "browser" aria-hidden="true" %} Pages. {% data reusables.pages.settings-verify-domain-setup %}
-
Wait for your DNS configuration to change, this may be immediate or take up to 24 hours. You can confirm the change to your DNS configuration by running the
dig
command on the command line. In the command below, replaceUSERNAME
with your username andexample.com
with the domain you're verifying. If your DNS configuration has updated, you should see your new TXT record in the output.dig _github-pages-challenge-USERNAME.example.com +nostats +nocomments +nocmd TXT
{% data reusables.pages.settings-verify-domain-confirm %}
Organization owners can verify custom domains for their organization.
{% data reusables.profile.access_org %} {% data reusables.profile.org_settings %}
-
In the "Code, planning, and automation" section of the sidebar, click {% octicon "browser" aria-hidden="true" %} Pages. {% data reusables.pages.settings-verify-domain-setup %}
-
Wait for your DNS configuration to change. This may be immediate or take up to 24 hours. You can confirm the change to your DNS configuration by running the
dig
command on the command line. In the command below, replaceORGANIZATION
with the name of your organization andexample.com
with the domain you're verifying. If your DNS configuration has updated, you should see your new TXT record in the output.dig _github-pages-challenge-ORGANIZATION.example.com +nostats +nocomments +nocmd TXT
{% data reusables.pages.settings-verify-domain-confirm %}