Security & Threat Intelligence · 13.08.2026, 21:40 UTC
AWS Certificate Manager will discontinue email validation to prove domain validation for certificates
| Schweregrad | info |
|---|---|
| Kategorie | Security & Threat Intelligence |
| Quelle | AWS Security Blog ↗ |
| Veröffentlicht | 13.08.2026 UTC |
Sicherheitsmeldung mit Schweregrad noch nicht bewertet. Technische Details im Tab „Originaltext“; empfohlene Schritte in der Checkliste.
Today, we’re announcing that AWS Certificate Manager (ACM) will discontinue support for email-validated public certificates by September 30, 2027. If you use email validation for your ACM public certificates, you need to migrate to DNS validation before that date. This change aligns with the Certification Authority/Browser (CA/B) Forum’s industry-wide deprecation of email-based domain validation and gives you a full year to migrate ahead of the Forum’s March 2028 deadline. In this blog post, we share the rationale for this change, the timeline, and the steps you can take to migrate your certificates to DNS validation. Background The CA/B Forum sets the standards that browsers and certificate authorities must follow for publicly trusted certificates. In November 2025, they voted to end support for email-based domain validation effective March 15, 2028. After that date, certificates validated through email won’t be trusted by browsers, regardless of which certificate authority issued them. ACM will be deprecating its email validation in-line with the CA/B Forum’s requirements, by September 30, 2027. The ACM timeline gives customers one year to migrate before the CA/B Forum’s hard deadline. Timelines for these changes If you currently use email validation for certificates requested from ACM, there are a few important dates that you should be aware of: January 1, 2027: ACM will no longer offer email validation in new AWS Regions. March 31, 2027: ACM will no longer offer email validation for new certificate requests in any Region. September 30, 2027: ACM …