Custom domain stuck in VALIDATING_OWNERSHIP — DNS propagated, no cert error
sarahammoud21
FREEOP

a month ago

Custom domain: www.seer-cv.com

Project: grand-unity (7d5386f4-661e-45df-a3ff-23dfc49c77af)

Service: ats-resume-saas

The certificate has been stuck in CERTIFICATE_STATUS_TYPE_VALIDATING_OWNERSHIP

for ~45 minutes. certificateErrorType is null, so there is no error surfaced —

it simply never progresses.

What I verified:

  1. DNS is correct and propagated. Your own API reports:

    recordType: CNAME

    requiredValue: np56jicr.up.railway.app

    currentValue: np56jicr.up.railway.app

    status: DNS_RECORD_STATUS_PROPAGATED

  2. Confirmed independently — dig against 1.1.1.1, 8.8.8.8, 9.9.9.9 and against

    the authoritative nameserver (jamie.ns.cloudflare.com) all return

    np56jicr.up.railway.app.

  3. Cloudflare proxy is OFF (DNS only / grey cloud). The hostname resolves

    straight to a Railway IP (69.46.46.118), not a Cloudflare edge IP.

  4. No CAA records exist on the zone, so Let's Encrypt is not blocked.

  5. The service itself is healthy and reachable. Requests to

    http://www.seer-cv.com/ return "301 Moved Permanently" with the

    x-railway-67 header, so Railway's edge is receiving traffic correctly.

  6. The likely problem: requests to

    http://www.seer-cv.com/.well-known/acme-challenge/

    return "404 Not Found" with Content-Type: text/plain — this looks like the

    request is being passed through to my application rather than intercepted

    by Railway's proxy for the ACME challenge.

  7. I already tried deleting and re-adding the custom domain. That produced a

    new CNAME target (xuok1gjt -> np56jicr), which I updated in DNS and verified

    as propagated, but the certificate is still stuck in the same state.

The service works perfectly on its railway.app domain

(ats-resume-saas-production.up.railway.app) — the issue is limited to

certificate issuance for the custom domain.

I have temporarily pointed the domain back to my previous host to restore the

site, so DNS may no longer show the CNAME while you investigate. I can point it

back to Railway at any time if you need it in place for testing — just let me

know.

Solved

1 Replies

Railway
BOT

a month ago

The certificate is stuck because the TXT ownership-verification record is missing. Custom domains require two DNS records: the CNAME for traffic routing (which you had configured correctly) and a TXT record for ownership verification. Add a TXT record at the host shown in your service's custom domain settings (under "Show DNS records") with the verification value listed there, and restore the CNAME to the target shown in those same settings. Once both records propagate, verification and certificate issuance will resume automatically.


Status changed to Awaiting User Response Railway • about 1 month ago


Railway
BOT

24 days ago

This thread has been marked as solved automatically due to a lack of recent activity. Please re-open this thread or create a new one if you require further assistance. Thank you!

Status changed to Solved Railway • 24 days ago


Welcome!

Sign in to your Railway account to join the conversation.

Loading...