a month ago
Custom domain: www.seer-cv.com
Project: grand-unity (7d5386f4-661e-45df-a3ff-23dfc49c77af)
Service: ats-resume-saas
The certificate has been stuck in CERTIFICATE_STATUS_TYPE_VALIDATING_OWNERSHIP
for ~45 minutes. certificateErrorType is null, so there is no error surfaced —
it simply never progresses.
What I verified:
-
DNS is correct and propagated. Your own API reports:
recordType: CNAME
requiredValue: np56jicr.up.railway.app
currentValue: np56jicr.up.railway.app
status: DNS_RECORD_STATUS_PROPAGATED
-
Confirmed independently — dig against 1.1.1.1, 8.8.8.8, 9.9.9.9 and against
the authoritative nameserver (jamie.ns.cloudflare.com) all return
np56jicr.up.railway.app.
-
Cloudflare proxy is OFF (DNS only / grey cloud). The hostname resolves
straight to a Railway IP (69.46.46.118), not a Cloudflare edge IP.
-
No CAA records exist on the zone, so Let's Encrypt is not blocked.
-
The service itself is healthy and reachable. Requests to
http://www.seer-cv.com/ return "301 Moved Permanently" with the
x-railway-67 header, so Railway's edge is receiving traffic correctly.
-
The likely problem: requests to
http://www.seer-cv.com/.well-known/acme-challenge/
return "404 Not Found" with Content-Type: text/plain — this looks like the
request is being passed through to my application rather than intercepted
by Railway's proxy for the ACME challenge.
-
I already tried deleting and re-adding the custom domain. That produced a
new CNAME target (xuok1gjt -> np56jicr), which I updated in DNS and verified
as propagated, but the certificate is still stuck in the same state.
The service works perfectly on its railway.app domain
(ats-resume-saas-production.up.railway.app) — the issue is limited to
certificate issuance for the custom domain.
I have temporarily pointed the domain back to my previous host to restore the
site, so DNS may no longer show the CNAME while you investigate. I can point it
back to Railway at any time if you need it in place for testing — just let me
know.
1 Replies
a month ago
The certificate is stuck because the TXT ownership-verification record is missing. Custom domains require two DNS records: the CNAME for traffic routing (which you had configured correctly) and a TXT record for ownership verification. Add a TXT record at the host shown in your service's custom domain settings (under "Show DNS records") with the verification value listed there, and restore the CNAME to the target shown in those same settings. Once both records propagate, verification and certificate issuance will resume automatically.
Status changed to Awaiting User Response Railway • about 1 month ago
24 days ago
This thread has been marked as solved automatically due to a lack of recent activity. Please re-open this thread or create a new one if you require further assistance. Thank you!
Status changed to Solved Railway • 24 days ago