AWS Certificate Manager supports switching from e-mail to DNS validation
AWS Certificate Manager now allows users to switch existing public TLS certificates from e-mail to DNS validation without reissuing the certificate or changing its ARN.
Why it matters
Users must transition because email validation will be phased out by March 15, 2028, and DNS validation enables automated renewals.
The details
- Email-validated certificate issuance stops March 31, 2027.
- Email-validated certificate renewals end September 30, 2027.
- Domain validation via CNAME records must be completed within 72 hours.
Show entities and relationshipsHide entities and relationships
In this article
Key connections
Amazon owns AWS Certificate Manager
Amazon develops and operates the AWS Certificate Manager service.
AWS Certificate Manager is related to Amazon CloudFront
AWS recommends DNS validation for new certificates and HTTP validation for Amazon CloudFront distributions.
Certification Authority/Browser (CA/B) Forum regulates AWS Certificate Manager
The CA/B Forum mandated deprecation of email-based domain validation for publicly trusted certificates, prompting ACM's transition timeline.
AWS Certificate Manager uses TLS
AWS Certificate Manager issues, manages, and renews public TLS certificates.
AWS Certificate Manager uses DNS
AWS Certificate Manager supports DNS validation to verify domain control and enable automated renewals.
Amazon owns Amazon CloudFront
Amazon operates the Amazon CloudFront content delivery network.
Related events
AWS Certificate Manager supports switching from e-mail to DNS validation
Get the weekly recap
The stories like this one, picked and explained — once a week, straight to your inbox.