Custom domain stuck in ISSUING for ~4 weeks despite correct, propagated DNS
emartins0210
HOBBYOP

a month ago

Hi,

A custom domain on my project has been stuck without a certificate since July 30,

about four weeks now. The app itself works fine on its *.up.railway.app domain.

Project: 3e8cb0e7-4686-4d9f-ab71-0b93f2988d32

Service: 326f368e-e40e-4026-bbf9-613f95f5dc6d (web)

Environment: 4def6e14-490a-493e-b33b-3d2701baab24 (production)

Domain: automacao.eugeniomartins.com.br

Domain ID: 85180f65-5c7a-4d1b-b73c-7c59a4411fbd

Current state (from your own API):

  • certificateStatus: CERTIFICATE_STATUS_TYPE_ISSUING
  • DNS record: DNS_RECORD_STATUS_PROPAGATED
  • requiredValue and currentValue both = tn3i7y85.up.railway.app

What I have already verified and ruled out:

  • CNAME is correct and propagated worldwide (confirmed via public resolvers and by

    your API reporting PROPAGATED).

  • No CAA records on the apex domain, and no DNSSEC, so nothing is blocking

    Let's Encrypt issuance.

  • Port 80 reaches your edge normally (HTTP returns 301), so the ACME HTTP path

    is reachable.

  • HTTPS with certificate verification disabled returns 404 and serves the

    *.up.railway.app wildcard certificate, so the hostname appears never to get

    attached at the edge.

  • I deleted and recreated the custom domain three times, updating the CNAME to the

    new target each time, and triggered customDomainIssueCertificate several times.

    It moved from VALIDATING_OWNERSHIP to ISSUING and has stayed there since.

  • Verified from two independent networks, so it is not a local DNS cache issue.

It looks like this hostname is wedged in your control plane. Could you please clear

the stuck state and re-trigger issuance?

Note: I also created painel.eugeniomartins.com.br (ID

2125335e-2d40-45ee-ba84-9941fc460041) as a diagnostic and never pointed its DNS.

Please feel free to delete that one.

Thanks!

Solved

1 Replies

Railway
BOT

a month ago

The domain's certificate is stuck because ownership verification has not completed - verified is currently false. The CNAME for traffic routing is correctly propagated, but there is no TXT record at the verification hostname (_railway-verify. prefix on the domain). Adding a TXT record there with the verification value shown in your service's Settings under Networking will allow verification to complete and the certificate to issue.


Status changed to Awaiting User Response Railway • about 1 month ago


Railway
BOT

a month ago

This thread has been marked as solved automatically due to a lack of recent activity. Please re-open this thread or create a new one if you require further assistance. Thank you!

Status changed to Solved Railway • about 1 month ago


Welcome!

Sign in to your Railway account to join the conversation.

Loading...