23 days ago
I added a custom domain (bc.scottweierbach.com) to a service on a new project, and its certificate has been stuck in VALIDATING_OWNERSHIP for over an hour now.
What I've already verified before posting:
DNS is fully propagated. The CNAME record (bc.scottweierbach.com pointing to the Railway-provided target) resolves correctly both via Railway's own domain-status API (shows DNS_RECORD_STATUS_PROPAGATED) and via external DNS lookups.
No CAA records exist on the root domain (scottweierbach.com) that could be blocking Let's Encrypt.
The same domain/registrar already works fine elsewhere. I have other subdomains of scottweierbach.com on separate Railway projects with valid, working certificates today, so the general DNS/registrar setup isn't the issue.
railway domain certificate retry refuses to run, saying retry is only available after issuance fails. This one hasn't failed, just seems stuck mid-validation.
Is there a known issue on Railway's side right now, or something else worth checking on my end? Happy to share the project/service ID if useful.
1 Replies
23 days ago
The CNAME is in place and propagated, but we don't see a TXT verification record published at _railway-verify.bc for this domain. Both records are required before a certificate can issue. You can find the expected TXT host and value in your service's Settings under Networking, next to the domain entry. Once that record propagates, verification and certificate issuance will proceed on their own.
Status changed to Awaiting User Response Railway • 23 days ago
Status changed to Solved tst4echoo • 23 days ago