Custom domain stuck validating — duplicate ACME challenge TXT records
arturoalaimo
FREEOP

22 days ago

Custom domain riskmonitornevastar.com on service market-intelligence-platform has been stuck at verified=false / CERTIFICATE_STATUS_TYPE_VALIDATING_OWNERSHIP for over an hour.

Confirmed correct on my end:

CNAME riskmonitornevastar.com → nnnck7uc.up.railway.app, status PROPAGATED

No CAA record restricting Let's Encrypt

DNSSEC not enabled

Cloudflare SSL/TLS mode: Full

Likely root cause: _acme-challenge.riskmonitornevastar.com currently has two different TXT record values present simultaneously — this looks like leftover/conflicting challenge tokens from a prior issuance attempt, blocking clean Let's Encrypt validation.

Request: Please remove and re-add the custom domain on the service (or otherwise clear the stale challenge state) to force a fresh certificate issuance.

IDs:

Project: f0028445-ed11-46e8-8bf7-e38f6abd1e6d

Service: 7177ceff-9ebd-4fbb-9ddd-ed89673481f6

Environment: 28d2d226-8965-448d-a39b-c87a173be115

Solved

1 Replies

Railway
BOT

22 days ago

No TXT record was found at _railway-verify for your domain, which is why ownership validation has not passed and the certificate cannot issue. The required value is railway-verify=fbdde4e08a81b6e8c611bc41eb4fefdbecc0491f7a55677629072445cdd7abb8. Add that as a TXT record with host _railway-verify in your Cloudflare DNS. The _acme-challenge TXT records you noticed are unrelated to ownership verification. Once the verification record propagates, the certificate process will resume.


Status changed to Awaiting User Response Railway • 22 days ago


Railway
BOT

15 days ago

This thread has been marked as solved automatically due to a lack of recent activity. Please re-open this thread or create a new one if you require further assistance. Thank you!

Status changed to Solved Railway • 15 days ago


Welcome!

Sign in to your Railway account to join the conversation.

Loading...