Custom domain stuck at VALIDATING_OWNERSHIP ~1h, DNS propagated, no CAA/DNSSEC, ACME path clean
kowl64
FREEOP

9 days ago

Project: DriverStandard (d0dde47b-b0f3-4c14-88eb-ec37ac37873d)

Environment: production (2a60cb78-4143-41eb-949b-196f77977d28)

Service: driverstandard (fb48632b-bd56-43b5-827d-ff7ce2a2acd2)

Custom domain: app.driverstandard.app (06e0168e-09c2-4635-bba7-7a18a7abd84b)

Required CNAME target: 3s1j8gh7.up.railway.app

certificateStatus has been CERTIFICATE_STATUS_TYPE_VALIDATING_OWNERSHIP since

approximately 10:26 BST on 26/09/2026. The edge serves the *.up.railway.app

wildcard certificate, so browsers show a certificate-name mismatch on the

production hostname.

Verified on our side


  • Your API reports the CNAME as DNS_RECORD_STATUS_PROPAGATED, and

    requiredValue == currentValue == 3s1j8gh7.up.railway.app.

  • DNS is on Cloudflare, record is DNS-only (grey cloud), NOT proxied.

  • dig +short CNAME app.driverstandard.app @1.1.1.1 -> 3s1j8gh7.up.railway.app.

    Authoritative check against dawn.ns.cloudflare.com returns the same.

  • No CAA records exist on driverstandard.app or app.driverstandard.app, so

    Let's Encrypt is not blocked.

  • DNSSEC is NOT enabled (no DS, no DNSKEY), so it is not a DNSSEC failure.

  • The ACME challenge path is reachable and not redirected:

    http://app.driverstandard.app/.well-known/acme-challenge/<random>  -> 404
    
    http://app.driverstandard.app/api/health                           -> 301 (expected)

    Response carries an x-railway header, confirming your edge is answering.

  • openssl s_client with -servername app.driverstandard.app returns

    subject CN=*.up.railway.app, i.e. routing reaches Railway but the

    domain-specific certificate has not been issued.

  • We called customDomainIssueCertificate for this domain id. It returned

    true, but the status did not change.

  • The API exposes only ONE dnsRecord for this domain, purpose

    DNS_RECORD_PURPOSE_TRAFFIC_ROUTE. No _railway-verify TXT record is

    advertised. Several forum threads were resolved by adding such a TXT

    record — if one is required here, please tell us the exact host and value

    and we will add it immediately.

  • No incident listed on status.railway.com.

Note on retries


The domain was removed and re-added ONCE earlier, which regenerated the CNAME

target (7civ3q22 -> 3s1j8gh7). Cloudflare was updated to match and the API now

confirms the match. We have NOT repeated this, to stay well inside the

Let's Encrypt duplicate-certificate rate limit.

Request


Please investigate what is blocking issuance server-side and clear it, or tell

us the exact additional DNS record required. Happy to provide anything else.

0 Replies

Status changed to Awaiting Railway Response Railway • 9 days ago


Welcome!

Sign in to your Railway account to join the conversation.

Loading...