Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Critical Azure Vulnerability Exposes Millions of Enterprise Records
August 16, 2026
AWS Certificate Manager Ends Email Validation for Public Certificates
August 16, 2026
Microsoft Merges Consumer and Enterprise Copilot Apps
August 16, 2026
Home/CyberSecurity News/AWS Certificate Manager Ends Email Validation for Public Certificates
CyberSecurity News

AWS Certificate Manager Ends Email Validation for Public Certificates

Key Takeaways AWS Certificate Manager (ACM) is phasing out email-based domain validation for public certificates. The complete termination of email-based automated renewals is scheduled for September...

David kimber
David kimber
August 16, 2026 4 Min Read
3 0

Key Takeaways

  • AWS Certificate Manager (ACM) is phasing out email-based domain validation for public certificates.
  • The complete termination of email-based automated renewals is scheduled for September 30, 2027.
  • This change aligns with a global mandate from the CA/B Forum, which will lead major browsers to distrust email-validated certificates from March 15, 2028.
  • Customers must transition to DNS validation, but AWS has provided tools to facilitate this without service disruption.

AWS Certificate Manager Ends Email Validation

AWS Certificate Manager (ACM) has announced a definitive timeline to discontinue email-based domain control validation (DCV) for public certificate renewals. The final cutoff for this method is set for September 30, 2027. This strategic shift aims to bring AWS cloud infrastructure into alignment with stringent global trust requirements established by the Certificate Authority and Browser (CA/B) Forum. Consequently, cloud architects, DevOps engineers, and security professionals are now tasked with migrating any remaining legacy certificates to DNS validation.

Table Of Content

  • Key Takeaways
  • AWS Certificate Manager Ends Email Validation
  • Accelerated Phaseout Schedule
  • Streamlined Transition to DNS Validation
  • What You Should Do

This move by AWS follows a pivotal decision made by the CA/B Forum in November 2025 to abolish email-based domain validation for public TLS/SSL certificates. A critical deadline looms: by March 15, 2028, leading web browsers will cease to trust any public certificate that was validated using email verification, irrespective of the issuing Certificate Authority (CA).

The cryptographic community has long identified email validation as a weak point, susceptible to various vulnerabilities. Risks include compromised mail exchange (MX) routing, potential interception of verification links, and reliance on outdated WHOIS administrative contacts, all of which introduce significant supply-chain security concerns. Adhering to contemporary standards for SSL/TLS certificate protection is crucial for organizations to maintain robust control over identity validation and preempt unexpected browser distrust issues.

Accelerated Phaseout Schedule

To proactively safeguard customer workloads from potential certificate renewal failures well in advance of the 2028 browser distrust deadline, AWS is implementing an accelerated, multi-stage phaseout plan:

  • January 1, 2027: Email validation will be restricted in newly launched AWS Regions.
  • March 31, 2027: Email validation will be prohibited for all newly requested certificates across every AWS Region.
  • September 30, 2027: Complete termination of email-based automated renewals within ACM.
  • March 15, 2028: The global CA/B Forum deadline, after which major browsers will distrust all email-validated certificates.

Streamlined Transition to DNS Validation

To facilitate a seamless transition without necessitating extensive infrastructure modifications, AWS has updated its certificate management APIs. These enhancements now support in-place validation method changes. Cloud engineers are no longer required to reissue certificates, reconfigure load balancer endpoints, or update Amazon Resource Names (ARNs) associated with Application Load Balancers (ALBs) or Amazon CloudFront distributions.

As detailed in the official announcement on the AWS Security Blog, administrators can leverage the UpdateCertificateOptions API. This allows for switching an active certificate’s validation method from email to DNS without causing any disruption to live traffic.

When initiating an update, whether through the AWS Management Console or the AWS CLI, the process unfolds as follows:

  1. ACM generates a unique CNAME record specifically for the customer.
  2. The administrator then publishes this record to their authoritative DNS servers.
  3. Organizations are provided a 72-hour window to complete DNS propagation, during which the certificate continues to operate actively under its existing email validation status.

For teams that utilize Amazon Route 53, the ACM console offers a convenient one-click workflow to automatically insert the necessary CNAME records into hosted zones. Enhancing authoritative name resolution with modern DNS security solutions can help protect these automated record updates from potential hijacking.

The migration from email approvals to DNS validation significantly bolsters cloud security by eliminating manual human intervention from the certificate renewal process. Once the designated CNAME record is successfully verified, ACM will automatically reissue and bind renewed certificates before their expiration, ensuring continuous security.

For specialized configurations employing Amazon CloudFront, AWS also provides an HTTP-based token validation path. This serves as an alternative automated mechanism for securing TLS communication protocols.

What You Should Do

  • Identify Email-Validated Certificates: Review your AWS Certificate Manager inventory to identify all public certificates currently using email validation.
  • Plan Your Transition: Develop a strategy to migrate these certificates to DNS validation well before the September 30, 2027, deadline.
  • Utilize AWS Tools: Leverage the UpdateCertificateOptions API, AWS Management Console, or AWS CLI to switch validation methods.
  • Implement DNS Records: Ensure the accurate and timely publication of CNAME records to your authoritative DNS servers. For Amazon Route 53 users, utilize the one-click integration.
  • Consider CloudFront Alternatives: If using Amazon CloudFront, explore the HTTP-based token validation path as an alternative automated mechanism.
  • Stay Informed: Regularly check the AWS Security Blog for further updates and best practices.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

Security

Share Article

David kimber

David kimber

David is a penetration tester turned security journalist with expertise in mobile security, IoT vulnerabilities, and exploit development. As an OSCP-certified security professional, David brings hands-on technical experience to his reporting on vulnerabilities and security research. His articles often feature detailed technical analysis of exploits and provide actionable defense recommendations. David maintains an active presence in the security research community and has contributed to multiple open-source security tools.

Previous Post

Microsoft Merges Consumer and Enterprise Copilot Apps

Next Post

Critical Azure Vulnerability Exposes Millions of Enterprise Records

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Microsoft Entra ID to Default to Passkeys, Retiring SMS and Voice MFA
August 15, 2026
AI Agents Persist, Rewrite Tools to Continue Attacks After Initial Malware Fails
August 14, 2026
Critical Citrix NetScaler Heap Overflow (CVE-2023-3519) Allows Remote Code Execution
August 14, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Emy Elsamnoudy
Emy Elsamnoudy
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us