自定义域名的Amazon S3静态网站显示“IP地址未找到”故障求助
Hey there, let's walk through the most likely causes of your issue and break down actionable steps to get your site up and running—since you're new to AWS hosting and DNS, I'll keep things straightforward:
1. First Check: DNS Propagation Status
Since you just switched your domain's nameservers to Route53, DNS propagation can take anywhere from a few minutes to 24 hours (it's global, so some regions might update faster than others). Here's how to verify:
- Run the command
nslookup scottreganchimneysweeping.co.ukin your terminal. Look at the "Name Server" section—if it still shows your old registrar's nameservers, propagation isn't complete yet. Wait a bit longer, or double-check that you copied all 4 Route53 nameservers exactly to your domain registrar's DNS settings (even a single typo here breaks everything). - Also run
dig scottreganchimneysweeping.co.uk A—it should return your CloudFront distribution's domain (not a raw IP) since you're using an alias record. If it returns nothing or an error, the DNS record isn't resolving correctly.
2. Validate CloudFront Distribution Settings
CloudFront misconfigurations are a common culprit here:
- Alternate Domain Names (CNAMEs): Make sure you've added
scottreganchimneysweeping.co.ukto this field in your CloudFront distribution. If not, CloudFront will reject requests to your custom domain, leading to errors. - Origin Domain Name: Ensure you're using the S3 static website endpoint (e.g.,
scottreganchimneysweeping.co.uk.s3-website-<your-region>.amazonaws.com), not the S3 REST API endpoint (e.g.,scottreganchimneysweeping.co.uk.s3.amazonaws.com). The REST endpoint doesn't support static website routing and will cause permission issues. - Default Root Object: Confirm you've set this to
index.html(or your site's main entry file). Without this, accessing the root domain might return a 403, though your "IP not found" error points more to DNS first. - SSL Certificate: Double-check that you selected the correct SSL certificate in CloudFront (note: CloudFront only accepts certificates issued in the
us-east-1region, even if your bucket is elsewhere). Also ensure the certificate's status is "Issued" and covers your domain.
3. Verify Route53 Record Configurations
- A Alias Record: Make sure the alias target is your CloudFront distribution's domain (e.g.,
d123xyz.cloudfront.net), not the S3 bucket's domain. Also check that there are no conflicting A/AAAA records for your domain in Route53—only one alias record pointing to CloudFront should exist. - SSL Validation CNAME: If you used DNS validation for your SSL certificate, confirm the CNAME record provided by AWS exists in your Route53 hosted zone and matches exactly (both the name and target values). A missing or incorrect record could prevent the certificate from being issued, though this usually leads to SSL errors rather than IP not found.
- NS/SOA Records: Ensure the NS records in your Route53 hosted zone are identical to the ones you entered at your domain registrar. Even a single mismatched character will break DNS resolution.
4. Check S3 Bucket Permissions & Setup
- Bucket Name: Confirm your S3 bucket name exactly matches your domain (
scottreganchimneysweeping.co.uk)—S3 static website hosting requires this for proper routing. - Bucket Policy/OAI: If you're using a CloudFront Origin Access Identity (OAI) (recommended for security), make sure your S3 bucket policy grants access to the OAI. If you're using public access (less secure), ensure the bucket has the correct public read permissions for static website content. Without proper permissions, CloudFront can't fetch your content, leading to 403 errors once DNS is working.
5. Rule Out Browser Caching
Chrome sometimes caches old DNS records, so try accessing your site in an incognito window. You can also flush your local DNS cache:
- Windows: Run
ipconfig /flushdnsin Command Prompt (as admin) - Mac: Run
sudo dscacheutil -flushcache; sudo killall -HUP mDNSResponderin Terminal
Start with the DNS propagation check first—this is the most common issue when you've just switched nameservers. Once DNS resolves correctly, you can troubleshoot any remaining 403 issues with CloudFront or S3 permissions.
内容的提问来源于stack exchange,提问作者c.gooderham94

