Users must transition because email validation will be phased out by March 15, 2028, and DNS validation enables automated renewals.
- Enables changing the domain validation method on existing ACM-issued public TLS certificates from e-mail to DNS without reissuing certificates or changing Amazon Resource Names (ARNs).
- Existing ARN references in CI/CD pipelines, load balancer configurations, and other AWS service integrations continue to work without modification.
- ACM will phase out support for email validation throughout 2027 in response to the CA/B Forum mandated deprecation effective March 15, 2028.
- ACM will stop issuing email-validated certificates starting March 31, 2027, and stop renewing email-validated certificates on September 30, 2027.
- Validation method can be switched via the ACM console or the UpdateCertificateOptions API, with a 72-hour window to add provided CNAME records to DNS.
- Feature is available across all AWS Regions where ACM certificates are supported.