Fake Site in my Domain Apex

Answer these questions to help the Community help you with Security questions.

What is the domain name?
cornopaez.com

Have you searched for an answer?
Yes – but I don’t even know how to search for this specific issue.

Please share your search results url:
https://cornopaez[.]com

When you tested your domain, what were the results?
The website served is not the one I configured.

Describe the issue you are having:
When visiting this URL (https://cornopaez[.]com) the site served is not the correct one. However, visiting the full site (https://www[.]cornopaez[.]com) results in the correct website being served.

What error message or number are you receiving?
N/A

What steps have you taken to resolve the issue?

  1. Verified the DNS configuration but I could still have something misconfigured.
  2. Created a new redirect rule so that it matches the domain apex with and without HTTPS

Was the site working with SSL prior to adding it to Cloudflare?
N/A

What are the steps to reproduce the error:

Have you tried from another browser and/or incognito mode?

Please attach a screenshot of the error:
No need – visiting the URLs above is enough.

Hello team –

I suspect I was not clear about what I need assistance with in this post. Let me rectify that.

My site is hosted through Heroku, I own the domain cornopaez.com, and Cloudflare is my registrar. I set up the DNS for my site as best as I could and things had been working fine since I migrated to Cloudflare as my registrar.

However, a couple of weeks ago I got notifications from Google Search Console that someone had been added to my domain as an owner. I gave the boot to those folks in the Search Console (my account is not compromised there) but I noticed that there were lots of errors for pages that Google could not crawl. Upon closer inspection, I discovered that my apex domain URL https://cornopaez.com showed a completely different site from what it is supposed to.

I have tried the following to rectify this situation:

  • Verified the DNS config to make sure nothing has changed
  • In Heroku, I made sure that the apex domain is registered to my account there – it wasn’t previously for some reason
  • In Cloudflare I’ve turned on Proxy for both apex domain and www
  • In Cloudflare I’ve created a static route to redirect traffic from the apex domain to www
  • In Cloudflare I’ve created a bulk redirect policy to redirect all traffic from apex domain to www

These steps have yielded no positive results – the bad website is still safely anchored to my apex domain.

What else can I do to rectify this?

Please advise.

This topic was automatically closed 15 days after the last reply. New replies are no longer allowed.