Custom domain stuck on "Validating ownership": Railway still sees the old registrar's DNS after a nameserver change
aurumdays
PROOP

12 hours ago

My custom domain www.thehanabanana.com has been stuck on certificate status "Validating ownership" since I added it (created 2026-10-05 02:09 UTC). Railway shows "Verified: yes", but the CNAME record status is "requires update" and the value Railway detects is "thehanabanana.com". That is the OLD record from my previous DNS host, not what public DNS returns today.

What I did:

  • The domain is registered at GoDaddy. A few hours ago I moved its nameservers to Cloudflare (joselyn.ns.cloudflare.com / stan.ns.cloudflare.com). The .com registry already returns the Cloudflare nameservers.

  • At Cloudflare I added both records Railway gave me, both "DNS only" (not proxied):

    CNAME www -> cq1fb3by.up.railway.app

    TXT _railway-verify.www (the value from Railway)

What public DNS returns now (1.1.1.1, 8.8.8.8 and 9.9.9.9 all agree):

www.thehanabanana.com CNAME cq1fb3by.up.railway.app -> 69.46.46.112

_railway-verify.www.thehanabanana.com TXT present and matching

What I think is happening:

GoDaddy's old nameservers (ns55/ns56.domaincontrol.com) still answer for the zone with the old default record "www CNAME thehanabanana.com". That is exactly the value Railway shows as detected. So it looks like the resolver behind Railway's DNS check cached the old nameserver delegation from before the switch. The TXT ownership check passed, so that part seems to use fresh DNS.

Result: no certificate is issued. https://www.thehanabanana.com gets Railway's default *.up.railway.app certificate; plain http answers with a redirect to https, so traffic does reach Railway.

The apex thehanabanana.com (added 00:58 UTC) is stuck the same way. I don't need the apex on Railway any more; I plan to remove it once www works.

Questions:

  1. Can someone at Railway re-run or flush the DNS check for www.thehanabanana.com so the certificate can issue?
  2. If not, will it clear by itself once the cached delegation expires, and roughly when?

No build or deploy errors; the service is healthy on its *.up.railway.app address.

Awaiting User Response

1 Replies

Railway
BOT

12 hours ago

Our DNS check now sees the correct record: the www CNAME shows as propagated to your cq1fb3by.up.railway.app target, and ownership is verified. Nothing in your Cloudflare records needs to change.

The certificate step is separate from that check. When it last ran, at 03:37 UTC, its HTTP request did not reach Railway. That points to a resolver that still had the old GoDaddy answer cached from before your nameserver change. A probe we ran just now did reach our edge correctly. There is nothing to flush on our side. The stale answer drops out once the cached delegation and the old record's TTL expire, and the certificate can issue after that.


Status changed to Awaiting User Response Railway • about 12 hours ago


Welcome!

Sign in to your Railway account to join the conversation.

Loading...