Custom domain verified but not responding after 72+ hours
gooodnest
FREEOP

a day ago

Custom domain www.halongbase.ru is verified in Railway, but it still does not respond after more than 72 hours.

Service domain works correctly:

https://halongbase-production.up.railway.app → HTTP 200

Custom domain:

www.halongbase.ru

Target port: 8080

Railway DNS records are configured exactly as shown:

CNAME www → uygqzowj.up.railway.app

TXT _railway-verify.www → Railway verification value

Railway dashboard shows green checks for both DNS records.

Public DNS resolves www.halongbase.ru to Railway.

No CAA records are present.

DNSSEC is not enabled.

Tests:

curl -Iv https://halongbase-production.up.railway.app → HTTP 200

curl -Iv https://www.halongbase.ru → hangs before TLS handshake

curl -Iv http://www.halongbase.ru → TCP connects, request is sent, but no HTTP response is returned

Could you please check or retrigger custom-domain routing / certificate issuance for this domain?

Awaiting User Response

1 Replies

Railway
BOT

a day ago

From our side the custom domain is fully set up: both DNS records have propagated, ownership is verified, the TLS certificate has been issued and is valid, and an HTTPS request to the domain from outside your network reaches your service and gets an HTTP 200 back. Routing and certificate issuance are already complete, so there is nothing to retrigger.

When TCP connects and then the TLS handshake hangs with no reset, but only from certain networks, the usual cause is filtering on the network path between the client and our edge. Some ISPs, including some Russian ones, drop traffic to specific edge IPs or to specific SNI hostnames. Your service domain and your custom domain can resolve to different edge IPs, which is why one can work while the other hangs from the same machine.

To tell which kind of filtering it is, try curl --resolve to force the custom domain onto a different edge IP, and openssl s_client -servername with the generated domain against the same IP. If only the custom hostname hangs, that is SNI filtering. If another IP works, that is IP filtering. We can't lift ISP-side filtering or assign specific edge IPs, and redeploying or changing region does not change the edge IP. The lasting fix is to put a proxy or CDN in front of the domain whose IPs your users can reach.


Status changed to Awaiting User Response Railway • about 24 hours ago


Welcome!

Sign in to your Railway account to join the conversation.

Loading...