AWS Certificate Manager now allows customers to change the domain validation method on existing public TLS certificates from email to DNS without reissuing certificates or changing ARNs.
Aug 13, 2026
18d agoKey Details
- Enables changing the domain validation method on existing ACM-issued public TLS certificates from e-mail to DNS without reissuing certificates or changing Amazon Resource Names (ARNs).
- Existing ARN references in CI/CD pipelines, load balancer configurations, and other AWS service integrations continue to work without modification.
- ACM will phase out support for email validation throughout 2027 in response to the CA/B Forum mandated deprecation effective March 15, 2028.
- ACM will stop issuing email-validated certificates starting March 31, 2027, and stop renewing email-validated certificates on September 30, 2027.
- Validation method can be switched via the ACM console or the UpdateCertificateOptions API, with a 72-hour window to add provided CNAME records to DNS.
- Feature is available across all AWS Regions where ACM certificates are supported.