aws AWS What's New ·

AWS Certificate Manager now supports switching existing certs from email to DNS validation

securityawsgadeprecationengineeraws-cloudfront
feature deprecation

AWS Certificate Manager (ACM) now enables users to change the domain validation method on existing public TLS certificates from email to DNS without reissuing the certificate or changing its ARN. This allows customers to proactively migrate ahead of the CA/B Forum's mandated deprecation of email-based domain validation, which ACM will phase out through 2027. Switching to DNS validation facilitates automated renewals and ensures existing ARN references in CI/CD pipelines remain valid. The feature is available in all AWS regions where ACM certificates are offered and can be managed via console or API.

  • Switch existing ACM certificates from email to DNS validation
  • Email-based domain validation for public TLS certificates being deprecated
Deprecations (1)
  • Email-based domain validation for public TLS certificates being deprecated

    Due to CA/B Forum mandates, email-based domain validation for publicly trusted certificates will be phased out by ACM throughout 2027, with full deprecation effective March 15, 2028. ACM will cease issuing new email-validated certificates after March 31, 2027, and stop renewing them after September 30, 2027.

Features (1)
  • Switch existing ACM certificates from email to DNS validation

    AWS Certificate Manager (ACM) now allows changing the domain validation method on existing public TLS certificates from email to DNS. This update enables users to migrate their certificates without reissuing them or modifying their existing Amazon Resource Names, ensuring continuity for CI/CD pipelines and service integrations.

Read the original announcement →

https://aws.amazon.com/about-aws/whats-new/2026/08/AWS-Certificate-Manager-Email-DNS-Switch

Related releases