Articles
How DNS-01 validation works
What is a DNS-01 challenge?
DNS-01 proves control of a domain through DNS rather than through a web server. It is the standard ACME challenge for wildcard identifiers. It is often a strong fit when the certificate target is behind a firewall, load balancer, CDN, or other architecture where HTTP validation would be difficult. For a domain name, the ACME server provides a unique challenge token. The ACME client combines that token with information derived from its ACME account key, hashes the resulting key authorization with SHA-256, and publishes the base64url-encoded digest in a DNS TXT record.
The validation record is placed under _acme-challenge.<domain>. For example, validating www.example.com uses a TXT record at _acme-challenge.www.example.com.
DigiCert queries DNS for the validation name. If one of the returned TXT values matches the value expected for that ACME challenge, domain control validation succeeds. After the challenge reaches a final state, the client should remove the temporary validation record unless the workflow intentionally retains other unrelated TXT values at the same name.
How DNS-01 works, step by step
- The ACME client requests a certificate containing one or more DNS identifiers.
- DigiCert returns an authorization object with a DNS-01 challenge for each identifier that requires dynamic ACME validation.
- The ACME client calculates the DNS-01 validation value from the challenge token and its ACME account key.
- The client or an integrated DNS automation component publishes the value as a TXT record at the required _acme-challenge name.
- After the DNS change is externally resolvable, the client tells the ACME server that the challenge is ready.
- DigiCert resolves the validation name from its validation infrastructure, including required multi-perspective checks for publicly trusted TLS issuance, and confirms that an expected TXT value is present.
- If DCV succeeds and any other applicable validation, CAA, policy, or approval requirements are satisfied, certificate issuance can proceed.
- After the challenge completes, the ACME client should clean up the temporary TXT value according to the client and DNS-provider workflow.
When DNS-01 is a strong fit
- Wildcard certificates. DNS-01 is the ACME challenge used for wildcard identifiers; HTTP-01 does not support wildcard validation.
- Private or firewalled certificate targets. The target server doesn't need to expose TCP port 80 for ACME validation because the proof is published in DNS.
- Load-balanced, CDN-fronted, or multi-server services. Validation is independent of which application backend receives user traffic.
- Centralized certificate automation. A controlled automation service can manage DNS validation for many certificate consumers, provided DNS privileges are carefully scoped.
- Environments where public DNS is programmable and auditable through a supported API or automation integration.
DNS-01 is not automatically the better choice. If a single web server can safely and predictably answer HTTP-01, that method can avoid granting an ACME workflow write access to DNS. The appropriate choice depends on architecture, privilege boundaries, DNS-provider capabilities, and operational ownership.
DNS caching, TTL, and validation timing can affect validation
Other factors can also affect validation timing, including provider replication, secondary authoritative servers, DNSSEC, and split-horizon DNS.
- Do not treat 60-300 seconds as a universal required TTL. Choose a TTL that matches your DNS platform and change-control model.
- If the _acme-challenge name or RRset was queried before the TXT value existed, negative caching can matter; the SOA negative-cache settings may influence how long an NXDOMAIN or no-data answer persists.
- Lowering a TTL immediately before a renewal does not force resolvers that already cached the previous TTL to discard it early. If you want a lower TTL for automation, establish it before you depend on it.
- Use the ACME client or DNS plugin's propagation check where available, and validate against public authoritative or external DNS views rather than only an internal corporate resolver.
- Multiple TXT values can legitimately coexist at the same _acme-challenge name. ACME validation succeeds when an expected value is present; cleanup should remove only the value created for the completed challenge.
Wildcard certificates and the base domain
DNS-01 is required for ACME wildcard validation. With DigiCert, validating the DNS-01 record at _acme-challenge.example.com can satisfy validation for both example.com and *.example.com when they are part of the applicable request. HTTP-01 cannot validate a wildcard identifier.
Supplemental resources
- DigiCert: ACME DNS-01 challenge
- DigiCert: Complete DNS-01 challenges for ACME
- DigiCert: DNS-01 challenge for wildcard domains
- DigiCert: ACME domain validation behavior
- DigiCert: Supported DCV methods
- DigiCert: Persistent DNS TXT record DCV
- RFC 8555: Automatic Certificate Management Environment (ACME)
- CA/Browser Forum: Latest TLS Baseline Requirements
Frequently asked questions
Ready to evaluate your environment?
See how DigiCert Trust Lifecycle Manager can support certificate lifecycle automation across protected web servers and the rest of your enterprise certificate estate.