Custom domain certificate stuck in VALIDATING_OWNERSHIP for hours — DNS fully propagated, no CAA
sos-1010
HOBBYOP

a month ago

Hi,

The Let's Encrypt certificate for my custom domain never gets issued. It has been

stuck in CERTIFICATE_STATUS_TYPE_VALIDATING_OWNERSHIP for many hours, across

two separate domain attachments, while DNS is fully propagated and matches the

required value exactly.

Affected resource

  • Domain: rdv.fratria.fr
  • Project: 25365793-c074-43e2-b610-d1253a942d80 (fratria-leads-api)
  • Environment: 6cf7253b-2e28-4168-ae71-44666bf80420 (production)
  • Service: e423a88c-d3fa-43c5-b34c-8e34083500ee (target port 3000)
  • Current customDomain id: 0c091a10-6433-4232-a251-a4faf143877c

Timeline (all times UTC, 2026-08-23)

  1. Morning: domain first attached to the service. Railway showed the DNS record

    as PROPAGATED, but the certificate stayed in VALIDATING_OWNERSHIP for

    several hours with no progress.

  2. ~19:09: I removed the domain and re-added it (standard "kick" procedure).

    Railway generated a new target (3rwxzlfv.up.railway.app); I updated the

    CNAME at my DNS provider (OVH) immediately.

  3. As of ~20:15 (more than 1 hour after re-add), the API still returns:

    • dnsRecords[0].status = DNS_RECORD_STATUS_PROPAGATED
    • requiredValue = currentValue = 3rwxzlfv.up.railway.app
    • certificateStatus = CERTIFICATE_STATUS_TYPE_VALIDATING_OWNERSHIP

DNS checks already done (so we don't loop on the usual suspects)

  • rdv.fratria.fr CNAME 3rwxzlfv.up.railway.app — resolves correctly on

    1.1.1.1 and 8.8.8.8, no stale record, low TTL (3600), propagation confirmed

    by Railway's own dashboard/API.

  • No CAA record anywhere in the chain: fratria.fr returns NOERROR with zero

    CAA records (nothing blocks Let's Encrypt), no CAA on rdv.fratria.fr either.

  • The zone is DNSSEC-signed and valid (AD flag set on resolver answers) — no

    DNSSEC breakage.

  • No Cloudflare or other proxy in front: plain OVH DNS, CNAME straight to

    *.up.railway.app.

  • The service itself is healthy and serving traffic on its

    railway.app domain (this is a production widget domain for our customers).

Since DNS has been conforming the whole time on both attachments and a full

remove/re-add did not unblock issuance, this looks stuck on Railway's side

(cert issuance job not firing or ACME order stuck). Could you kick/retry the

certificate issuance for this domain, or tell me what else is blocking it?

Thanks!

Sosthène — Fratria (fratria-leads-api)

Solved

2 Replies

Railway
BOT

a month ago

The domain's CNAME is correctly propagated, but the TXT ownership-verification record is missing, which is why the certificate is stuck in VALIDATING_OWNERSHIP. Custom domains require both a CNAME pointing to the Railway target and a TXT record for ownership verification. You can find the required TXT hostname and value in your service's Settings under Networking next to the domain entry. Once that TXT record is added and propagates, verification will complete and certificate issuance will proceed.


Status changed to Awaiting User Response Railway • about 1 month ago


sos-1010
HOBBYOP

a month ago

Resolved — the missing TXT ownership-verification record was indeed the cause. I added the _railway-verify.rdv TXT at OVH, verification completed and the certificate was issued shortly after. Thank you!


Status changed to Awaiting Railway Response Railway • about 1 month ago


Status changed to Solved Railway • about 1 month ago


Welcome!

Sign in to your Railway account to join the conversation.

Loading...