You pushed your static site to GitHub Pages, hooked up a custom domain on Namecheap, and immediately got smacked with a 404 or a broken SSL warning. Routing a registrar like Namecheap to GitHub’s static edge isn’t magic, but it does trip people up because you have to align a repository CNAME file with four distinct apex A records and a subdomain pointer.
Here is how I set up Namecheap Advanced DNS for both root and www domains, wire up the repo, verify ownership to prevent domain takeovers, and get Let’s Encrypt HTTPS working cleanly without downtime.

The Apex vs Subdomain DNS Challenge on GitHub Pages
GitHub Pages doesn’t hand you a dedicated VPS with a single static IP. Instead, traffic routes through an Anycast CDN cluster backed by four IPv4 and four IPv6 addresses. If you try to set a CNAME on your bare root domain (example.com), Namecheap will throw an error—RFC 1034 blocks CNAME records on zone apexes because they clash with SOA and NS records.
To handle both your root apex and the www subdomain properly, you need two distinct sets of records:
- Apex records (
@): Four A records pointing directly to GitHub’s Anycast IP addresses. - Subdomain records (
www): A single CNAME record pointing to your GitHub handle, likeusername.github.io.(or your org slug).
If you want a deeper look at why DNS handles root records this way across different providers, check out my breakdown on Configuring Root Domains in Namecheap DNS: A Record vs CNAME.
Step 1: Commit the CNAME File in Your Git Repository
GitHub Pages needs to know which incoming Host header belongs to your project. You configure this by dropping a plain-text file named CNAME into the root of your publishing branch (typically main, master, or gh-pages).
Create it from your terminal or editor:
echo "example.com" > CNAME
git add CNAME
git commit -m "chore: add custom domain CNAME for GitHub Pages"
git push origin mainKeep only one domain in this file. If you want your site to live on example.com and forward www.example.com, enter the apex (example.com). GitHub automatically serves a 301 redirect to the primary domain once both records are active.
One big catch: if you use a static site generator or bundler like Vite, Astro, or Hugo, drop the CNAME file inside your public/ or static/ folder. If you put it in the repo root without telling your bundler, your build script will overwrite the file on your next push.
Step 2: Configure Namecheap Advanced DNS Records
Log in to Namecheap, go to your Domain List, and click Manage next to your domain. Switch over to the Advanced DNS tab.
First, wipe out any default records Namecheap added out of the box—especially the “Parking Page” URL Redirects or placeholder CNAMEs. Leave any MX records alone if you already have email set up.
Add these four A records for GitHub’s Anycast network:
- Type:
A Record| Host:@| Value:185.199.108.153| TTL:Automatic(or30 min) - Type:
A Record| Host:@| Value:185.199.109.153| TTL:Automatic - Type:
A Record| Host:@| Value:185.199.110.153| TTL:Automatic - Type:
A Record| Host:@| Value:185.199.111.153| TTL:Automatic
Next, create the CNAME record for your www subdomain:
- Type:
CNAME Record| Host:www| Value:username.github.io.| TTL:Automatic
Swap out username with your actual GitHub username or organization name. You can double-check current IP ranges in the GitHub Pages custom domain documentation.
If you want full IPv6 routing, you can also add the four GitHub AAAA records:
Host: @ Value: 2606:50c0:8000::153
Host: @ Value: 2606:50c0:8001::153
Host: @ Value: 2606:50c0:8002::153
Host: @ Value: 2606:50c0:8003::153If you plan to split traffic later—like keeping static docs on GitHub Pages while pointing an app subdomain elsewhere—check out my guide on how to Point a Namecheap Subdomain to a Separate Server.
Step 3: Verify Custom Domain in GitHub Repository Settings
Head back to your repository on GitHub:
- Click Settings.
- In the sidebar, select Pages.
- Under Custom domain, type your domain (e.g.,
example.com). - Click Save.
GitHub kicks off a DNS check immediately, querying Namecheap’s nameservers to confirm the A and CNAME records route to its edge. You’ll see a yellow banner that says “DNS check in progress”.
After a few minutes, it should turn green with “DNS check successful”. If it shows an error about missing records, give Namecheap’s DNS caches 5 to 10 minutes to settle and try saving again.
Step 4: Secure the Site with HTTPS
Directly under the custom domain input in your Pages settings, you’ll see the Enforce HTTPS checkbox. GitHub issues free TLS certificates via Let’s Encrypt.
Immediately after saving your domain, this box is almost always greyed out with a message stating “Certificate is being provisioned” or “Unavailable for your site”. Don’t panic. Let’s Encrypt needs anywhere from 10 to 45 minutes to run its ACME HTTP-01 challenge against your repository.
Grab a coffee, come back in half an hour, and once the certificate finishes issuing, check Enforce HTTPS. GitHub will then automatically issue 301 redirects for any incoming plain HTTP traffic over to HTTPS, adhering to standard MDN Web Docs HTTP Redirection standards.
What I Ran: Verifying DNS Propagation from Terminal
Never rely on a browser window to debug DNS issues—browser caches and OS-level DNS resolvers will mislead you. Query the authoritative records directly with dig.
Check your apex A records against Google’s public resolver:
dig @8.8.8.8 example.com A +shortYou should see all four GitHub Anycast IPs in the answer section:
185.199.108.153
185.199.109.153
185.199.110.153
185.199.111.153Next, verify your www CNAME:
dig @8.8.8.8 www.example.com CNAME +shortYou should see your GitHub pages domain returned:
username.github.io.Finally, send a head request using curl to make sure GitHub responds with a valid TLS cert and the right response headers:
curl -Iv https://example.comLook for HTTP/2 200 (or HTTP/1.1 200 OK) alongside the Server: GitHub.com header.
Gotchas I Hit: Domain Takeovers and CI Wipes
These are three issues I’ve run into across various client deploys:
1. Domain Takeover Vulnerability
If your DNS points to GitHub Pages before you register the domain in your repo, anyone could theoretically create a repo, add your domain in their CNAME, and hijack your traffic. GitHub now enforces domain verification to stop this.
To secure your domain permanently, head to your GitHub account -> Settings -> Pages -> Add a domain. GitHub will give you a unique TXT record:
Type: TXT Record
Host: _github-pages-challenge-username
Value: 3a9f02c98d74e4c2b9a7183e8b0123Add this TXT record to Namecheap’s Advanced DNS tab, wait a minute, and click Verify on GitHub. This ties the domain exclusively to your account or org.
2. GitHub Actions Overwriting the CNAME
If you build with a CI pipeline (like GitHub Actions using peaceiris/actions-gh-pages or a custom deploy script), the build runner will blow away the CNAME file in the deployment branch unless you explicitly declare it. If your domain drops off your repo after every push, update your workflow step:
- name: Deploy to GitHub Pages uses: peaceiris/actions-gh-pages@v3 with: github_token: ${{ secrets.GITHUB_TOKEN }} publish_dir: ./dist cname: example.com3. Stale CAA Records Blocking Let’s Encrypt
If you previously configured custom DNS security rules on Namecheap, you might have left behind CAA (Certification Authority Authorization) records that restrict certificate issuance. If your CAA records don’t whitelist Let’s Encrypt, the automated cert provisioning will fail silently.
If “Enforce HTTPS” is still disabled after 24 hours, check Namecheap and add a CAA record permitting Let’s Encrypt:
Type: CAA Record | Host: @ | Value: 0 issue "letsencrypt.org"For a look at how DNS and SSL compare when hosting elsewhere, check out my guide on how to Point Namecheap Domain to Netlify.
Frequently Asked Questions
Why is “Enforce HTTPS” greyed out in my GitHub Pages settings?
The toggle stays disabled while Let’s Encrypt issues your certificate. GitHub only starts the ACME challenge once its background worker confirms all four A records and the CNAME match GitHub’s edge. This usually takes 15 to 30 minutes. If it’s still locked after a few hours, check for conflicting A records or restrictive CAA records in Namecheap.
Should I use example.com or www.example.com in my repo settings?
Use whichever one you want as your canonical URL. If you enter example.com in your repo settings and CNAME file, GitHub serves content on the apex and 301-redirects www.example.com to it (as long as your CNAME record is configured in Namecheap). If you prefer www, put www.example.com in the repo settings and the apex will redirect to www.
How long does Namecheap DNS take to resolve to GitHub Pages?
Namecheap DNS changes generally take 5 to 30 minutes with their default nameservers. If your local machine or ISP has an older TTL cached, it might take a bit longer locally. Querying 8.8.8.8 or 1.1.1.1 with dig will show you whether the records have propagated globally.
Can I run email on my Namecheap domain while using GitHub Pages?
Yes. GitHub Pages only touches your A, AAAA, and CNAME records. Your MX, SPF, DKIM, and DMARC records remain completely separate and can point to Namecheap Private Email, Google Workspace, or ProtonMail without any issues.
Next Steps
Now that your static site is running over HTTPS on your custom domain, make sure your domain’s email authentication records are locked down properly. Follow my walkthrough on how to Configure SPF, DKIM, and DMARC in Namecheap DNS.

