a month ago
Hi, I'm trying to attach a custom domain to my web service and the certificate has been stuck for several days now, well past the documented "up to 72 hours" window.
Project: fortunate-light
Service: web
Domain: www.vzhyk.in.ua
Status:
Certificate status: CERTIFICATE_STATUS_TYPE_VALIDATING_OWNERSHIP
Domain verified: false
No error message shown
What I've already checked (per your SSL troubleshooting docs):
CNAME record (www.vzhyk.in.ua → g8n7f8mz.up.railway.app) is correctly set and shows as DNS_RECORD_STATUS_PROPAGATED in the domain-status API
Independently confirmed via Google's DNS-over-HTTPS resolver - CNAME resolves correctly
No CAA records on the domain (checked via dig CAA) - nothing blocking Let's Encrypt
No DNSSEC configured
The web service itself is deployed and running (responds on the Railway-generated domain)
I have deliberately NOT deleted/re-added the domain, to avoid hitting the Let's Encrypt 5-duplicate-certs/week rate limit
Could you take a look at why certificate issuance for this domain isn't completing? Happy to provide any further diagnostics needed.
Thanks!
1 Replies
a month ago
Your CNAME record is correctly propagated, but the domain is missing the TXT verification record needed for ownership verification. At your DNS provider, add a TXT record at the hostname shown in your service's custom domain settings (under "Show DNS records") with the verification value displayed there. Once that TXT record propagates, verification will complete and certificate issuance will proceed automatically.
Status changed to Awaiting User Response Railway • about 1 month ago
Status changed to Solved zhdanovvlad25 • about 1 month ago