a month ago
Hi Railway team,
I'm having trouble with the SSL certificate for a custom domain on my project.
Project: content-flow
Project ID: d7e23227-f069-4163-8b4f-c60379ddfe0d
Service: AP_Business_Card
Environment: production
Custom domain: artemprokopenko.dev
The certificate for this domain stopped working (browsers show a privacy/certificate error when visiting https://artemprokopenko.dev). To try to fix it, I removed the custom domain from the service's Networking settings and re-added it. Railway generated a new CNAME target and both required DNS records (CNAME @ and the _railway-verify TXT record) show as verified/green in the dashboard. However, more than 15 minutes later, the certificate still fails and the domain still shows the privacy error in the browser.
For comparison, the Railway-generated subdomain (apbusinesscard-production.up.railway.app) loads correctly over HTTPS with a valid certificate, so the app and deployment themselves are healthy — this looks isolated to certificate issuance for the custom domain specifically.
I checked status.railway.com and don't see any ongoing incidents for Domains or Networking.
Could you please check the certificate provisioning status/logs for artemprokopenko.dev on this service and help get it reissued? Happy to provide any additional details you need.
Thanks,
Artem
4 Replies
a month ago
When you removed and re-added the custom domain, a new CNAME target was generated, but your DNS provider still has the CNAME pointed at the old one. Update the CNAME record at your DNS provider to match the target currently shown in the service's Settings under Networking, and the certificate error will clear once the new record propagates.
Status changed to Awaiting User Response Railway • 27 days ago
Status changed to Solved artemprokopenko123 • 27 days ago
a month ago
rected the stale CNAME record at my DNS provider (Namecheap) to point to the new target shown in Railway's Networking settings. Both DNS records (CNAME and TXT) now show verified/green in the Railway dashboard. However, it's now been over 30 minutes since the DNS fix and https://artemprokopenko.dev still shows a certificate/privacy error in the browser, while the app itself is healthy (the Railway-generated subdomain loads fine over HTTPS). Could someone check the certificate provisioning status/logs for this domain? Happy to provide anything else needed.
Status changed to Awaiting Railway Response Railway • 27 days ago
a month ago
Your domain's certificate is valid and complete on our side, and edge routing is working normally. Public DNS resolvers are still caching the previous CNAME target from the earlier domain entry, which is expected to clear once the old record's TTL expires (up to 24 hours depending on what your previous TTL was set to). You can try flushing your local DNS cache or testing from a different network to confirm the new record is serving correctly elsewhere.
Status changed to Awaiting User Response Railway • 27 days ago
a month ago
Confirmed fixed — it was DNS/browser caching of the old CNAME as you predicted. Working correctly now from a fresh browser/network. Thanks for the help!
Status changed to Awaiting Railway Response Railway • 27 days ago
Status changed to Solved Railway • 27 days ago