XiaTools

How to Configure DNS for Google Cloud Storage Custom Static Websites

Updated 10 Oct 2026

Configuring DNS for a custom static website hosted on Google Cloud Storage (GCS) requires mapping your domain name to an external HTTP(S) load balancer linked to your storage bucket. Because GCS buckets cannot directly serve custom domains over naked root domains or HTTPS without an intermediary load balancer, you must set up specific DNS records pointing to a global static IP address. Before making any modifications to your name servers, it is always a good idea to check your existing records using the DNS Lookup tool to ensure a clean starting state and verify propagation later.

Understanding the GCS Custom Domain Architecture

Hosting a static website on Google Cloud Storage involves more than just creating a public bucket. While GCS allows you to name your bucket after your domain (e.g., www.example.com), it does not natively provision SSL certificates or handle root domain traffic redirection without a Global External Application Load Balancer.

To serve your static site securely via HTTPS, the standard architecture consists of:

  1. A GCS bucket configured for public website hosting.
  2. A Global External HTTP(S) Load Balancer.
  3. A reserved global static IP address attached to the load balancer.
  4. An SSL certificate managed by Google Cloud or uploaded manually.
  5. DNS records at your domain registrar pointing to the load balancer's IP address.

Root Domains vs. Subdomains

When planning your DNS strategy, you must decide between a subdomain (like www.example.com or app.example.com) and a root apex domain (like example.com). Subdomains use standard CNAME records, which are straightforward to manage. Root domains require pointing to an IP address because standard DNS protocols do not allow a CNAME record at the root apex.

Step-by-Step DNS Configuration Guide

Follow these steps to configure your DNS records once your Google Cloud load balancer and bucket are provisioned.

Step 1: Reserve a Global Static IP Address

Before configuring DNS, ensure your Google Cloud project has a reserved global static IPv4 and IPv6 address assigned to your load balancer.

  1. Open the Google Cloud Console and navigate to VPC network > IP addresses.
  2. Click Reserve static address.
  3. Name your address, set the IP version to IPv4 (and optionally IPv6), and set the type to Global.
  4. Note down the generated IP address (for example, 192.0.2.1).

Step 2: Configure DNS Records at Your Registrar

Log in to your domain registrar or DNS hosting provider (such as Cloudflare, AWS Route 53, GoDaddy, or Google Cloud DNS). Note that provider-specific menu paths may vary slightly depending on your vendor.

Create the following records based on whether you are using a subdomain or a root domain:

Record Type Host / Name Value / Target TTL Purpose
A www 192.0.2.1 300 Points the www subdomain to your load balancer
AAAA www 2001:db8::1 300 Points IPv6 traffic to your load balancer
A @ (Root) 192.0.2.1 300 Points root apex domain to your load balancer
TXT _acme-challenge Managed by GCP 300 Used for automated SSL certificate validation (if applicable)

Step 3: Verify DNS Propagation

Once you save your DNS records, use command-line utilities or online tools to verify that they are resolving correctly across global nameservers.

Open your terminal and run a dig query to check your A record:

dig +short A www.example.com

Sample output:

192.0.2.1

You can also use nslookup on Windows PowerShell:

nslookup www.example.com

Sample output:

Server:  UnKnown
Address:  192.0.2.1

Name:    www.example.com
Address: 192.0.2.1

Testing Your Custom Domain Setup

After your DNS changes have fully propagated, test both HTTP and HTTPS access to your storage bucket using curl to ensure headers and redirects are working properly.

curl -I https://www.example.com

Expected response output:

HTTP/2 200 
content-type: text/html; charset=utf-8
server: ESF

If you see a 301 Moved Permanently or 404 Not Found, check your URL map settings in the Google Cloud Console to ensure the bucket backend service is properly attached.

Common Mistakes and How to Fix Them

  • Using CNAME records for the root domain: Attempting to create a CNAME record for example.com will break standard DNS compliance. Use an A record pointing directly to the global static IP, or use a DNS provider that offers CNAME flattening at the root.
  • Forgetting IPv6 Records: If you provisioned an IPv6 address for your load balancer but forgot to create the corresponding AAAA record, users on IPv6-only mobile networks may experience connection timeouts.
  • SSL Certificate Provisioning Delays: Google-managed SSL certificates can take anywhere from 10 minutes to several hours to provision. Ensure your DNS records are fully propagated before troubleshooting SSL handshake errors.
  • Bucket Permissions Misconfigured: If your DNS resolves correctly and your load balancer is active, but you receive a 403 Forbidden error, verify that the allUsers principal has the Storage Object Viewer role on your GCS bucket.

Configuration Checklist

  • GCS bucket created and configured for static website hosting.
  • Global External HTTP(S) Load Balancer provisioned.
  • Global static IPv4 (and IPv6) address reserved and attached.
  • DNS A and AAAA records added at your domain registrar.
  • Google-managed SSL certificate active and bound to the frontend.
  • DNS propagation verified using command-line tools.

Frequently asked questions

Can I point a custom domain directly to a GCS bucket without a load balancer?

No. Google Cloud Storage requires a Global External HTTP(S) Load Balancer to handle custom domains, SSL certificates, and root apex traffic mapping. Direct DNS CNAME mapping to storage.googleapis.com only works for subdomains if verified via Google Webmaster Central, and it does not support custom HTTPS certificates out of the box.

How long does DNS propagation take after updating my records?

DNS propagation typically takes anywhere from 5 minutes to a few hours, depending on the Time To Live (TTL) values set on your previous records and how quickly global recursive resolvers update their caches.

Why am I getting a 404 Not Found error after setting up my custom domain DNS?

A 404 error usually means your DNS is resolving correctly to the load balancer, but the load balancer cannot find the requested content. Verify that your URL map points to the correct backend bucket and that your default index page (such as index.html) is uploaded.

Do I need to configure both IPv4 and IPv6 DNS records?

It is strongly recommended. If you reserve both an IPv4 and an IPv6 address for your Google Cloud load balancer, you should create both `A` and `AAAA` DNS records to ensure optimal accessibility for all users.

How do I redirect my root domain to the www subdomain?

You can achieve this by setting up two separate bucket configurations or URL redirect rules within your Google Cloud load balancer. One bucket serves the main content, while the second bucket is configured solely as an HTTP redirect bucket pointing traffic from example.com to www.example.com.

Related articles

Free tools