Custom domain stuck in VALIDATING_OWNERSHIP despite correct, propagated CNAME
Anonymous
HOBBYOP

8 hours ago

A custom domain has been stuck in VALIDATING_OWNERSHIP for over three hours, even

though Railway's own API reports the DNS record as correct and propagated.

Project: la-cueva-tienda (819fbbff-7f12-4a1a-ace0-2f10accee893)

Environment: production (7d1951fe-baf9-4956-a9b9-996a336d8893)

Service: tienda (109b6c34-6d12-47ad-86c3-18167808a842)

Domain: www.lacuevashop.com

What the domains query returns right now:

certificateStatus: CERTIFICATE_STATUS_TYPE_VALIDATING_OWNERSHIP

dnsRecords.status: DNS_RECORD_STATUS_PROPAGATED

currentValue: cqiatdat.up.railway.app

requiredValue: cqiatdat.up.railway.app

purpose: DNS_RECORD_PURPOSE_TRAFFIC_ROUTE

So Railway sees exactly the value it asked for, and still does not issue the

certificate. Only one record is listed as required (the CNAME); no

_railway-verify TXT record is being requested for this domain.

Independently verified: the CNAME resolves to cqiatdat.up.railway.app from both

the Google and Cloudflare public resolvers. DNS is on Cloudflare with the proxy

DISABLED (grey cloud), TTL 60. No CAA records, no DNSSEC, no conflicting A

record. Requests do reach Railway's edge: https://www.lacuevashop.com answers

HTTP 404 served with the *.up.railway.app wildcard certificate, which suggests

the domain is simply not attached to the service yet.

Already tried: deleting and re-adding the custom domain (a new target was

assigned each time and I updated the CNAME accordingly), and removing the apex

domain lacuevashop.com in case two pending domains were interfering.

This project was transferred into this workspace earlier today via Transfer

ownership, in case that left domain validation in a bad state.

This looks identical to two already-solved threads: "Custom domain stuck on

VALIDATING_OWNERSHIP despite correct DNS" (14 days ago) and "Custom Domain Stuck

on VALIDATING_OWNERSHIP Despite Correct DNS" (15 days ago). In both, the answer

was that the ownership verification workflow stalled before picking up the

completed DNS, and a Railway employee re-triggered certificate issuance, which

fixed it within minutes.

Could you re-trigger validation for www.lacuevashop.com the same way? Thanks.

Solved

1 Replies

Railway
BOT

8 hours ago

The CNAME is propagated correctly, but a TXT record for domain ownership is also required and has not been published yet. Open the domain's settings in your service's Networking section to see the exact TXT record host and value you need to add in Cloudflare. Certificate issuance will resume on its own once that TXT record propagates.


Status changed to Awaiting User Response Railway about 8 hours ago


Status changed to Solved Anonymous about 8 hours ago


Welcome!

Sign in to your Railway account to join the conversation.

Loading...