Wildcard ownership remains verified=false after six hours with exact TXT
austinmao
PROOP

a month ago

Provider-side ownership verification recheck requested.

Project: 27863013-7715-45c1-8c32-97d591f60218 (od-edge-staging2)

Environment: production, 99dd2d74-432c-4a14-840f-d34199a8928c

Service: od-edge, 86f3f536-91d6-49b0-a358-d8c865c54b33

Deployment: a65dae02-fa2d-4517-86f0-4d0529550da4, SUCCESS/RUNNING

Custom domain: *.od.staging.holalumina.com

Custom domain ID: 5bf1fae9-34ab-4b96-94fb-ea78ba8df953

The domain is ACTIVE on target port 8080. Its certificate is VALID/COMPLETE. Railway reports both traffic and ACME CNAME records propagated. The exact ownership TXT value currently returned by Railway resolves without drift from both authoritative Cloudflare nameservers, the system resolver, 1.1.1.1, and 8.8.8.8. The TXT has remained present for more than six hours (created 2026-07-15T09:04:45Z), but domain status still reports verification.verified=false. A concrete workspace hostname returns HTTP 404 with x-railway-fallback=true.

No domain, CNAME, port, service variable, certificate, or deployment mutation has been attempted after adding the required TXT. Please force or retrigger only the provider-side ownership verification check and confirm when the domain flag becomes verified=true. Do not delete or recreate the domain. The TXT token value is intentionally omitted from this thread.

$20 Bounty

2 Replies

Railway
BOT

a month ago

This thread has been opened as a public bounty so the community can help solve it. The thread and any further activity are now visible to everyone.

Status changed to Open Railway about 1 month ago


Try disabling Cloudflare proxy on your CNAME.

If that doesn’t work, you can also try removing the domain from Railway and add it back after ~10-15 mins if that doesn’t work. Update DNS records as necessary.


austinmao
PROOP

a month ago

Thanks. Both relevant Cloudflare CNAMEs are already DNS-only, not proxied: the wildcard traffic CNAME and the _acme-challenge CNAME each report proxied=false. Railway also reports both CNAMEs propagated, the certificate VALID/COMPLETE, and the domain ACTIVE on port 8080. The exact _railway-verify TXT required by Railway resolves from both authoritative nameservers and public resolvers, but verified=false and x-railway-fallback persist after six hours. Deleting/re-adding the domain is intentionally excluded because it would discard the existing domain identity and valid certificate. Please have Railway staff run the provider-side ownership verification recheck for custom domain ID 5bf1fae9-34ab-4b96-94fb-ea78ba8df953. The TXT value is omitted.


Welcome!

Sign in to your Railway account to join the conversation.

Loading...