AWS Certificate Manager supports switching from e-mail to DNS validation
News
AWS Certificate Manager (ACM) now enables switching existing ACM-issued public TLS certificates from email to DNS validation without reissuing or changing the certificate ARN.
- Email validation is being deprecated by CA/B Forum; ACM stops issuing email-validated certificates March 31, 2027
- Certificate ARN remains unchanged after switching validation methods, preserving CI/CD and AWS service integrations
- Use ACM console or UpdateCertificateOptions API to switch validation methods
- ACM provides CNAME records for each domain with 72 hours to add to DNS configuration
- Monitor validation status via console or ListCertificateDomainValidations API
- DNS validation enables fully automated certificate renewals and is recommended for new certificates
This feature is available across all AWS Regions where ACM certificates are supported, helping organizations transition ahead of the email validation deprecation deadline.
The AWS News Feed is currently looking for gold sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.
Related articles
Aug 13
2026
2026
AWS Certificate Manager will discontinue email validation to prove domain validation for certificates
Jul 6
2026
2026
AWS Certificate Manager now supports the ACME protocol for public certificates
Aug 6
2026
2026
Automate certificates with ACME support in AWS Certificate Manager
Feb 19
2026
2026
AWS Certificate Manager updates default certificate validity to comply with new guidelines
The AWS News Feed is currently looking for silver sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.