VPS迁移后网站仅可通过Google公共DNS访问的排查方法咨询
Hey André, let's walk through troubleshooting this problem step by step—since your site only works with Google Public DNS, the root cause is almost certainly tied to DNS propagation delays or misconfiguration. Here's where to start your investigation:
1. Verify DNS Propagation Across Different Servers
First, confirm if other DNS servers are still resolving your domain to the old VPS IP. Use these terminal commands to compare results:
- Check with your local DNS:
dig yourdomain.comornslookup yourdomain.com - Check with Google DNS (for reference):
dig yourdomain.com @8.8.8.8ornslookup yourdomain.com 8.8.8.8 - Test other public DNS providers too, like Cloudflare (
dig yourdomain.com @1.1.1.1) or Quad9 (dig yourdomain.com @9.9.9.9). If only Google DNS returns the new IP, propagation is incomplete or your DNS records aren't being picked up by other servers.
2. Double-Check Your Domain Registrar's DNS Settings
- Confirm you've updated your domain's A/AAAA records to point to the new VPS IP—it's easy to overlook a typo here!
- If you switched DNS providers during migration, ensure the NS (Name Server) records at your registrar are set to the new DNS server's addresses. Some registrar interfaces have hidden caching, so you might need to force a refresh even if you think changes are already saved.
- Check the TTL (Time to Live) value on your DNS records. If it was set to a high value (like 86400 seconds / 24 hours) before migration, stubborn caches might still hold onto the old IP—even after 6 days.
3. Inspect Your New VPS's DNS Service (If Self-Hosted)
If you're running a DNS server (e.g., BIND, NSD) on your new VPS:
- Validate your zone file for syntax errors:
named-checkzone yourdomain.com /etc/bind/zones/yourdomain.com.db(adjust the path to match your setup) - Ensure the DNS service is running without errors:
systemctl status bind9(Debian/Ubuntu) orsystemctl status named(CentOS/RHEL) - Check if the server is reachable on port 53 (DNS uses UDP/TCP 53):
telnet your-dns-server-ip 53ornc -zv your-dns-server-ip 53
4. Rule Out DNSSEC Issues
If your domain uses DNSSEC, make sure you've updated the DS records at your registrar to match the new DNS server's DNSSEC keys. Mismatched or outdated DS records will cause some DNS servers to reject your domain's records, leading to failed resolution.
5. Test Network Connectivity Beyond DNS
If some DNS servers resolve to the new IP but still can't access the site:
- Ping the new IP to confirm basic connectivity:
ping your-new-vps-ip - Use
mtr your-new-vps-ipto trace the network route and check for packet loss or blocked nodes. - Verify your new VPS's firewall (ufw, iptables, or cloud provider firewall) isn't blocking incoming traffic on ports 80/443—migration can sometimes reset firewall rules accidentally.
Start with the DNS propagation checks first—this is the most common reason for this kind of partial access issue. Let me know if you hit any snags along the way!
内容的提问来源于stack exchange,提问作者André

