← Back to News

AWS sets a deadline for email-validated certs

2026-08-15 · aws-security

AWS has announced that Certificate Manager will discontinue support for email-validated public certificates by September 30, 2027, ahead of the broader browser-industry deadline. The change pushes teams toward DNS-based validation and forces a review of how certificate ownership, renewal records, and domain control are documented. That may sound like a routine PKI update, but certificate transitions are exactly the kind of operational change that exposes weak backup habits. If domain, DNS, and recovery records live only in active systems, a bad migration or account compromise can lock teams out of trusted recovery paths.


What Happened

AWS said customers using email validation for ACM public certificates need to migrate to DNS validation before support ends. The move aligns with the CA/B Forum's industry-wide deprecation of email-based domain validation for publicly trusted certificates.

The Cost of Data Loss

When certificate inventories, DNS ownership records, and escalation contacts are incomplete or lost, outages can stretch from minutes into days. Losing the authoritative trail for PKI assets can also delay incident recovery, break encrypted services, and create expensive manual reissuance work across production environments.

How Cold Storage Prevents This

Cold storage helps by preserving offline copies of certificate inventories, DNS validation procedures, registrar recovery details, and emergency runbooks that are independent of live control planes. If an account is compromised or a migration goes sideways, teams can rebuild trust chains from clean offline records instead of guessing under pressure.

Read Original Post →