Custom domain certificate stuck on VALIDATING_OWNERSHIP for 2+ hours — DNS confirmed correct
dazapata7
HOBBYOP

a month ago

Project: catalogos-dunamix (ID: cfce305a-d59a-446b-bda9-fad08b98353e)

Service: app (ID: 6973d69c-09f3-41c1-abe2-6c72e082ca52)

Custom domain: catalogo.mercadoalegre.app

Domain ID: bcd4092f-a293-445f-9a3d-f9e8b9747ca8

CNAME target: tz60wg95.up.railway.app

The domain was added ~2h30m ago. Certificate status has been stuck on CERTIFICATE_STATUS_TYPE_VALIDATING_OWNERSHIP the entire time.

DNS is confirmed correct — verified directly against the authoritative Cloudflare nameservers (bypassing all caching):

dig @rustam.ns.cloudflare.com catalogo.mercadoalegre.app CNAME

→ tz60wg95.up.railway.app. (matches Railway's required value exactly)

No conflicting A record, no CAA record blocking issuance, no Cloudflare proxy (DNS only, confirmed gray-clouded).

The actual failure, confirmed via openssl:

openssl s_client -connect catalogo.mercadoalegre.app:443 -servername catalogo.mercadoalegre.app

The server (69.46.46.21) correctly routes the TLS connection by SNI, but presents Railway's generic wildcard certificate (SAN: *.up.railway.app, up.railway.app) instead of a dedicated certificate covering catalogo.mercadoalegre.app. Routing works, but certificate issuance for this specific hostname never completed.

Already tried: deleted and re-added the custom domain (same domain ID and CNAME target were reassigned) to force a fresh issuance attempt — no change after several minutes, same wildcard cert still served.

I also see several other threads in this forum reporting the exact same symptom (stuck on VALIDATING_OWNERSHIP for hours to days, with DNS confirmed correct), so this looks like a current platform-side issue with certificate issuance rather than something isolated to my domain.

Could you check the certificate issuance queue/worker for this domain? Happy to provide anything else needed.

Solved

1 Replies

Railway
BOT

a month ago

Your CNAME record is set correctly, but the certificate is stuck because the required TXT ownership-verification record has not been created yet. Custom domains need both a CNAME for traffic routing and a TXT record for ownership verification. In your service's Settings under the custom domain entry, you will see the required TXT record details (host and value). Add that TXT record in your Cloudflare DNS, and once it propagates, verification and certificate issuance will proceed on their own.


Status changed to Awaiting User Response Railway • 28 days ago


Railway
BOT

21 days ago

This thread has been marked as solved automatically due to a lack of recent activity. Please re-open this thread or create a new one if you require further assistance. Thank you!

Status changed to Solved Railway • 21 days ago


Welcome!

Sign in to your Railway account to join the conversation.

Loading...