raimzeal.com stuck at CERTIFICATE_STATUS_TYPE_ISSUING since 2026-07-15 — DNS correct, retry blocked
eniggie
HOBBYOP

18 days ago

Hi Railway team — my apex custom domain has been stuck mid-issuance since 2026-07-15 and every self-serve remedy is blocked. The apex currently returns 000 (no response) for end users.

Project: d4f3455e-78cc-437c-b3d9-e73de2a8c454

Service: raimzeal | Environment: production

Domain: raimzeal.com | Domain ID: d65f039a-be7f-471a-b4aa-e11e9e0b2841

Account: eniggie@gmail.com (ECONTEUR LLC)

What "railway domain status raimzeal.com" reports:

Sync status: ACTIVE

Verified: no

Certificate status: CERTIFICATE_STATUS_TYPE_ISSUING

Updated: 2026-07-15T15:15:05.294+00:00 — unchanged for about 3 weeks

DNS is correct and has been for weeks. The zone was moved to Cloudflare and the apex uses CNAME flattening:

raimzeal.com — A — 69.46.46.73

selspwby.up.railway.app — A — 69.46.46.73 (identical; flattening resolves to your edge)

_railway-verify.raimzeal.com — TXT — "railway-verify=95e6944f37dce139b2d053627f5abcf121173ca18c5554a28367797a29878b1a"

Verified identical from the authoritative nameservers, 8.8.8.8 and 1.1.1.1. The TXT value matches the expected value shown in the dashboard exactly, character for character. The dashboard shows the CNAME row green and the _railway-verify row warning, so I believe the verification check is stale from before the nameserver move and is not being re-run.

Already tried:

  1. "railway domain certificate retry raimzeal.com" was refused with: "Certificate retry is only available after certificate issuance fails. Current status: CERTIFICATE_STATUS_TYPE_ISSUING." The stuck ISSUING state itself blocks the retry path.
  2. "railway redeploy" on the service produced no change; the Updated timestamp is still 2026-07-15.
  3. Confirmed propagation from multiple resolvers over several days.

Ask: please force a server-side re-verification or reset the certificate state for domain d65f039a-be7f-471a-b4aa-e11e9e0b2841 so issuance can complete. If this is a Let's Encrypt rate-limit backoff, please tell me the window so I can stop chasing DNS.

Please do not advise removing and re-adding the domain. This account is at its custom-domain limit, so if the re-add were refused the apex would be stranded with no way back. I need it resolved in place.

Context: www.raimzeal.com is already served correctly by this same Railway service. Only the apex is affected.

Thank you.

Solved

1 Replies

Status changed to Awaiting Railway Response Railway 18 days ago


18 days ago

Your DNS is correct and the TXT verification token matches. The certificate workflow stalled before your DNS was in place and never re-ran once it propagated. We've triggered a certificate re-issue for raimzeal.com, which will re-run verification and complete issuance. It may take a few minutes to finish.


Status changed to Awaiting User Response Railway 18 days ago


Railway
BOT

11 days ago

This thread has been marked as solved automatically due to a lack of recent activity. Please re-open this thread or create a new one if you require further assistance. Thank you!

Status changed to Solved Railway 11 days ago


Welcome!

Sign in to your Railway account to join the conversation.

Loading...