Custom domain test.truespotter.com stuck on TXT verification >24h; serves *.up.railway.app cert despite correct DNS
kwarpechowski
HOBBYOP

5 hours ago

Problem and desired outcome

I added the custom domain test.truespotter.com to a Railway service and created both DNS records shown in the "Configure DNS Records" dialog. The CNAME shows as verified, but the TXT record (_railway-verify.test) has shown a warning since 2026-10-06, even though public resolvers and the authoritative nameserver return exactly the expected value. As a result the domain is not usable: HTTPS requests reach Railway but receive the default *.up.railway.app certificate (browser marks the site as not secure) and a Railway-branded error page instead of my app. This is still happening as of 2026-10-07 (CEST, UTC+2). I'd like Railway to check why the TXT verification is not completing and re-run it, so the domain gets attached and a certificate is issued.

Resources and timing

  • Custom domain: test.truespotter.com
  • Railway CNAME target: mw6a9g7c.up.railway.app
  • Project / service / environment: [fill in: I will select the affected service in the support form]
  • DNS provider: nazwa.pl (nameservers ns1.nazwa.pl, ns2.nazwa.pl, ns3.nazwa.pl)
  • TXT warning first observed: 2026-10-06 (exact time unknown); still present 2026-10-07

Evidence and attempts

Railway's "Configure DNS Records" dialog shows the CNAME test → mw6a9g7c.up.railway.app with a green check, and the TXT _railway-verify.test with a warning icon.

DNS checks performed on 2026-10-07 from Windows PowerShell (Resolve-DnsName):

TXT _railway-verify.test.truespotter.com @1.1.1.1      -> railway-verify=e9939889ffe1a1ed9fa9d59dad54103da6e54f314473ab5a00c0bd52979aff02
TXT _railway-verify.test.truespotter.com @8.8.8.8      -> railway-verify=e9939889ffe1a1ed9fa9d59dad54103da6e54f314473ab5a00c0bd52979aff02
TXT _railway-verify.test.truespotter.com @ns1.nazwa.pl -> railway-verify=e9939889ffe1a1ed9fa9d59dad54103da6e54f314473ab5a00c0bd52979aff02
CNAME test.truespotter.com @1.1.1.1                    -> mw6a9g7c.up.railway.app
NS truespotter.com                                     -> ns1/ns2/ns3.nazwa.pl

The TXT value returned by DNS was compared character by character with the full value copied from the Railway dialog; they are identical. Only one TXT record exists at that name.

Browser check of https://test.truespotter.com on 2026-10-07: the browser shows "Not secure". The certificate presented is CN *.up.railway.app, issued by Let's Encrypt (YE2), valid 2026-09-27 to 2026-12-26, i.e. Railway's generic certificate rather than one for test.truespotter.com. The page shown is a Railway-branded error page with a "Go to Railway" button.

Not yet tried: removing and re-adding the domain (I'm avoiding this because it would generate a new TXT token), and checking CAA records for truespotter.com.

Why contact support?

Contacting Railway support was suggested by the AI assistant I was troubleshooting with. The reason given was that the DNS configuration has been verified as correct at every level (Cloudflare and Google public resolvers plus the authoritative nameserver) for more than 24 hours, yet the verification status in Railway has not changed. That points to the verification check on Railway's side not completing or not being re-run, which I can't trigger or inspect myself. I'm asking Railway to check the verification status for this domain and re-run or reset it.

Uncertainty and constraints

The cause is not known. The leading hypothesis is that Railway's TXT verification check is stuck or was not retried after the record became valid. Evidence for this: identical, correct values from all resolvers checked. Not ruled out: a CAA record restricting certificate issuance (not checked yet), or a resolver used by Railway that cached an earlier NXDOMAIN. An earlier query I made had a typo in the domain name, but that was only my local query, not a change to the DNS record. Please do not delete or recreate the domain without telling me, since that would change the token.

Prepared with Railway's support template (v1).

Awaiting User Response

1 Replies

Status changed to Awaiting Railway Response Railway • about 5 hours ago


5 hours ago

Both of your DNS records are correct: the CNAME is propagated and the published TXT value matches your verification token exactly, while the domain was still sitting in ownership verification.

We've started a fresh verification and certificate issuance for the domain, with the existing token and records kept as they are, so nothing needs to be removed or re-added. It may take a few minutes to complete.


Status changed to Awaiting User Response brody • about 5 hours ago


Welcome!

Sign in to your Railway account to join the conversation.

Loading...