AWS Certificate Manager Supports Switching From e-mail to DNS Validation
AWS, Thursday, August 13th, 2026
AWS Certificate Manager lets customers switch existing public certificates from email to DNS validation.
AWS Certificate Manager now enables customers to change the domain validation method on existing ACM-issued public TLS certificates from email to DNS, without reissuing the certificate or changing its Amazon Resource Name.
The change responds to the CA/Browser Forum's mandated deprecation of email-based domain validation for publicly trusted certificates, effective 15 March 2028.
ACM will phase out email validation support throughout 2027, stopping issuance of email-validated certificates on 31 March 2027 and ceasing renewals on 30 September 2027. Preserving the existing ARN means downstream integrations do not need updating. The capability gives customers a migration path ahead of those deadlines.