Home icon

AWS Certificate Manager will discontinue email validation to prove domain validation for certificates

Security Blog



This article announces that AWS Certificate Manager (ACM) will discontinue email validation for public certificates by September 30, 2027, aligning with CA/B Forum industry standards.

  • Email validation will no longer be offered for new certificates starting March 31, 2027
  • Existing email-validated certificates must migrate to DNS or HTTP validation before September 30, 2027
  • Updated UpdateCertificateOptions API allows switching validation method in-place without changing certificate ARN
  • DNS validation recommended for most use cases; HTTP validation available for CloudFront certificates
  • ACM automatically renews DNS-validated certificates with no manual intervention required
  • Tools provided to identify email-validated certificates via console or AWS CLI

This change ensures certificates remain trusted as industry standards evolve and simplifies certificate lifecycle management through automatic renewals.



Go to article

The AWS News Feed is currently looking for gold sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.

Related articles

Aug 13
2026
AWS Certificate Manager supports switching from e-mail to DNS validation
Jan 9
2024
AWS Certificate Manager will discontinue WHOIS lookup for email-validated certificates
Feb 19
2026
AWS Certificate Manager updates default certificate validity to comply with new guidelines
Jul 6
2026
AWS Certificate Manager now supports the ACME protocol for public certificates

The AWS News Feed is currently looking for silver sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.