Apex TLS certificate fails with Railway internal error
rodriguez7
HOBBYOP

a month ago

Custom domain: permitracker.com

The production application and www.permitracker.com are healthy, but the apex custom domain cannot obtain a valid certificate. Railway progressed through certificate validation, then changed to:

Failed to issue TLS certificate

An internal error occurred. Please retry or contact support.

Verified diagnostics:

  • Apex CNAME points only to Railway's generated target: 7fi481na.up.railway.app
  • Railway ownership TXT record is present and correct
  • Authoritative Namecheap DNS, 1.1.1.1, and 8.8.8.8 all resolve through Railway
  • No conflicting A or AAAA record remains
  • No restrictive CAA record and no DNSSEC delegation
  • HTTP reaches the Railway application when certificate verification is bypassed
  • Public TLS still presents DNS:*.up.railway.app, so browsers correctly reject permitracker.com
  • The dashboard Try Again action was used once on 2026-07-16 around 13:34 CEST and failed immediately with the same internal error

The DNS conflict that originally existed was removed on 2026-07-15, and clean DNS has been globally visible for approximately 17 hours. Please retry/reissue the apex certificate from Railway's side or investigate the certificate provisioning state. I can provide project, service, environment, custom-domain IDs, and the verification token privately if needed.

$10 Bounty

1 Replies

Railway
BOT

a month ago

This thread has been opened as a bounty so the community can help solve it.

Status changed to Open Railway about 1 month ago


Your root domain (permitracker.com), is currently working and accessible on my end, with valid certs, and correct DNS setup. It might be just a caching issue, try to access it from an incognito tab or use a different device/network

image.png

Attachments


Welcome!

Sign in to your Railway account to join the conversation.

Loading...