3 ms·
UPDATE: Github responded with the following... (GitHub Developer Support) Apr 4, 2:52 AM UTC Hi Scott, Thanks for reaching out, and sorry for the trouble!
by scottndecker 8y ago
UPDATE: Github responded with the following...
(GitHub Developer Support)
Apr 4, 2:52 AM UTC
Hi Scott,
Thanks for reaching out, and sorry for the trouble!
GitHub Pages doesn't currently have a verification process when configuring a new custom domain. We chose this design due to its low friction, but unfortunately it also means that any GitHub user can claim any custom domain, so long as it isn't already in use on another repository.
When you downgraded your account to GitHub Free, GitHub Pages for your private repository was disabled, and this released your custom domain for potential use by other GitHub users. While the risk of another user accidentally claiming your specific custom domain is low, we've experienced trouble lately with opportunistic ne'er-do-wells strategically claiming custom domains they find to be available.
Our engineering team is currently investigating potential improvements to prevent this in future. In the meantime, we're taking the precaution of performing manual verification in any cases such as yours. A quick way we can verify your ownership of the domain would be for you to add a TXT record to your domain's DNS configuration.
When you create the TXT record, please include the following value:...
and from there gave me a value to put in my DNS to verify ownership.
Not a great experience today but at least they responded and are working to remedy the situation (which I still believe was a huge ball drop on their part in terms of both communication and implementation).
- cypherpunks01 8y agoI had this exact same problem too on March 26th and my first response was poor, the rep said "I'm sorry to hear that your domain was taking [sic] over by another user" and tried to get me to verify my own domain with them. I told them that I was disappointed with the response and then another support rep wrote a much more helpful and detailed reply: "Sorry for the trouble you've had with this. GitHub Pages doesn't currently have a way of linking ownership of a domain to a GitHub account. When you point your domain's DNS records towards GitHub IPs all we can tell on our side is that the domain can be attached to a Pages site—but we can't tell which one, or which account it's owned by, until the domain is linked in the repository settings page. When you leave your domain pointing towards GitHub, but don't attach it to a live Pages site, any other GitHub user can link your domain to a Pages site without any further verification. All we can see from your domain are the GitHub IPs listed in the DNS records, so we have no way of linking it to a specific account. As this domain is now attached to a Pages site, we have to consider that the person currently using it is the legitimate owner, whether that be via a domain ownership transfer, the domain has expired and someone else has purchased it, or other means. We use this setup to make it quick and easy to get started with GitHub Pages, without having to perform even more complex DNS verification steps or waiting for propagation time. We are aware that it can be abused however and are looking at possible solutions, but we don't have anything to announce at this time. If you would like to use this domain with GitHub Pages again yourself then you will need to follow the verification process. If you don't want to use this domain with GitHub Pages then you can safely remove any DNS records that point towards GitHub to stop the malicious site displaying at your domain. However you may have to verify it with us again in future if you would like to use GitHub Pages again. Let us know if you have any further questions, or would like to continue verifying your ownership of your domain with us."
- applecrazy 8y agoIt's great to hear that at least they have some mitigation for this issue so it never happens again. It's nice that you brought awareness to this issue so a process change could be made at GH HQ.