SSLmentor

Quality TLS/SSL certificates for websites and internet projects.

domain validation

domain validation

Domain Verification - SSL Certificates

Domain validation is required before any SSL certificate can be issued. It is an essential requirement for the CA to immediately issue a domain certificate (DV) or to start organization validation (OV and EV certificates). All validations are performed by the certificate authority. Let’s take a look at the available domain validation methods.

EMAIL validation

The fastest way to verify a domain is email validation (DCV). The certificate authority sends a verification email to the selected address, and the domain owner or administrator clicks the link inside to confirm the certificate request. The entire process takes only a few minutes, and the certificate is issued immediately after approval.

Only the following email addresses are available for domain confirmation: admin@, administrator@, webmaster@, hostmaster@, postmaster@.
The offered email addresses are set according to CA/B Forum rules and no other email can be used! The verification email cannot be sent to a personal address, e.g., myname@gmail.com.
The validation email address on the domain must be created and active. If none of the listed email addresses are available, one must be created. It can also be an alias pointing to an existing email address on the domain.

Starting March 15, 2028, email domain verification will be DISCONTINUED! Only verification via DNS records and HTTP/HTTPS files will remain allowed.

What to do if the validation email does not arrive?

The validation email is sent directly by the certificate authority immediately after ordering the certificate from the CA. Certificate authorities usually send validation emails from no-reply addresses (CA Sectigo noreply_support@trust-provider.com, CA RapidSSL from no-reply@rapidssl.com).
The validation email can be resent at any time. Resending is done in the Administration panel: Certificate details -> Order information -> Validation type: -> edit -> Send.

Important: If the validation email cannot be received even after multiple attempts, check the domain name to ensure there was no typo when ordering. It is also possible that your provider has anti-spam filters configured such that emails from foreign authorities are rejected. In that case, you need to contact your email service provider or consider using DNS/HTTP(S) validation.

DNS validation

Configuring domain DNS records is usually done with the hosting provider or domain registrar. The certificate authority generates a unique token that you add to your DNS as a TXT record, or configured as a CNAME (PositiveSSL certificates). As soon as the record is added to DNS and propagates, the certificate authority can check the record, and if it is correct, the domain is verified.

There are two ways to configure the TXT record in your DNS settings. The certificate authority checks both records, and at least one must be set up correctly.

  • Host: yourdomain.com
  • prefix _dnsauth → Host: _dnsauth.yourdomain.com
Example of DNS validation using a TXT record
DNS TXT record: d3pyrjg65d8hh1bv0tgr4bx890yksq8j
Example of DNS validation using a CNAME record
DNS CNAME record: _cfd00c1ec2d56372b27b9562f5da83d0.yourdomain.com CNAME
cb3a889855882c6518c0ac959be30067.e8349bfb8ec9a0334864d9bf350a1188.t0119001001421510849.comodoca.com

Important:

  • If you request a certificate for www.yourdomain.com, the TXT record must still be placed on the root domain (yourdomain.com).
  • For higher-level domains (subdomains), DNS records must be set up at the same level.
  • Propagation of a new DNS record can take up to 30 minutes, and in some cases even longer.
  • Always verify that the record is available using online tools like digwebinterface.com or whatsmydns.net.

File-Based Authentication (HTTP(S) validation)

This DCV method validates the domain using a file on the server. The certificate authority verifies the domain via a TXT file placed in the web space of the domain. The publicly accessible file contains a text string (token) that must be uploaded to the /.well-known/pki-validation/ directory of the website. The certificate authority checks the file to confirm that you control the domain. Each request always has its own text strings, which are specified in the order details. The strings shown below are for illustration purposes only.

Example of HTTP(S) validation for a RapidSSL certificate
File name: fileauth.txt
File path: http://yourdomain.com/.well-known/pki-validation/fileauth.txt
File content (token):
 8CC79447A5MTg4MzY1MA2#!cm5ywz5m1lzoyfp2xhy7

The text file contains only the token, without any additional information.
The following path must also be valid: http://www.yourdomain.com/.well-known/pki-validation/fileauth.txt
Example of HTTP(S) validation for a Sectigo PositiveSSL certificate
File name: 048B0565E245687S52C7801EA7D4B954F3.txt
File path: http://yourdomain.com/.well-known/pki-validation/048B0565E245687S52C7801EA7D4B954F3.txt
File content:
 ecf434d0ef25e1ae777fbc7e98fb996182a7353254796fe586088809e4adec7d
 sectigo.com
 a40cfr5ef4a5ba6d365d

Each line must contain only the specified value.
The following path must also be valid: http://www.yourdomain.com/.well-known/pki-validation/048B0565E245687S52C7801EA7D4B954F3.txt

Important:

  • The verification file must be accessible at the address without "www" and also at the address with "www". This also applies when requesting a certificate for a domain with "www", e.g., www.yourdomain.com.
  • If you order an SSL certificate for the domain yourdomain.com and the file is accessible only on the domain http(s)://yourdomain.com, but is not available on www.yourdomain.com, then the SSL certificate will be issued for the domain yourdomain.com only. This principle also applies in reverse — an order for www.yourdomain.com without the file accessible on yourdomain.com will result in a certificate issued only for www.yourdomain.com.
  • For higher-level domains (subdomains), files must be set up at the same level.
  • For WildCard SSL certificates, the HTTP(S) verification method can no longer be used.
  • Always verify yourself that the file is available and displays in your browser!

IP address validation

IP address validation works the same way as HTTP(S) validation. A file must be placed on the server so that it is accessible to the certificate authority at IP/.well-known/pki-validation/. The certificate authority verifies its existence, thereby validating that the applicant has control over the IP address management.

http(s)://9.9.9.9/.well-known/pki-validation/fileauth.txt

Back to Help
Found an error or don't understand something? Write us!

CA Sectigo
CA RapidSSL
CA Thawte
CA GeoTrust
CA DigiCert
CA Certum