AWS Route 53 DNS解析失败:Mycroft Nutrition域名切换至AWS端点故障排查
Let’s break down the key areas to investigate now that you’ve set up the custom domain and corresponding DNS records:
Confirm DNS Propagation is Complete
DNS changes don’t take effect instantly—TTL (Time To Live) settings (typically 30 minutes to 24 hours) control how long servers cache old records. Run these commands locally to check your current resolution:nslookup mycroftnutrition.com dig mycroftnutrition.comYou can also use a global DNS checker tool to verify records are updated across regions. If your TTL was set to a high value (like 24 hours), you might need to wait for cached records to expire.
Double-Check API Gateway Custom Domain Mapping
It’s easy to overlook the critical base path mapping step when setting up a custom domain in API Gateway:- Navigate to your API Gateway custom domain settings
- Ensure you’ve mapped the root path (
/) or your desired path to yourdevAPI stage - Confirm the ACM certificate linked to the custom domain is in the
us-east-1region (required for API Gateway custom domains) and shows a status of "Issued"
Inspect SSL/TLS and Browser Error Details
If you’re seeing browser errors, open developer tools (F12) and check the Network tab for specific issues:- Is there an SSL certificate mismatch? This occurs if the ACM certificate doesn’t cover
mycroftnutrition.comor its subdomains - Are you using a supported TLS version? API Gateway requires TLS 1.2 or higher—older clients/browsers might fail to connect
- Ensure your DNS record type matches what API Gateway provides: use either an
Arecord (pointing to CloudFront static IPs) or aCNAMErecord (pointing to the API Gateway domain target), don’t mix record types
- Is there an SSL certificate mismatch? This occurs if the ACM certificate doesn’t cover
Verify Request Routing to Lambda
Even if your original API endpoint works, the custom domain might not be routing requests correctly:- Enable access logging in API Gateway and check CloudWatch logs to see if requests are reaching the gateway
- Review Lambda’s CloudWatch logs to confirm invocations happen when you access the custom domain
- Check CORS settings if you’re accessing the domain from a frontend: your API’s CORS configuration should explicitly allow
mycroftnutrition.comas an allowed origin
Eliminate Heroku DNS Residues
Make sure all old Heroku-related DNS records (CNAME, A, ALIAS) have been removed from your domain’s DNS settings. Usedig +trace mycroftnutrition.comto trace the full resolution path and spot any lingering old records that could cause conflicts.
内容的提问来源于stack exchange,提问作者Benjamin Lee

