a month ago
Issue: Custom domain api.noriekliving.com has been stuck on "Validating domain ownership" (CERTIFICATE_STATUS_TYPE_VALIDATING_OWNERSHIP) for several hours, with DNS confirmed correct and propagated the entire time.
What I've checked:
DNS is clean and correct: single CNAME api.noriekliving.com → xotv7scu.up.railway.app, no CAA records on either the apex or the subdomain, no DNSSEC configured (absent, not misconfigured), no conflicting A/CNAME records at the same name.
Confirmed via Railway's own domain-status API, not just external resolvers — dnsRecords[0].status is DNS_RECORD_STATUS_PROPAGATED and currentValue exactly matches requiredValue (xotv7scu.up.railway.app). This has been true for hours; status hasn't moved since.
TLS handshake on api.noriekliving.com:443 succeeds, but the server presents the generic *.up.railway.app certificate (issued Jul 29, expires Oct 27) instead of one for api.noriekliving.com.
Checked public CT logs (crt.sh) for api.noriekliving.com — zero certificates ever issued for this hostname. So this isn't a cert-exists-but-wrong-one-served/SNI routing issue, it looks like issuance itself has never completed.
For comparison: the web app's custom domains on the same root domain (noriekliving.com, www.noriekliving.com — hosted on Vercel, added the same day) verified and had certificates issued within minutes.
Have not deleted/recreated the domain, deliberately — aware repeated delete/recreate risks the Let's Encrypt rate limit (5 duplicate certs/ domain/week, then a 7-day lockout), and don't want to make this worse.
IDs:
Project ID: f6161bb5-4c28-4c2a-b5b1-21f7be292a14
Service ID (api): a43d2b54-10db-423e-81c1-8dd729a55a5d
Domain ID (api.noriekliving.com): c0f6d725-aa13-44c2-b01c-284288c802ef
CNAME target: xotv7scu.up.railway.app
Could you check the internal state of this domain and either force re-evaluation or let me know what's blocking it? Happy to provide more detail if needed.
1 Replies
a month ago
The CNAME traffic record is propagated correctly, but the required TXT ownership-verification record has not been added yet, which is why the certificate is stuck at "Validating domain ownership." Custom domains need both a CNAME and a TXT record before a certificate can issue. Add a TXT record at the host shown in your service's custom domain settings (the _railway-verify entry) with the exact value displayed there. Verification and certificate issuance will proceed on their own once the TXT record propagates.
Status changed to Awaiting User Response Railway • about 1 month ago
24 days ago
This thread has been marked as solved automatically due to a lack of recent activity. Please re-open this thread or create a new one if you require further assistance. Thank you!
Status changed to Solved Railway • 24 days ago