The certificate has been stuck on CERTIFICATE_STATUS_TYPE_VALIDATING_OWNERSHIP
daralaz77
HOBBYOP

21 days ago

Domain: api.scholabot.com, service api, project robot-school (id 14c4cf09-dec1-4a49-ad62-5c5932691594).

The certificate has been stuck on CERTIFICATE_STATUS_TYPE_VALIDATING_OWNERSHIP since 2026-09-09 (6+ days), well past the ~72h threshold your own docs mention.

I've ruled out the common causes myself:

DNS: CNAME correctly propagated, matches the required value (0q2pin0r.up.railway.app) exactly.

CAA records: none present on the domain (so no CA restriction).

DNSSEC: not enabled (no DS records at the registrar).

Not a Cloudflare-proxy issue: the record is DNS-only (grey cloud), resolves directly to the Railway hostname.

railway domain certificate retry api.scholabot.com returns: "Certificate retry is only available after certificate issuance fails. Current status: CERTIFICATE_STATUS_TYPE_VALIDATING_OWNERSHIP" — so it's not even in a retryable "failed" state.

Could someone look at this from your side? I'd rather not delete/re-add the domain given the 5-duplicate-certs-per-week Let's Encrypt rate limit you document.

(There's also an orphaned second custom domain on the same service, api.sholabot.com — a typo domain I never actually own — with no DNS ever configured for it. Happy to delete that one if it's not relevant, just flagging in case it's interfering.)

Solved

3 Replies

Railway
BOT

21 days ago

The CNAME is correctly propagated, but the TXT ownership-verification record is missing. Certificates cannot issue until that record exists. Please add a TXT record with host _railway-verify.api and value railway-verify=262267a50a578cd01aeba74ef49c6fe7fde8796a444c991483f1aa2ffe7c6212 at your DNS provider (your provider appends the zone automatically). Once it propagates, verification and certificate issuance will resume on their own, no need to remove and re-add the domain.


Status changed to Awaiting User Response Railway • 21 days ago


daralaz77
HOBBYOP

20 days ago

The TXT record has been added and has propagated, but Railway hasn't completed the re-verification; could you help by doing it manually?


Status changed to Awaiting Railway Response Railway • 20 days ago


20 days ago

Your TXT record is correctly in place and matches the expected token, but the verification workflow had stalled before it could pick up the update. A certificate re-issuance has been started for the domain and may take a few minutes to complete.


Status changed to Awaiting User Response brody • 20 days ago


Railway
BOT

13 days ago

This thread has been marked as solved automatically due to a lack of recent activity. Please re-open this thread or create a new one if you require further assistance. Thank you!

Status changed to Solved Railway • 13 days ago


Welcome!

Sign in to your Railway account to join the conversation.

Loading...