I accidentally found out that a domain that I do not own forwards to my Discourse website. I installed Discourse over a month ago. I am not sure if that has something to do with the way I installed Discourse.

Whoever last used that Digital Ocean droplet (or whatever other hosting service you might use), still has their domain name pointing at what is now your server.

You need to configure let’s encrypt (just re-run discourse-setup and provide your email address when it asks for the let’s encrypt email), or get me to do it.


Thanks a lot. So encrypting is the only way to avoid such a thing happening?

You could find the person whose domain it is and ask them not to point it at your site. :slight_smile:

But seriously, there are lots of other reasons that you want to have your site encrypted anyway.


You have a good point. I honestly thought about getting my site encrypted right after the installation, but I thought that I should first get some content on it, and get it a little popular before I do so.

I think I’ll just follow the instruction provided here ‘Setting up Let’s Encrypt’, if I got stuck, I’d let you help me with that.

