Custom domain certificate stuck on "Validating Ownership" for 48+ hours
samuelgaeta-gif
HOBBYOP

3 hours ago

Hi, I need help with a custom domain that's been stuck issuing its SSL certificate for over 48 hours.

Project: aglive-crm

Service: app

Custom domain: crm.worgtech.com.br

Domain ID: 37009264-1af8-428d-8f5f-3b8205848dea

Current status: certificate stuck at CERTIFICATE_STATUS_TYPE_VALIDATING_OWNERSHIP, verified: false

What I've already checked/tried:

CNAME record is correctly propagated to k666uvk5.up.railway.app (confirmed via dig from multiple points).

No CAA records on the domain that would block Let's Encrypt.

No DNSSEC configured (so it's not a DNSSEC validation issue).

The domain sits behind Cloudflare; I disabled the Cloudflare proxy (set the DNS record to "DNS only" / grey cloud) over 24 hours ago, following your own troubleshooting guide's "Toggle Trick" — but the certificate status hasn't changed since.

Since it's been well past the typical 1-hour issuance window and the proxy interference (the most likely cause per your docs) was already ruled out over a day ago, could you please check what's blocking certificate issuance on your end, or manually trigger a retry?

Thanks!

Versão em português, caso queira usar assim mesmo:

Olá, preciso de ajuda com um domínio customizado que está travado há mais de 48 horas tentando emitir o certificado SSL.

Projeto: aglive-crm

Serviço: app

Domínio customizado: crm.worgtech.com.br

ID do domínio: 37009264-1af8-428d-8f5f-3b8205848dea

Status atual: certificado travado em CERTIFICATE_STATUS_TYPE_VALIDATING_OWNERSHIP, verified: false

O que já verifiquei/tentei:

Registro CNAME propagado corretamente para k666uvk5.up.railway.app (confirmado via dig).

Nenhum registro CAA bloqueando o Let's Encrypt.

DNSSEC não configurado.

O domínio está atrás da Cloudflare; desativei o proxy da Cloudflare (mudei para "Somente DNS") há mais de 24 horas, seguindo o guia de troubleshooting de vocês ("Toggle Trick") — mas o status do certificado não mudou desde então.

Awaiting User Response

1 Replies

Railway
BOT

3 hours ago

Your CNAME record is correctly propagated, but the TXT verification record required for domain ownership is missing. Custom domains need both a CNAME pointing to the Railway target and a TXT record for verification - certificates won't issue until both are in place. You can find the exact TXT record name and value to add at your DNS provider under your service's Settings in the Networking section, next to the domain entry.


Status changed to Awaiting User Response Railway about 3 hours ago


Welcome!

Sign in to your Railway account to join the conversation.

Loading...