Troubleshooting
The symptoms actually encountered, and what causes them nine times out of ten.
5 minUpdated
Verification fails
| Symptom | Most likely cause |
|---|---|
| The TXT record is not found | Propagation is not finished. Wait and retry. Also check the name is _zyre-verify and not _zyre-verify.your-site.com — many panels append the domain themselves. |
| The origin file is not accepted | Open https://your-site.com/.well-known/zyre-origin-verify in a browser. If you see a redirect, a styled error page, or nothing, we see the same. The .well-known folder is hidden: turn on the matching option in your file manager. |
| The origin is refused as "not public" | The declared address is a private (LAN) address or points back at Zyre itself. Give your server's public address, the one the whole world can reach. |
After the cutover
All my visitors get a 503 error
First check emergency lockdown (Tools → Protection): that is its exact signature. A red banner should show at the top of the dashboard if it is on. Otherwise your origin server has stopped answering — check the Monitoring screen.
My site shows the Zyre dashboard
Your DNS points at us but no origin is declared for this domain — so we have nowhere to relay. Set the origin under Tools → Infrastructure. It is the only case where the cutover breaks something, and it takes a minute to fix.
www does not work / certificate error on www
The www version has no record of its own, or it still points elsewhere. See The www version.
Only some of my visitors seem protected
Almost always a leftover AAAA (IPv6) record: IPv6 visitors go straight to you. Delete it. Otherwise, propagation is simply not finished yet.
Unexpected blocks
A form, an admin page or an integration that stops working after the cutover is most likely a false positive. Ask the blocked person for the incident reference shown, find the row under Threats, and report it. See False positives.
Payment notifications stopped arriving
Your payment providers send notifications to your domain, so they cross the firewall. Their addresses are never banned automatically, and the account owner is emailed if one is refused. Also check no emergency lockdown is on: it refuses everything, including those notifications.
Figures that seem to contradict
- "Threats" and "Blocked requests" differ: a site in observation mode logs threats without blocking them. The gap is expected, and a banner says so.
- Traffic looks lower than in my analytics: Zyre only counts what reaches the firewall. Visits served by a third-party cache, or arriving through an address that does not route through us, are not there.
- A different period gives a different total: both counters and table follow the selector at the top. Check it is on the window you think.
This page did not answer your question?
Contact us