Custom domain certificate stuck in VALIDATING_OWNERSHIP even after delete+re-add with correct DNS
altafvanat-dev
FREEOP

a month ago

Need some help with below?

Domain ID: 8c988c1b-2ace-4048-86a1-36fc8be68682

Domain: www.osynligt.se

Service: osynlig (project scamradar)

CNAME target: 6g1l7owq.up.railway.app

DNS record is confirmed propagated and matching (DNS_RECORD_STATUS_PROPAGATED) via the API, verified independently via public DNS lookup. HTTP (port 80) reaches the Railway edge correctly and 301-redirects to HTTPS. HTTPS fails with an SNI/certificate mismatch.

I deleted the domain, waited ~5.5 hours, and re-added it — got a new CNAME target (6g1l7owq.up.railway.app instead of the old 27uz8gbb.up.railway.app), updated DNS to match immediately (confirmed matching within minutes). Certificate has now been stuck in VALIDATING_OWNERSHIP for 40+ minutes since re-adding, despite DNS already being correct.

Domain is managed via Cloudflare (DNS only / grey-clouded, not proxied) so ACME HTTP-01 challenges should reach the origin directly. Can someone check/retrigger certificate issuance for this domain?

Solved

1 Replies

Railway
BOT

a month ago

The certificate is stuck because the TXT ownership-verification record is missing. Your CNAME is correct and propagated, but a second record is also required for domain verification. In Cloudflare, add a TXT record with the Name set to _railway-verify.www and the Value set to the verification string shown in your domain's DNS settings in the Railway dashboard. Once that propagates, verification will complete and the certificate should issue.


Status changed to Awaiting User Response Railway • about 1 month ago


Railway
BOT

a month ago

This thread has been marked as solved automatically due to a lack of recent activity. Please re-open this thread or create a new one if you require further assistance. Thank you!

Status changed to Solved Railway • 27 days ago


Welcome!

Sign in to your Railway account to join the conversation.

Loading...