a month ago
Hi,
The Let's Encrypt certificate for my custom domain never gets issued. It has been
stuck in CERTIFICATE_STATUS_TYPE_VALIDATING_OWNERSHIP for many hours, across
two separate domain attachments, while DNS is fully propagated and matches the
required value exactly.
Affected resource
- Domain:
rdv.fratria.fr - Project:
25365793-c074-43e2-b610-d1253a942d80(fratria-leads-api) - Environment:
6cf7253b-2e28-4168-ae71-44666bf80420(production) - Service:
e423a88c-d3fa-43c5-b34c-8e34083500ee(target port 3000) - Current customDomain id:
0c091a10-6433-4232-a251-a4faf143877c
Timeline (all times UTC, 2026-08-23)
-
Morning: domain first attached to the service. Railway showed the DNS record
as
PROPAGATED, but the certificate stayed inVALIDATING_OWNERSHIPforseveral hours with no progress.
-
~19:09: I removed the domain and re-added it (standard "kick" procedure).
Railway generated a new target (
3rwxzlfv.up.railway.app); I updated theCNAME at my DNS provider (OVH) immediately.
-
As of ~20:15 (more than 1 hour after re-add), the API still returns:
dnsRecords[0].status = DNS_RECORD_STATUS_PROPAGATEDrequiredValue = currentValue = 3rwxzlfv.up.railway.appcertificateStatus = CERTIFICATE_STATUS_TYPE_VALIDATING_OWNERSHIP
DNS checks already done (so we don't loop on the usual suspects)
-
rdv.fratria.fr CNAME 3rwxzlfv.up.railway.app— resolves correctly on1.1.1.1 and 8.8.8.8, no stale record, low TTL (3600), propagation confirmed
by Railway's own dashboard/API.
-
No CAA record anywhere in the chain:
fratria.frreturns NOERROR with zeroCAA records (nothing blocks Let's Encrypt), no CAA on
rdv.fratria.freither. -
The zone is DNSSEC-signed and valid (AD flag set on resolver answers) — no
DNSSEC breakage.
-
No Cloudflare or other proxy in front: plain OVH DNS, CNAME straight to
*.up.railway.app. -
The service itself is healthy and serving traffic on its
railway.appdomain (this is a production widget domain for our customers).
Since DNS has been conforming the whole time on both attachments and a full
remove/re-add did not unblock issuance, this looks stuck on Railway's side
(cert issuance job not firing or ACME order stuck). Could you kick/retry the
certificate issuance for this domain, or tell me what else is blocking it?
Thanks!
Sosthène — Fratria (fratria-leads-api)
2 Replies
a month ago
The domain's CNAME is correctly propagated, but the TXT ownership-verification record is missing, which is why the certificate is stuck in VALIDATING_OWNERSHIP. Custom domains require both a CNAME pointing to the Railway target and a TXT record for ownership verification. You can find the required TXT hostname and value in your service's Settings under Networking next to the domain entry. Once that TXT record is added and propagates, verification will complete and certificate issuance will proceed.
Status changed to Awaiting User Response Railway • about 1 month ago
a month ago
Resolved — the missing TXT ownership-verification record was indeed the cause. I added the _railway-verify.rdv TXT at OVH, verification completed and the certificate was issued shortly after. Thank you!
Status changed to Awaiting Railway Response Railway • about 1 month ago
Status changed to Solved Railway • about 1 month ago