Heroku APEX域名映射故障:DNSSIMPLE配置ALIAS后无法访问
Let’s walk through the likely culprits and fixes to get your enjkey.com domain working properly, since your enjkey.fr setup is already functional as a reference.
1. Verify Heroku App Domain Binding First
The most common issue here is a missing domain association on Heroku’s side.
- Log into your Heroku Dashboard, navigate to the app linked to
thawing-cricket-4ciojhbsgdzsnnlz7zbd1mgt.herokudns.com. - Go to Settings > Domains and certificates and confirm that
enjkey.comis listed under "Domains". If it’s missing:- Add it via the UI, or run this command in your terminal:
heroku domains:add enjkey.com --app thawing-cricket-4ciojhbsgdzsnnlz7zbd1mgt
- Add it via the UI, or run this command in your terminal:
- Compare this to your
enjkey.frsetup—its associated Heroku app should haveenjkey.frproperly bound.
2. Validate the ALIAS Target’s DNS Resolution
Your ALIAS record points to a Heroku-provided DNS target, but we need to confirm that target is resolving correctly:
- Run this command to check the Heroku target for
enjkey.com:dig thawing-cricket-4ciojhbsgdzsnnlz7zbd1mgt.herokudns.com - Compare the output to the working target for
enjkey.fr:dig sleepy-thicket-82uxyrwqkhvsubs0pcw85rj0.herokudns.com
Both should return valid IPv4/IPv6 addresses. If the enjkey.com target doesn’t resolve, the issue lies with Heroku’s DNS setup for that app—not DNSimple.
3. Remove the Redundant ALIAS TXT Record
I notice you’ve added a manual TXT record for enjkey.com:
TXT enjkey.com ALIAS for thawing-cricket-4ciojhbsgdzsnnlz7zbd1mgt.herokudns.com 3600
DNSimple automatically handles ALIAS record resolution—this manual TXT entry is unnecessary and could potentially interfere with DNS parsing. Delete this record from your enjkey.com DNS settings (you can also remove the one for enjkey.fr while you’re at it, since it’s redundant there too).
4. Check DNS Propagation & Direct DNS Server Queries
Even with a 3600 TTL, DNS changes can take time to propagate across global servers. To bypass local/ISP caching and check what DNSimple is serving directly:
- Run this command to query DNSimple’s nameserver for
enjkey.com:dig @ns1.dnsimple.com enjkey.com - You should see the ALIAS record resolving to the same IPs as the Heroku target we checked earlier. If this works but public DNS still fails, wait for the TTL to expire (up to 1 hour) or flush your local DNS cache.
5. Validate SSL Certificate Setup
Since you’re accessing HTTPS URLs, a missing or invalid SSL certificate will block access:
- Check the certificate status for your
enjkey.comapp on Heroku:heroku certs:info --app thawing-cricket-4ciojhbsgdzsnnlz7zbd1mgt - Ensure the certificate is issued and valid. Heroku’s Automatic SSL will generate a certificate within an hour of adding the domain—if it’s missing, trigger a refresh via the Heroku UI or command line.
- If you’re seeing browser SSL errors, check the Security tab in your browser’s dev tools for specific details (e.g., "certificate name mismatch" or "no certificate found").
6. Rule Out MX Record Conflicts
While your MX records for 1&1 are valid, double-check that there are no hidden A records for enjkey.com (DNSimple’s ALIAS should take precedence, but conflicting records can cause issues). Your current config only has the ALIAS for the root domain, which is correct, but it’s worth confirming no other records are overriding it.
Start with steps 1, 2, and 3—these are the most likely fixes for your issue. If you still run into problems, share the output of the dig commands and Heroku domain/certificate status, and we can dig deeper.
内容的提问来源于stack exchange,提问作者ttt ttt

