16 days ago
A custom domain certificate has been stuck in VALIDATING_OWNERSHIP and never advances. Both required DNS records were verified correct and globally resolvable, so this does not appear to be the usual missing-TXT case.
Domain: www.laposata.dk
Domain ID: aa4d3bb4-c362-4538-8054-d1724b12d6e3
Project ID: c24d1d56-00af-4486-b4d0-1498df6a9332
Service: laposata-website (production)
certificateStatus: CERTIFICATE_STATUS_TYPE_VALIDATING_OWNERSHIP
status.verified: false
TIMELINE
2026-08-04 21:57 CEST CNAME pointed at stxte639.up.railway.app
2026-08-05 09:55 CEST still unverified, ~12 hours later
VERIFIED WHILE POINTED AT RAILWAY
CNAME www.laposata.dk -> stxte639.up.railway.app
Railway API reported DNS_RECORD_STATUS_PROPAGATED
currentValue == requiredValue
TXT _railway-verify.www.laposata.dk
value exactly matched status.verificationToken
resolved NOERROR from ns61/ns62.domaincontrol.com
(authoritative) and from 8.8.8.8, 1.1.1.1, 9.9.9.9
No CAA records on laposata.dk (Let's Encrypt not blocked)
No DNSSEC (no DS records)
DNS-only at GoDaddy, no proxy in the path
Domain served 404 with fallback *.up.railway.app cert throughout
"railway domain certificate retry" refused - issuance had not failedI deliberately have NOT deleted and re-added the domain, to avoid rotating the CNAME target and verification token and risking a Let's Encrypt failed-authorization backoff.
Current state: I have temporarily repointed the CNAME back to our existing host so visitors are not served 404s. The verification TXT record is still in place and unchanged. I can repoint to the Railway target immediately on request.
Could someone please requeue certificate issuance for this domain?
3 Replies
16 days ago
The CNAME for www.laposata.dk is currently resolving to laposata.dk instead of the required Railway target stxte639.up.railway.app, so the domain's DNS status is not propagated and the certificate workflow cannot advance. The TXT verification record at _railway-verify.www.laposata.dk is correct and matches. Please repoint the CNAME back to stxte639.up.railway.app at GoDaddy and reply here once it has propagated so the domain status can be rechecked.
Status changed to Awaiting User Response Railway • 16 days ago
16 days ago
Done - the CNAME is repointed to the Railway target and has propagated. Railway's own API now reports the correct value.
2026-08-05 23:26 CEST
CNAME www.laposata.dk
ns61.domaincontrol.com (authoritative) stxte639.up.railway.app.
8.8.8.8 stxte639.up.railway.app.
1.1.1.1 stxte639.up.railway.app.
TXT _railway-verify.www.laposata.dk
railway-verify=ca5d...19e2d (matches status.verificationToken)
Railway API:
currentValue: stxte639.up.railway.app
status: DNS_RECORD_STATUS_PROPAGATED
verified: false
certificate: CERTIFICATE_STATUS_TYPE_VALIDATING_OWNERSHIPBoth records are in place and propagated, and Railway sees the CNAME, but verified is still false and the certificate has not advanced.
One change since the original post: I removed a stale TXT record that had been sitting at _railway-verify.laposata.dk (apex) from an earlier misconfiguration. Only the correct _railway-verify.www record remains now, so there is no duplicate token in the zone.
Ready for the domain status to be rechecked, and for certificate issuance to be requeued if it is wedged server-side. I will leave the CNAME pointed at Railway - please let me know if you need anything else from my side.
Status changed to Awaiting Railway Response Railway • 16 days ago
15 days ago
Both DNS records are confirmed correct and propagated. The certificate workflow was stuck because the original verification attempt expired before your DNS was in place, and it never re-ran automatically. We've re-triggered certificate issuance for www.laposata.dk - it should complete within a few minutes.
Status changed to Awaiting User Response Railway • 15 days ago
8 days ago
This thread has been marked as solved automatically due to a lack of recent activity. Please re-open this thread or create a new one if you require further assistance. Thank you!
Status changed to Solved Railway • 8 days ago