11 hours ago
Project: postuler-auto (project ID a25aa6f9-4f75-4e13-8edd-9a04efe7dd11)
Service: web (service ID 13dcc874-6d3b-4b41-853f-e2af64486e39)
Custom domain: www.keyjob.fr (domain ID 524e0e0b-0086-4ffe-a0f1-af970ecf358a)
The custom domain www.keyjob.fr has been stuck with certificate status VALIDATING_OWNERSHIP (verified: false) for over 3 hours.
Timeline:
CNAME record www.keyjob.fr → hj6gpa6w.up.railway.app was created at the registrar (OVH) and confirmed correct.
Railway's own domain-status check has been consistently reporting currentValue matching requiredValue (both hj6gpa6w.up.railway.app) for over 2 hours now.
Independently confirmed the CNAME resolves correctly via Google DNS (8.8.8.8), Cloudflare (1.1.1.1), and the domain's own authoritative OVH nameservers (dns111.ovh.net, ns111.ovh.net).
No CAA record exists on the domain that could block certificate issuance (confirmed via dns.google/resolve?type=CAA).
curl https://www.keyjob.fr still fails with a certificate/SNI mismatch error — the edge is reachable but serving the wrong certificate.
Since DNS has been confirmed correct on every path (including Railway's own check) for a sustained period, this looks like a stalled certificate issuance rather than a DNS propagation delay. Could you manually trigger re-issuance or investigate?
2 Replies
11 hours ago
This thread has been marked private. Your CNAME is propagated and pointing correctly at Railway. However, the TXT verification record needed for ownership validation is not present, which is why the certificate is stuck. Custom domains need both a CNAME and a TXT record before a certificate can issue. In your service's networking settings, open "Show DNS records" for this domain to see the required TXT record host and value, then create that TXT record at OVH. Once it propagates, verification and certificate issuance will proceed on their own.
Status changed to Awaiting User Response Railway • about 11 hours ago
Status changed to Awaiting Railway Response Railway • about 6 hours ago
6 hours ago
Your custom domain is now fully verified, the TLS certificate is valid, and traffic is routing correctly through our edge. The TXT verification record that was missing when we last replied is now in place, which unblocked the certificate issuance. No further action is needed on your side.
Status changed to Awaiting User Response Railway • about 6 hours ago