12 days ago
Hi Railway team,
A custom domain on my service is stuck at CERTIFICATE_STATUS_TYPE_VALIDATING_OWNERSHIP and never issues a certificate, even though ownership is already verified and DNS is correct.
DETAILS
Project: trigunung-web (97aef8b2-a729-4247-8c81-aa3bac8695a2)
Environment: production (cf01f7e7-ce7e-4f87-86b3-535564966552)
Service: web (026cc015-8598-48b5-a218-ccc814ff20c4)
Custom domain: www.trigunung.com (c2399517-3ec1-4374-b357-6f61acc7ffab)
Target: cm2zxep0.up.railway.app
Target port: 8080 (service listens on $PORT = 8080, confirmed in logs)
CURRENT STATUS (railway domain status) Sync status: ACTIVE Verified: yes Certificate status: CERTIFICATE_STATUS_TYPE_VALIDATING_OWNERSHIP
DNS (authoritative: nova.dns-parking.com, and confirmed via 8.8.8.8) www.trigunung.com. CNAME cm2zxep0.up.railway.app. _railway-verify.www.trigunung.com. TXT "railway-verify=e5d52cf744b970290289e6ea9774fa250360ad84aa4d1cef472fdfa5383075e7" cm2zxep0.up.railway.app resolves to 69.46.46.49
EVIDENCE THE EDGE SEES THE HOST curl --resolve www.trigunung.com:80:69.46.46.49 http://www.trigunung.com/ -> HTTP 301 redirect to https://www.trigunung.com/ curl --resolve www.trigunung.com:443:69.46.46.49 https://www.trigunung.com/ -> TLS handshake succeeds but serves the wildcard certificate CN=*.up.railway.app -> "subjectAltName does not match www.trigunung.com", so the custom cert was never issued.
WHAT I ALREADY TRIED
Waited about 3 hours after DNS fully propagated (Google DNS confirms the CNAME).
Deleted and re-created the custom domain. It verified immediately (Verified: yes) and issued a new target (cm2zxep0), DNS was updated accordingly. Still stuck.
Set the target port explicitly to 8080 via: railway domain update www.trigunung.com --port 8080
railway domain certificate retry -> refused with: "Certificate retry is only available after certificate issuance fails. Current status: CERTIFICATE_STATUS_TYPE_VALIDATING_OWNERSHIP." So it never transitions to a failed state I can retry from.
ROOT CAUSE FOUND (from railway domain status --json) Your DNS check is reading a STALE value for the CNAME:
"dnsRecords": [{ "recordType": "DNS_RECORD_TYPE_CNAME", "name": "www", "requiredValue": "cm2zxep0.up.railway.app", "currentValue": "trigunung.com", <-- stale, this was the value BEFORE I changed it "status": "DNS_RECORD_STATUS_REQUIRES_UPDATE" }]
The authoritative nameservers (nova/cosmos.dns-parking.com) and public resolvers (8.8.8.8) all return the correct value with a 3600s TTL:
www.trigunung.com. 3600 IN CNAME cm2zxep0.up.railway.app.
The previous record had a 14400s TTL, so I believe your resolver cached it before I made the change and will not refresh until that TTL expires.
Re-running railway domain update www.trigunung.com --port 8080 did not force a fresh DNS lookup - currentValue stayed at "trigunung.com".
REQUEST Please force a fresh DNS re-check for this custom domain (bypassing your resolver cache) so the certificate can be issued. The service is healthy and serving traffic fine on web-production-35802.up.railway.app.
Thank you.
UPDATE - 23 September 2026, 15:06 WIB
Your DNS checker now reads the record correctly and consistently. The earlier flapping between "trigunung.com", "w98ssy6x.up.railway.app" and the correct value has stopped. Current output of railway domain status:
dnsRecords[0].requiredValue : cm2zxep0.up.railway.app dnsRecords[0].currentValue : cm2zxep0.up.railway.app dnsRecords[0].status : DNS_RECORD_STATUS_PROPAGATED verification.verified : true certificate.status : CERTIFICATE_STATUS_TYPE_VALIDATING_OWNERSHIP
So DNS propagation is no longer the blocker - your own API confirms the record is PROPAGATED and ownership is verified - yet the certificate has been stuck in VALIDATING_OWNERSHIP for over 2.5 hours (domain registered 05:42 UTC, last updated 06:30 UTC, still validating at 08:06 UTC).
Checks done on our side, all passing:
CNAME from authoritative NS (nova.dns-parking.com) : cm2zxep0.up.railway.app
CNAME from 8.8.8.8 and 1.1.1.1 : cm2zxep0.up.railway.app
TXT _railway-verify.www : present and matching
domain targetPort : 8080
application listening port (from deploy logs) : 8080 (matches)
default domain web-production-35802.up.railway.app : HTTP 200
railway domain certificate retry is refused with "only available after certificate issuance fails", so we cannot trigger a new attempt ourselves.
REQUEST Please advance or restart the ACME order for www.trigunung.com. Nothing further can be changed on our side - DNS, verification token and target port are all correct.
0 Replies
12 days ago
It looks like you already have a thread open about this: Custom domain certificate stuck at VALIDATING_OWNERSHIP for 3+ hours. We're automatically closing this one, and we'll reply to you there soon. If you have anything more to add about this topic, please post it in that thread.
Status changed to Duplicate Railway • 12 days ago