Custom domain stuck in VALIDATING_OWNERSHIP for 8 days despite correct DNS + TXT
muslimwellness
PROOP

2 months ago

Custom domain: apply.muslimwellness.ca

(Happy to share project / service / environment / domain IDs privately if needed.)

Problem


Our custom domain has been stuck at

Certificate status: CERTIFICATE_STATUS_TYPE_VALIDATING_OWNERSHIP

Verified: no

since it was created on 2026-08-11 (8+ days). The edge serves the default

*.up.railway.app wildcard cert for this host, so no per-domain certificate has

ever been issued, and HTTPS fails with

"no alternative certificate subject name matches target host name".

The DNS is fully correct and confirmed at the AUTHORITATIVE nameservers

(not just cached resolvers):

CNAME apply -> 50ytntd3.up.railway.app (matches dashboard)

TXT _railway-verify.apply -> the exact railway-verify=... token shown in the dashboard

                                (single, clean record)
  • No CAA record anywhere in the tree blocks issuance (railway.app itself

    authorizes letsencrypt.org).

  • HTTP requests to the host return 301 -> HTTPS (edge recognizes the host).

  • The ACME challenge path (/.well-known/acme-challenge/...) returns 404, i.e.

    the edge is handling it, not the app.

  • The app's listening port matches the domain's target port.

  • Sync status: ACTIVE.

So ownership validation should have passed long ago against the TXT record,

but the certificate is stuck in VALIDATING_OWNERSHIP.

What we've tried


  • railway domain certificate retry -> rejected:

    "Certificate retry is only available after certificate issuance fails.

    Current status: CERTIFICATE_STATUS_TYPE_VALIDATING_OWNERSHIP."

  • railway domain update ... --port <same value> to re-arm the validation loop

    (Updated timestamp refreshed) -> no change, still Verified: no /

    VALIDATING_OWNERSHIP.

Request


Please clear/re-run the stuck ownership validation server-side and issue the

Let's Encrypt certificate for apply.muslimwellness.ca. We would prefer NOT to

delete and re-add the domain, because that regenerates the _railway-verify TXT

token and CNAME target and would force our DNS administrator to redo the

records. If a re-add is the only option, please confirm whether the CNAME

target (50ytntd3.up.railway.app) and verify token would be preserved.

Solved

1 Replies

Status changed to Awaiting Railway Response Railway • about 2 months ago


Okay, it seems to be re-issued. You should be okay now.


Status changed to Awaiting User Response Railway • about 2 months ago


Railway
BOT

a month ago

This thread has been marked as solved automatically due to a lack of recent activity. Please re-open this thread or create a new one if you require further assistance. Thank you!

Status changed to Solved Railway • about 1 month ago


Welcome!

Sign in to your Railway account to join the conversation.

Loading...