Custom domain certificate stuck at VALIDATING_OWNERSHIP for 3+ hours
kangaglobal
HOBBYOP

5 days ago

Custom domain certificate stuck at VALIDATING_OWNERSHIP for 3+ hours

Project luminous-energy, production environment, service merry-youthfulness.

www.kangalearn.com has been at certificate status VALIDATING_OWNERSHIP since roughly 06:00 UTC on 30 September. The CNAME points to the target you issued (beklz9ra.up.railway.app), your own API reports the DNS record as PROPAGATED with the correct value, and dig confirms it resolves. The record is DNS-only at Cloudflare, not proxied.

Things I have already tried: adding the apex kangalearn.com (same result), deleting and re-adding the domain twice, redeploying the service, and deleting another custom domain to free a slot. All stayed at VALIDATING_OWNERSHIP.

Also: test.kangalearn.com on the same service previously had a VALID certificate. After I deleted and re-added it, it too now sits at VALIDATING_OWNERSHIP — so issuance appears broken for this service generally, not just for one domain.

Could you issue the certificates or tell me what is blocking them?

Awaiting User Response

1 Replies

Railway
BOT

5 days ago

The CNAME is correct, but the TXT ownership record is missing. Until ownership is verified, no certificate can be issued. At Cloudflare, add a TXT record with the name _railway-verify.www and the value railway-verify=7bc0ad345a072df1047742f71db93806fb7177acb3e8886289b7462b785cc485. Verification and issuance continue on their own once that record propagates.

Every time a domain is deleted and re-added, it gets a new verification token. That is why the other subdomain went back to validating after you re-added it: it also needs the TXT value now shown for it in the service's Settings, under Networking. Leave the domain entries in place from now on, so the values don't change again.


Status changed to Awaiting User Response Railway • 5 days ago


Welcome!

Sign in to your Railway account to join the conversation.

Loading...