Custom domains stuck on "Validating domain ownership" — DNS verified, cert won't provision
jeffreysilverman22
PROOP

23 days ago

Custom domains stuck on "Validating domain ownership" — DNS verified, cert won't provision

Two custom domains on my service have been stuck on CERTIFICATE_STATUS_TYPE_VALIDATING_OWNERSHIP for 18+ hours

despite correct DNS.

Project ID: f1b41134-6aba-405a-b386-f9ae55514f95

Service ID: 064ba819-74a6-42a9-a904-2c7c85c2c5ba

Environment: production (54393883-0d14-44bd-829a-e16b66be5d91)

Stuck domains:

  • clip.lifeinlilac.com (domain ID: a7c585f6-7c84-4d38-b727-874cd4af504d)
  • appclip.lifeinlilac.com (domain ID: 55ec64a5-042f-4f12-98d8-da71063f9fa6)

DNS is correct and propagated:

  • CNAME clip → mg3dn3fj.up.railway.app (confirmed via dig @8.8.8.8)
  • CNAME appclip → 6ff5lcrt.up.railway.app (confirmed via dig @8.8.8.8)
  • Both TXT _railway-verify records resolve correctly

What I've tried:

  • Verified DNS propagation on Google DNS (8.8.8.8) and GoDaddy nameservers
  • Ran customDomainIssueCertificate mutation — returned true but status unchanged
  • Redeployed the service
  • No CAA records blocking Let's Encrypt
  • No conflicting A records on the subdomains

Other custom domains on same service work fine:

  • ordershipping.lifeinlilac.com — CERTIFICATE_STATUS_TYPE_VALID
  • scheels.lifeinlilac.com — CERTIFICATE_STATUS_TYPE_VALID
  • returns.lifeinlilac.com — CERTIFICATE_STATUS_TYPE_VALID

Can someone look into why cert provisioning is stuck for these two domains?

Solved

4 Replies

Railway
BOT

23 days ago

Both stuck domains have a TXT record value with a duplicated prefix. The records currently resolve to railway-verify=railway-verify=… but the value must start with railway-verify= exactly once. For the record at _railway-verify.clip, set the value to railway-verify=266e6174f8a8b5436d786094b328e7535003f19564c17b1b08f091483bba1825. For the record at _railway-verify.appclip, set it to railway-verify=b1e7e2262289b4c5319d1f476eeb828010a4bdce12f1f4328c5667c4b5d88ec7. Verification and certificate issuance will resume automatically once the corrected values propagate.


Status changed to Awaiting User Response Railway • 23 days ago


Railway

Both stuck domains have a TXT record value with a duplicated prefix. The records currently resolve to `railway-verify=railway-verify=…` but the value must start with `railway-verify=` exactly once. For the record at `_railway-verify.clip`, set the value to `railway-verify=266e6174f8a8b5436d786094b328e7535003f19564c17b1b08f091483bba1825`. For the record at `_railway-verify.appclip`, set it to `railway-verify=b1e7e2262289b4c5319d1f476eeb828010a4bdce12f1f4328c5667c4b5d88ec7`. Verification and certificate issuance will resume automatically once the corrected values propagate.

jeffreysilverman22
PROOP

23 days ago

fixed


Status changed to Awaiting Railway Response Railway • 23 days ago


Status changed to Solved Railway • 23 days ago


jeffreysilverman22

fixed

jeffreysilverman22
PROOP

22 days ago

and still not working


Status changed to Awaiting Railway Response Railway • 22 days ago


Railway
BOT

22 days ago

One of the two domains is now verified and has a valid certificate. The other is still stuck because its TXT record at _railway-verify.clip still contains a duplicated prefix, reading railway-verify=railway-verify=… instead of the required railway-verify=266e6174f8a8b5436d786094b328e7535003f19564c17b1b08f091483bba1825. Correct that value at your registrar and verification will resume automatically once it propagates.


Status changed to Awaiting User Response Railway • 22 days ago


Railway
BOT

15 days ago

This thread has been marked as solved automatically due to a lack of recent activity. Please re-open this thread or create a new one if you require further assistance. Thank you!

Status changed to Solved Railway • 15 days ago


Welcome!

Sign in to your Railway account to join the conversation.

Loading...