23 days ago
Custom domains stuck on "Validating domain ownership" — DNS verified, cert won't provision
Two custom domains on my service have been stuck on CERTIFICATE_STATUS_TYPE_VALIDATING_OWNERSHIP for 18+ hours
despite correct DNS.
Project ID: f1b41134-6aba-405a-b386-f9ae55514f95
Service ID: 064ba819-74a6-42a9-a904-2c7c85c2c5ba
Environment: production (54393883-0d14-44bd-829a-e16b66be5d91)
Stuck domains:
- clip.lifeinlilac.com (domain ID: a7c585f6-7c84-4d38-b727-874cd4af504d)
- appclip.lifeinlilac.com (domain ID: 55ec64a5-042f-4f12-98d8-da71063f9fa6)
DNS is correct and propagated:
- CNAME clip → mg3dn3fj.up.railway.app (confirmed via dig @8.8.8.8)
- CNAME appclip → 6ff5lcrt.up.railway.app (confirmed via dig @8.8.8.8)
- Both TXT _railway-verify records resolve correctly
What I've tried:
- Verified DNS propagation on Google DNS (8.8.8.8) and GoDaddy nameservers
- Ran customDomainIssueCertificate mutation — returned true but status unchanged
- Redeployed the service
- No CAA records blocking Let's Encrypt
- No conflicting A records on the subdomains
Other custom domains on same service work fine:
- ordershipping.lifeinlilac.com — CERTIFICATE_STATUS_TYPE_VALID
- scheels.lifeinlilac.com — CERTIFICATE_STATUS_TYPE_VALID
- returns.lifeinlilac.com — CERTIFICATE_STATUS_TYPE_VALID
Can someone look into why cert provisioning is stuck for these two domains?
4 Replies
23 days ago
Both stuck domains have a TXT record value with a duplicated prefix. The records currently resolve to railway-verify=railway-verify=… but the value must start with railway-verify= exactly once. For the record at _railway-verify.clip, set the value to railway-verify=266e6174f8a8b5436d786094b328e7535003f19564c17b1b08f091483bba1825. For the record at _railway-verify.appclip, set it to railway-verify=b1e7e2262289b4c5319d1f476eeb828010a4bdce12f1f4328c5667c4b5d88ec7. Verification and certificate issuance will resume automatically once the corrected values propagate.
Status changed to Awaiting User Response Railway • 23 days ago
Railway
Both stuck domains have a TXT record value with a duplicated prefix. The records currently resolve to `railway-verify=railway-verify=…` but the value must start with `railway-verify=` exactly once. For the record at `_railway-verify.clip`, set the value to `railway-verify=266e6174f8a8b5436d786094b328e7535003f19564c17b1b08f091483bba1825`. For the record at `_railway-verify.appclip`, set it to `railway-verify=b1e7e2262289b4c5319d1f476eeb828010a4bdce12f1f4328c5667c4b5d88ec7`. Verification and certificate issuance will resume automatically once the corrected values propagate.
23 days ago
fixed
Status changed to Awaiting Railway Response Railway • 23 days ago
Status changed to Solved Railway • 23 days ago
jeffreysilverman22
fixed
22 days ago
and still not working
Status changed to Awaiting Railway Response Railway • 22 days ago
22 days ago
One of the two domains is now verified and has a valid certificate. The other is still stuck because its TXT record at _railway-verify.clip still contains a duplicated prefix, reading railway-verify=railway-verify=… instead of the required railway-verify=266e6174f8a8b5436d786094b328e7535003f19564c17b1b08f091483bba1825. Correct that value at your registrar and verification will resume automatically once it propagates.
Status changed to Awaiting User Response Railway • 22 days ago
15 days ago
This thread has been marked as solved automatically due to a lack of recent activity. Please re-open this thread or create a new one if you require further assistance. Thank you!
Status changed to Solved Railway • 15 days ago