Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
AWS Phasing Out Email Validation for Public Certificates

AWS Phasing Out Email Validation for Public Certificates

Posted on August 16, 2026 By CWS

AWS Certificate Manager (ACM) has announced a significant change in its certificate validation procedures, with plans to permanently end email-based domain control validation (DCV) for public certificates by September 30, 2027. This decision is part of an effort to align with global trust mandates set by the Certificate Authority and Browser (CA/B) Forum, necessitating cloud architects, DevOps engineers, and security teams to shift from legacy email validation to DNS validation methods.

The Move Toward DNS Validation

The transition follows a pivotal decision made by the CA/B Forum in November 2025 to phase out email validation for public TLS/SSL certificates. By March 15, 2028, major web browsers will no longer trust any certificate validated via email, regardless of the issuing Certificate Authority (CA). The cryptographic community has long criticized email validation for its vulnerabilities, including compromised mail exchange (MX) routing and outdated WHOIS contacts, which pose significant supply-chain risks.

To mitigate potential certificate renewal failures and ensure compliance with upcoming standards, AWS has laid out a phased plan. Starting January 1, 2027, email validation will be restricted in new AWS regions, and by March 31, 2027, it will be prohibited for all new certificate requests across AWS regions. The complete cessation of email-based renewals will occur by September 30, 2027.

Simplified Transition Process

AWS has updated its certificate management APIs to facilitate a seamless transition to DNS validation. Users can modify validation methods in-place without the need to reissue certificates or reconfigure existing infrastructure components. The UpdateCertificateOptions API allows administrators to change a certificate’s validation from email to DNS, minimizing disruptions to live traffic.

When initiating a DNS update, ACM generates a unique CNAME record, which administrators must publish to their authoritative DNS servers. Organizations have a 72-hour window to complete DNS propagation, during which the certificate remains operational under its current validation status. For Amazon Route 53 users, the ACM console provides a one-click option to automatically insert CNAME records into hosted zones.

Enhancing Cloud Security

Switching to DNS validation enhances cloud security by eliminating manual processes from certificate renewal workflows. Once the CNAME record is verified, ACM automatically reissues and binds renewed certificates before they expire. For setups involving Amazon CloudFront, AWS also offers an HTTP-based token validation as an alternative method for securing TLS communication.

The shift from email to DNS validation is a critical step in bolstering cloud security and complying with industry standards. By adopting these measures, organizations can ensure their certificate management processes remain robust against potential threats.

As AWS continues to refine its security protocols, the focus remains on providing customers with reliable and secure certificate management solutions, paving the way for a more secure digital infrastructure.

Cyber Security News Tags:AWS, AWS Certificate Manager, CA/B Forum, certificate management, cloud security, Cybersecurity, digital certificates, DNS validation, email validation, SSL/TLS

Post navigation

Previous Post: Microsoft Unifies Copilot Apps for Enhanced User Experience
Next Post: Azure Data Breach Exposes Millions from Major Firms

Related Posts

Fake FileZilla Sites Distribute Remote Access Trojan Fake FileZilla Sites Distribute Remote Access Trojan Cyber Security News
Noodle RAT Targets Windows and Linux: A Growing Cyber Threat Noodle RAT Targets Windows and Linux: A Growing Cyber Threat Cyber Security News
Threat Actors Attacking Windows Systems With New Multi-Stage Malware Framework PS1Bot Threat Actors Attacking Windows Systems With New Multi-Stage Malware Framework PS1Bot Cyber Security News
Canadian Cybersecurity Leaders Shine at Web Summit Vancouver Canadian Cybersecurity Leaders Shine at Web Summit Vancouver Cyber Security News
10 Best Cloud Monitoring Tools in 2025 10 Best Cloud Monitoring Tools in 2025 Cyber Security News
Linux Firewall IPFire 2.29 Core Update 195 Released With VPN Protocol Support Linux Firewall IPFire 2.29 Core Update 195 Released With VPN Protocol Support Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Over 543,000 GitHub Credentials Remain Vulnerable
  • US Treasury Targets ATM Malware Network in Sanctions
  • MikroTik RouterOS Vulnerability Exposes Critical Risks
  • Over 500,000 Active Credentials Found on GitHub
  • Urgent Fixes Issued for Cisco SD-WAN Critical Flaw

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • October 2026
  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Over 543,000 GitHub Credentials Remain Vulnerable
  • US Treasury Targets ATM Malware Network in Sanctions
  • MikroTik RouterOS Vulnerability Exposes Critical Risks
  • Over 500,000 Active Credentials Found on GitHub
  • Urgent Fixes Issued for Cisco SD-WAN Critical Flaw

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark