Custom domain certificate stuck at "Validating Ownership" for over a week despite fully correct DNS
jambuveda
FREEOP

12 days ago

My custom domain app.jambuveda.com (project: jambuveda_app, service: jambuveda-app) has had its TLS certificate stuck in VALIDATING_OWNERSHIP for more than a week.

What I've verified:

DNS is correct and fully propagated: app.jambuveda.com CNAME → ls0175ko.up.railway.app (confirmed via independent DNS lookups against Google's public resolver, not just Railway's own status page).

No conflicting A/AAAA/TXT records on the same hostname.

No CAA record on the root domain blocking any certificate authority.

The Railway dashboard itself reports the DNS record status as "Propagated."

I've triggered "Retry Certificate" multiple times over several days with no change and no error message shown.

I also tried removing and re-adding the domain once already — it briefly generated a new required CNAME target, DNS was updated to match immediately, but the certificate got stuck in the same VALIDATING_OWNERSHIP state again.

Attempting to remove the domain again via the API times out after 180 seconds with no effect (domain remains attached).

This looks like a stuck certificate-issuance job on Railway's backend for this specific domain, not a DNS or configuration issue on my end. Could someone from the team or with experience on a similar case take a look, or suggest what else to check?

Solved

1 Replies

Railway
BOT

12 days ago

Your CNAME is correct, but the domain hasn't passed ownership verification because the TXT verification record is missing. We don't find any TXT record published at the verification host, and the certificate can't be issued until that check passes. Retrying the certificate or removing and re-adding the domain won't get past this step.

At your DNS provider, add a TXT record with the host _railway-verify.app (your provider adds your domain after it) and set its value to exactly railway-verify=ce3febbf3532d250d717356b6529034620d505cdc2b359f97d3b0e5dcabc8b44. You can also copy both from the domain's DNS records in the service's Settings, Networking section.

After that record propagates, verification and certificate issuance continue on their own. Keep the existing domain entry in place, because removing it creates a new CNAME target and a new token.


Status changed to Awaiting User Response Railway • 12 days ago


Railway
BOT

5 days ago

This thread has been marked as solved automatically due to a lack of recent activity. Please re-open this thread or create a new one if you require further assistance. Thank you!

Status changed to Solved Railway • 5 days ago


Welcome!

Sign in to your Railway account to join the conversation.

Loading...