VALID custom-domain cert, but verified=false and x-railway-fallback
andriy555solar-afk
PROOP

a month ago

Hostname: solomiya-energy.com

Project: triumphant-purpose

Project ID: bce49d08-22a4-4aae-b1ef-30559f106a7a

Environment: production

Environment ID: f912566e-20fc-41e4-a361-c46b86efd122

Service: marketing-web-rirw

Service ID: 06999409-9d2a-4389-b5e8-7055af5fa287

Domain ID: fac686ab-6a13-48ad-848b-c7f71e1ebf45

Target port: 8080

Current state as of 2026-07-16 18:46:32 +03:

  • certificateStatus: CERTIFICATE_STATUS_TYPE_VALID
  • Presented TLS certificate: CN=solomiya-energy.com, SAN=DNS:solomiya-energy.com
  • verified: false
  • dnsRecordStatus: DNS_RECORD_STATUS_PROPAGATED
  • syncStatus: ACTIVE
  • requiredValue: bsigib98.up.railway.app
  • currentValue: "" (empty in Railway GraphQL)
  • Public DNS resolves the apex to 69.46.46.71, the required Railway target
  • The _railway-verify TXT record is present and matches Railway's required value
  • https://solomiya-energy.com returns HTTP 404
  • Server: railway-hikari
  • x-railway-fallback: true
  • No X-Tilda headers
  • The Railway service hostname marketing-web-rirw-production.up.railway.app returns HTTP 200 without the fallback header

Railway GraphQL lists this custom domain only under the correct production service marketing-web-rirw with targetPort 8080. Therefore it does not appear attached to the wrong service, environment, or port.

Mutation history for transparency:

  • 2026-07-16 18:17:04 +03:

    customDomainIssueCertificate returned true.

    The certificate changed from ISSUING to VALID.

  • 2026-07-16 18:22:08 +03:

    customDomainUpdate returned true.

    targetPort remained 8080, but verified remained false and the apex continued returning the Railway fallback 404.

The domain was not deleted or re-added. No redeploy was performed. DNS has not been changed since the controlled cutover.

The production apex has been unavailable since approximately 2026-07-16 10:07 +03.

Please inspect and repair or requeue the internal custom-domain verification and edge-to-service routing binding for this domain without requiring domain deletion/re-creation.

There are also two pre-existing pending changes shown in the Railway project UI. They have not been inspected or applied. Please advise whether they are related before we apply anything.

$10 Bounty

4 Replies

Railway
BOT

a month ago

This thread has been opened as a bounty so the community can help solve it.

Status changed to Open Railway about 1 month ago


Try to remove your custom domain and all its related DNS records, wait for 10 - 15 minutes, and add it again.


darseen

Try to remove your custom domain and all its related DNS records, wait for 10 - 15 minutes, and add it again.

andriy555solar-afk
PROOP

a month ago

Thanks for the suggestion. Before performing a destructive domain reset, could a Railway team member confirm that this is required for this specific domain?

The certificate is already VALID, the required CNAME and _railway-verify TXT records are present, DNS is PROPAGATED with syncStatus ACTIVE, and the Railway service hostname returns HTTP 200.

However, Railway still reports verified=false and currentValue="", while the production apex returns HTTP 404 with x-railway-fallback:true.

Railway’s SSL troubleshooting documentation warns against repeatedly deleting and re-adding domains because of Let’s Encrypt duplicate-certificate rate limits, and this domain has already gone through a certificate reissue.

Could Railway staff please inspect or requeue the internal domain verification and edge-to-service routing binding, or provide the exact required reset and rollback procedure?

I will not change the domain or DNS records until Railway staff confirms the procedure.


andriy555solar-afk
PROOP

a month ago

Custom domain solomiya-energy.com (domainId: fac686ab-6a13-48ad-848b-c7f71e1ebf45) reaches the Railway edge directly and is served a valid Railway-issued Let’s Encrypt certificate for solomiya-energy.com, but requests return:

  • HTTP 404
  • server: railway-hikari
  • x-railway-fallback: true
  • x-railway-edge: ams1

The required _railway-verify.solomiya-energy.com TXT record is published exactly once and returns the same value from both authoritative Cloudflare nameservers (gloria.ns.cloudflare.com, yichun.ns.cloudflare.com) and from multiple public validating resolvers (system, 1.1.1.1, 8.8.8.8, 9.9.9.9):

railway-verify=657f9ddabaed0a2894bed0e64bdb999cd3393538ac130489d6d42dcb49cd42e9

External DNS publication, propagation and DNSSEC are verified. Cloudflare zone shows:

  • Apex: CNAME @bsigib98.up.railway.app (DNS only / grey cloud; public A flatten = 69.46.46.71)
  • TXT _railway-verify → matching token (DNS only)
  • www remains a separate CNAME to Pages and was not modified

The Railway API/dashboard snapshot (2026-07-17 ~01:36–01:43 UTC+3) shows:

  • verificationToken: railway-verify=657f9ddabaed0a2894bed0e64bdb999cd3393538ac130489d6d42dcb49cd42e9 (MATCH to published TXT)
  • ownership/DNS status: verified=false (UI: TXT yellow triangle; banner “Waiting for DNS update”)
  • CNAME traffic-route record: DNS_RECORD_STATUS_PROPAGATED (UI green check)
  • certificateStatus: CERTIFICATE_STATUS_TYPE_VALID / detailed COMPLETE
  • certificate issuedAt: 2026-07-16T14:18:47.000Z, expiresAt: 2026-10-14T14:18:46.000Z
  • fingerprintSha256: c7cb962a2b09cfa299ca2bbd14334355ee03ee4c90d28fc0c28f936a797539e3
  • serviceId: 06999409-9d2a-4389-b5e8-7055af5fa287 (marketing-web-rirw)
  • environmentId: f912566e-20fc-41e4-a361-c46b86efd122 (production)
  • projectId: bce49d08-22a4-4aae-b1ef-30559f106a7a (triumphant-purpose)
  • targetPort: 8080
  • syncStatus: ACTIVE
  • edgeId: edge-6705e5cc5ae5e82ae931d2b1f900f08f
  • latestDeployment: 8addda04-fd64-4de8-9b19-2ed9a63620f8 SUCCESS, commit 85b2229cd1f1f005faf5a9e3a572912a8c801c26
  • control hostname marketing-web-rirw-production.up.railway.app returns HTTP 200 without x-railway-fallback

Please inspect the existing custom-domain object and:

  1. Confirm the stored ownership-verification state and latest TXT lookup result.
  2. Re-run or reconcile the ownership-verification job if the stored token matches the published TXT.
  3. Confirm the hostname binding to the intended service and environment.
  4. Confirm the stored target port (8080).
  5. Reconcile or republish the hostname-to-service mapping at the Railway edge if ownership is already valid or after verification flips to true.

Please do not delete and recreate the domain. We need to preserve the existing domain ID and diagnostic state, and the certificate was issued recently (2026-07-16).

Probe timestamps (UTC):

  • Baseline HTTP apex/service: 2026-07-16 22:27–22:28
  • GraphQL domain snapshot: 2026-07-16 22:36
  • Post DNS-modal recheck snapshot + apex retest: 2026-07-16 22:42–22:43

andriy555solar-afk

Thanks for the suggestion. Before performing a destructive domain reset, could a Railway team member confirm that this is required for this specific domain? The certificate is already VALID, the required CNAME and _railway-verify TXT records are present, DNS is PROPAGATED with syncStatus ACTIVE, and the Railway service hostname returns HTTP 200. However, Railway still reports verified=false and currentValue="", while the production apex returns HTTP 404 with x-railway-fallback:true. Railway’s SSL troubleshooting documentation warns against repeatedly deleting and re-adding domains because of Let’s Encrypt duplicate-certificate rate limits, and this domain has already gone through a certificate reissue. Could Railway staff please inspect or requeue the internal domain verification and edge-to-service routing binding, or provide the exact required reset and rollback procedure? I will not change the domain or DNS records until Railway staff confirms the procedure.

As Darseen suggested, please remove your domain from Railway and add it back after ~10-15 mins. Update DNS records as necessary.


Welcome!

Sign in to your Railway account to join the conversation.

Loading...