8 hours ago
A custom domain has been stuck in VALIDATING_OWNERSHIP for over three hours, even
though Railway's own API reports the DNS record as correct and propagated.
Project: la-cueva-tienda (819fbbff-7f12-4a1a-ace0-2f10accee893)
Environment: production (7d1951fe-baf9-4956-a9b9-996a336d8893)
Service: tienda (109b6c34-6d12-47ad-86c3-18167808a842)
Domain: www.lacuevashop.com
What the domains query returns right now:
certificateStatus: CERTIFICATE_STATUS_TYPE_VALIDATING_OWNERSHIP
dnsRecords.status: DNS_RECORD_STATUS_PROPAGATED
currentValue: cqiatdat.up.railway.app
requiredValue: cqiatdat.up.railway.app
purpose: DNS_RECORD_PURPOSE_TRAFFIC_ROUTE
So Railway sees exactly the value it asked for, and still does not issue the
certificate. Only one record is listed as required (the CNAME); no
_railway-verify TXT record is being requested for this domain.
Independently verified: the CNAME resolves to cqiatdat.up.railway.app from both
the Google and Cloudflare public resolvers. DNS is on Cloudflare with the proxy
DISABLED (grey cloud), TTL 60. No CAA records, no DNSSEC, no conflicting A
record. Requests do reach Railway's edge: https://www.lacuevashop.com answers
HTTP 404 served with the *.up.railway.app wildcard certificate, which suggests
the domain is simply not attached to the service yet.
Already tried: deleting and re-adding the custom domain (a new target was
assigned each time and I updated the CNAME accordingly), and removing the apex
domain lacuevashop.com in case two pending domains were interfering.
This project was transferred into this workspace earlier today via Transfer
ownership, in case that left domain validation in a bad state.
This looks identical to two already-solved threads: "Custom domain stuck on
VALIDATING_OWNERSHIP despite correct DNS" (14 days ago) and "Custom Domain Stuck
on VALIDATING_OWNERSHIP Despite Correct DNS" (15 days ago). In both, the answer
was that the ownership verification workflow stalled before picking up the
completed DNS, and a Railway employee re-triggered certificate issuance, which
fixed it within minutes.
Could you re-trigger validation for www.lacuevashop.com the same way? Thanks.
1 Replies
8 hours ago
The CNAME is propagated correctly, but a TXT record for domain ownership is also required and has not been published yet. Open the domain's settings in your service's Networking section to see the exact TXT record host and value you need to add in Cloudflare. Certificate issuance will resume on its own once that TXT record propagates.
Status changed to Awaiting User Response Railway • about 8 hours ago
Status changed to Solved Anonymous • about 8 hours ago