Custom domain SSL certificate stuck in "Validating" for several hours
kaito-myt
HOBBYOP

2 months ago

Hi Railway team,

Two custom domains have been stuck at certificate issuance ("Validating

ownership") for several hours and never progress to "Issued". HTTPS returns

a TLS handshake failure (wrong certificate) on both.

Project ID: c4001a55-2b65-4500-a020-3f9ed6044999

Environment: production (4f8f4624-6ebf-4da2-b30d-bb9bbbe36df0)

Affected custom domains:

  1. m2p.tools -> service "M2P-Portal" (46820ff5-7be1-440a-bea7-d7f403bf2afc)

    Required CNAME target: qf4co28m.up.railway.app

  2. a2p.m2p.tools -> service "A2P" (90eb3b41-95f9-4955-9e62-c9bd0021... )

    Required CNAME target: fejfqglp.up.railway.app

For m2p.tools (the cleanest case), everything on the DNS side is correct:

  • DNS is fully propagated: your dashboard reports the record as "Propagated",

    and both Cloudflare (1.1.1.1) and Google (8.8.8.8) resolvers return the

    Railway edge for it.

  • The record is DNS-only (NOT proxied through Cloudflare): requests reach the

    Railway edge directly (responses include the "x-railway-*" header and there

    is no "cf-ray"/"server: cloudflare" header).

  • No CAA records restrict issuance, and DNSSEC is not enabled on the zone.

Despite this, certificateStatus stays "VALIDATING_OWNERSHIP" and no Let's

Encrypt certificate is ever issued. HTTPS to https://m2p.tools fails the TLS

handshake (certificate does not match the host).

What I already tried, with no change:

  • Waited several hours.

  • Deleted and re-created the custom domain (a2p.m2p.tools) and updated DNS to

    the new target — still stuck.

  • Redeployed the services after attaching the domains — still stuck.

Could you please look into why certificate issuance is stuck for these domains

and re-trigger / repair it? Happy to provide any additional details.

Thanks!

Solved

1 Replies

Railway
BOT

2 months ago

Both domains are missing the required TXT ownership-verification record, which is why they stay at "Validating ownership" and certificates never issue. Custom domains require two DNS records: the CNAME for traffic routing and a TXT record at the _railway-verify host shown in your dashboard to prove ownership. The CNAME alone is not sufficient. For the first domain, add a TXT record at the verification host with the token value shown in your dashboard. For the second domain, the same TXT record is needed, and its CNAME also needs updating since it currently points to the old target from before you deleted and re-created the domain rather than the new target shown in your dashboard. Once both records (CNAME and TXT) are in place and propagated for each domain, verification will complete and certificates will issue automatically.


Status changed to Awaiting User Response Railway • about 2 months ago


Railway
BOT

a month ago

This thread has been marked as solved automatically due to a lack of recent activity. Please re-open this thread or create a new one if you require further assistance. Thank you!

Status changed to Solved Railway • about 1 month ago


Welcome!

Sign in to your Railway account to join the conversation.

Loading...