Custom domain book.23amblesideretreat.co.za is stuck on "Waiting for DNS update" for the TXT record.
23ambleside
HOBBYOP

a month ago

Custom domain book.23amblesideretreat.co.za is stuck on "Waiting for DNS update" for the TXT record. Both records are correct and confirmed authoritative on all four of the zone's nameservers (ns1/ns3.tld-ns.net, ns2/ns4.tld-ns.com) — my registrar supplied dig output against each. The value matches exactly: railway-verify=4f833895c6b02255fdc9b76ab1e6b584e96c2d8fb0c11f9d8f7136008c30aae7. The zone was re-published today (SOA serial 2026090401). There had been an inconsistency under the previous serial, so I suspect a cached negative on your side. Could you force a re-verification without regenerating the token? Project efficient-warmth, service Booking-manager.

Solved

3 Replies

Status changed to Awaiting Railway Response Railway • about 1 month ago


a month ago

Your DNS records are correct: the CNAME is propagated and the TXT verification token at _railway-verify.book.23amblesideretreat.co.za matches exactly. The verification workflow stalled while the earlier DNS inconsistency was in place and never re-ran after your fix. We have started a certificate re-issuance for this domain, which should complete within a few minutes.


Status changed to Awaiting User Response brody • about 1 month ago


brody

Your DNS records are correct: the CNAME is propagated and the TXT verification token at `_railway-verify.book.23amblesideretreat.co.za` matches exactly. The verification workflow stalled while the earlier DNS inconsistency was in place and never re-ran after your fix. We have started a certificate re-issuance for this domain, which should complete within a few minutes.

23ambleside
HOBBYOP

a month ago

The domain is still serving your platform's default certificate, not one for our domain.

Certificate presented at book.23amblesideretreat.co.za:

Subject CN: *.up.railway.app

Subject Alt Names: *.up.railway.app, up.railway.app

Issuer: Let's Encrypt YE1

Valid: 29 Jul 2026 – 27 Oct 2026

Serial: 06:DA:79:BB:56:1D:A3:EF:EB:0E:75:1C:A2:1A:BD:39:99:FE

No SAN covers book.23amblesideretreat.co.za, so browsers report a domain mismatch and refuse the connection. The validity dates show this certificate predates the re-issuance you began today by several weeks — so no new certificate has been issued or deployed for our domain.

Please confirm the status of the ACME order for this domain and whether validation failed. Our DNS is confirmed correct on your side, and there are no CAA records on the zone restricting issuance.


Status changed to Awaiting Railway Response Railway • about 1 month ago


Railway
BOT

a month ago

The certificate re-issuance has completed successfully: the domain is now verified, the certificate status is valid, and edge routing is responding normally (HTTP 200). The *.up.railway.app wildcard certificate you observed was served from a cached TLS session before the new certificate finished deploying. If your browser still shows the mismatch, close all tabs to that domain and reconnect, or test in an incognito window, so a fresh TLS handshake picks up the new certificate.


Status changed to Awaiting User Response Railway • about 1 month ago


Status changed to Solved 23ambleside • about 1 month ago


Welcome!

Sign in to your Railway account to join the conversation.

Loading...