Custom domain cert stuck at VALIDATING_OWNERSHIP for 8+ hours — DNS is correct
wccrurl
PROOP

a month ago

Hi Railway support,

My custom domain hera.masegoinc.com has been stuck at VALIDATING_OWNERSHIP

for over 8 hours despite all DNS records being correctly configured and

propagated.

Project ID: fe836a51-0f66-4710-bb74-ebb31f45ae18

Service ID: d98754fc-6672-4f9d-b547-a04558b4f1dc

Domain ID: 243fcccc-207c-4da8-8605-6a4c0b535cab

Domain: hera.masegoinc.com

Current DNS state (verified via Google DNS 8.8.8.8 and Cloudflare

1.1.1.1):

CNAME: hera.masegoinc.com8axw3cod.up.railway.app

TXT: _railway-verify.hera.masegoinc.com → railway-verify=railway-verif

y=9148da0960dd78f4655df797944bea3f42c18d8e0e66b0a48386833190360451 ✓

CAA: No CAA records on masegoinc.com (Let's Encrypt is not blocked)

Your own API confirms CNAME is PROPAGATED and currentValue matches

requiredValue:

certificateStatus: CERTIFICATE_STATUS_TYPE_VALIDATING_OWNERSHIP

CNAME currentValue: 8axw3cod.up.railway.app

CNAME requiredValue: 8axw3cod.up.railway.app

CNAME status: DNS_RECORD_STATUS_PROPAGATED

The Railway-generated domain (hera-production-e408.up.railway.app) works

fine — the service is healthy and serving traffic. It's only the custom

domain cert that won't issue.

Note: this domain was deleted and re-created twice during setup (CNAME

target changed from irjfdudp → sqxtfwn0 → 8axw3cod). The final CNAME

(8axw3cod) has been stable and matching for several hours. It's possible

the earlier deletions left stale state in the cert pipeline.

Could you check the cert issuance queue for this domain and manually

retrigger if needed? Happy to provide any additional information.

Thanks,

Robert

Solved$10 Bounty

Pinned Solution

Try removing the domain from Railway and any associated DNS records from your DNS provider. Wait for ~10-15 mins, then re-add everything back.

See if that fixes it.

1 Replies

Status changed to Awaiting Railway Response Railway about 1 month ago


Status changed to Open Railway about 1 month ago


Try removing the domain from Railway and any associated DNS records from your DNS provider. Wait for ~10-15 mins, then re-add everything back.

See if that fixes it.


Status changed to Solved 0x5b62656e5d 16 days ago


Welcome!

Sign in to your Railway account to join the conversation.

Loading...