Custom domain SSL certificate stuck on "Validating Ownership" for multiple days
zhdanovvlad25
HOBBYOP

a month ago

Hi, I'm trying to attach a custom domain to my web service and the certificate has been stuck for several days now, well past the documented "up to 72 hours" window.

Project: fortunate-light

Service: web

Domain: www.vzhyk.in.ua

Status:

Certificate status: CERTIFICATE_STATUS_TYPE_VALIDATING_OWNERSHIP

Domain verified: false

No error message shown

What I've already checked (per your SSL troubleshooting docs):

CNAME record (www.vzhyk.in.ua → g8n7f8mz.up.railway.app) is correctly set and shows as DNS_RECORD_STATUS_PROPAGATED in the domain-status API

Independently confirmed via Google's DNS-over-HTTPS resolver - CNAME resolves correctly

No CAA records on the domain (checked via dig CAA) - nothing blocking Let's Encrypt

No DNSSEC configured

The web service itself is deployed and running (responds on the Railway-generated domain)

I have deliberately NOT deleted/re-added the domain, to avoid hitting the Let's Encrypt 5-duplicate-certs/week rate limit

Could you take a look at why certificate issuance for this domain isn't completing? Happy to provide any further diagnostics needed.

Thanks!

Solved

1 Replies

Railway
BOT

a month ago

Your CNAME record is correctly propagated, but the domain is missing the TXT verification record needed for ownership verification. At your DNS provider, add a TXT record at the hostname shown in your service's custom domain settings (under "Show DNS records") with the verification value displayed there. Once that TXT record propagates, verification will complete and certificate issuance will proceed automatically.


Status changed to Awaiting User Response Railway • about 1 month ago


Status changed to Solved zhdanovvlad25 • about 1 month ago


Welcome!

Sign in to your Railway account to join the conversation.

Loading...