Articles

How DNS-01 validation works

What is a DNS-01 challenge?

DNS-01 proves control of a domain through DNS rather than through a web server. It is the standard ACME challenge for wildcard identifiers. It is often a strong fit when the certificate target is behind a firewall, load balancer, CDN, or other architecture where HTTP validation would be difficult. For a domain name, the ACME server provides a unique challenge token. The ACME client combines that token with information derived from its ACME account key, hashes the resulting key authorization with SHA-256, and publishes the base64url-encoded digest in a DNS TXT record.

The validation record is placed under _acme-challenge.<domain>. For example, validating www.example.com uses a TXT record at _acme-challenge.www.example.com.

DigiCert queries DNS for the validation name. If one of the returned TXT values matches the value expected for that ACME challenge, domain control validation succeeds. After the challenge reaches a final state, the client should remove the temporary validation record unless the workflow intentionally retains other unrelated TXT values at the same name.

How DNS-01 works, step by step

  1. The ACME client requests a certificate containing one or more DNS identifiers.
  2. DigiCert returns an authorization object with a DNS-01 challenge for each identifier that requires dynamic ACME validation.
  3. The ACME client calculates the DNS-01 validation value from the challenge token and its ACME account key.
  4. The client or an integrated DNS automation component publishes the value as a TXT record at the required _acme-challenge name.
  5. After the DNS change is externally resolvable, the client tells the ACME server that the challenge is ready.
  6. DigiCert resolves the validation name from its validation infrastructure, including required multi-perspective checks for publicly trusted TLS issuance, and confirms that an expected TXT value is present.
  7. If DCV succeeds and any other applicable validation, CAA, policy, or approval requirements are satisfied, certificate issuance can proceed.
  8. After the challenge completes, the ACME client should clean up the temporary TXT value according to the client and DNS-provider workflow.

When DNS-01 is a strong fit

DNS-01 is not automatically the better choice. If a single web server can safely and predictably answer HTTP-01, that method can avoid granting an ACME workflow write access to DNS. The appropriate choice depends on architecture, privilege boundaries, DNS-provider capabilities, and operational ownership.

DNS caching, TTL, and validation timing can affect validation

Other factors can also affect validation timing, including provider replication, secondary authoritative servers, DNSSEC, and split-horizon DNS.

Wildcard certificates and the base domain

DNS-01 is required for ACME wildcard validation. With DigiCert, validating the DNS-01 record at _acme-challenge.example.com can satisfy validation for both example.com and *.example.com when they are part of the applicable request. HTTP-01 cannot validate a wildcard identifier.

Supplemental resources

Frequently asked questions

What is a DNS-01 challenge, and what does the TXT record contain?
DNS-01 is an ACME domain-control challenge that proves control by publishing a TXT record under _acme-challenge for the domain being validated. The record contains a base64url-encoded SHA-256 digest derived from the challenge token and the ACME account key. It is more precise to call this the DNS-01 validation value than to say the TXT record contains the raw CA token.
When should I use DNS-01 instead of HTTP-01?
Use DNS-01 when you need wildcard validation, when the target service cannot expose port 80, or when DNS-based proof is operationally cleaner than routing an HTTP challenge through load balancers, CDNs, or many backend servers. HTTP-01 can still be the simpler and lower-privilege choice for a straightforward web server.
Can DNS-01 validate wildcard certificates?
Yes, DNS-01 is the ACME challenge used for wildcard identifiers. DigiCert documents that validation at _acme-challenge.example.com can cover both example.com and *.example.com for the applicable request. HTTP-01 does not support wildcard validation.
Does DNS-01 require my application server to be reachable from the internet?
No, DigiCert needs public DNS visibility of the validation TXT record, not inbound access to the certificate target. This makes DNS-01 useful for internal or firewalled servers that still need publicly trusted certificates.
What TTL should I use for _acme-challenge records?
DigiCert has no universal requirement to use a 60-300 second TTL for ACME DNS-01. A reasonably low TTL can reduce cache persistence, but provider replication and negative caching also matter. Set the intended TTL before renewal windows, then tune the client's wait or propagation check to match observed DNS behavior.
Does successful DNS-01 mean the certificate will always be issued immediately?
No, DNS-01 establishes domain control. Certificate issuance can still depend on certificate type, organization validation where applicable, CAA authorization, account policy, approvals, and other CA requirements. DigiCert also documents that prevalidated OV/EV domains can use out-of-band DCV rather than a dynamic ACME challenge on each order.

Ready to evaluate your environment?

See how DigiCert Trust Lifecycle Manager can support certificate lifecycle automation across protected web servers and the rest of your enterprise certificate estate.

Explore DigiCert Trust Lifecycle Manager Talk to DigiCert