Custom domain zodd.fun stuck in CERTIFICATE_STATUS_TYPE_VALIDATING_OWNERSHIP after DNS migration to Cloudflare
zodd-launchpad
HOBBYOP

a month ago

My custom domain zodd.fun has been stuck verifying ownership for the frontend service, even after migrating DNS management to Cloudflare (previously on Spaceship, which is not a documented-supported provider for apex CNAME flattening).

Domain: zodd.fun

Domain ID: 587c4630-6eb3-4223-a4fe-f7c39d3df04a

Request ID from a "Not Found" error page served on the domain: uCPaF812Qd-D_CYxH4GxDA

What I've done so far:

  • Migrated DNS from Spaceship to Cloudflare (Free plan)
  • Added a CNAME record: zodd.fun -> eq9fj139.up.railway.app (Proxy status: DNS only / grey cloud)
  • Added the TXT ownership verification record: _railway-verify.zodd.fun = railway-verify=b1a9b15e8ceb98db51d81f85c9260573ec55121f91e0a35d86bfac6f5714f694
  • Switched nameservers at the registrar to Cloudflare's (guss.ns.cloudflare.com / stevie.ns.cloudflare.com)
  • Nameserver propagation has completed

Current symptoms:

  • The domain now serves a valid SSL certificate (the earlier NET::ERR_CERT_COMMON_NAME_INVALID browser error is gone), so DNS/Cloudflare appears to be routing correctly
  • However, visiting the domain in a browser now returns Railway's own "Not Found" page with the Request ID above
  • In the Railway dashboard, the domain still shows verified: false and status CERTIFICATE_STATUS_TYPE_VALIDATING_OWNERSHIP, unchanged since before the Cloudflare migration

Additional note: an automated fetch of https://zodd.fun reported the site loading with no SSL/error issues, which conflicts with what I'm seeing directly in-browser (cert error, then "Not Found") -- flagging this discrepancy in case it's useful.

Could you help confirm whether the CNAME/TXT records are correctly detected on Railway's side, and why domain verification hasn't progressed since the DNS migration?

Solved

1 Replies

Railway
BOT

a month ago

Your CNAME is correctly propagated and resolving to our edge, but the TXT verification record contains a token from a previous domain entry. The token changed when the domain entry was recreated (this happens if the domain was removed and re-added, or the service/environment was recreated), so the value at your registrar no longer matches what we expect. Update the TXT record with the current verification token shown in your service's Settings under the domain's DNS records, and verification and certificate issuance will resume automatically once the new value propagates.


Status changed to Awaiting User Response Railway • 28 days ago


Railway
BOT

21 days ago

This thread has been marked as solved automatically due to a lack of recent activity. Please re-open this thread or create a new one if you require further assistance. Thank you!

Status changed to Solved Railway • 21 days ago


Welcome!

Sign in to your Railway account to join the conversation.

Loading...