AWS said AWS Certificate Manager (ACM) will phase out email validation for public certificates in 2027 and is directing customers to move to DNS validation. The change follows a CA/Browser Forum decision to end email-based domain validation for publicly trusted certificates by March 15, 2028. Under AWS's timeline, email validation will no longer be offered in new AWS Regions starting January 1, 2027, and ACM will stop accepting new requests for email-validated public certificates in all Regions on March 31, 2027.
AWS will stop renewing existing email-validated public certificates on September 30, 2027, making migration necessary for affected customers. To reduce disruption, AWS is updating the UpdateCertificateOptions API so organizations can switch certificates from email to DNS validation in place without changing the certificate ARN or dependent resources; after the change, customers must add an ACM-provided CNAME record within 72 hours to complete validation and enable automatic renewal. AWS said HTTP validation will remain available only for certificates used with Amazon CloudFront, while recommending DNS validation for most deployments.

See the reporting duties and controls this puts on the clock.
6 events from the most recent confirmed update back to the earliest known activity.
The CA/Browser Forum voted in November 2025 to end support for email-based domain validation for publicly trusted certificates, prompting industry migration to other validation methods.
From March 15, 2028, public certificate authorities will no longer be allowed to use email-based domain validation to issue or renew publicly trusted certificates, though certificates issued before that date remain valid until expiration.
AWS said ACM will stop renewing existing email-validated public certificates, requiring customers to complete migration to DNS validation before this point to avoid renewal interruption.
AWS said ACM will stop allowing new certificate requests that use email validation in any AWS Region.
AWS said ACM will stop offering email validation for public certificates in new AWS Regions as the first phase of its deprecation plan.
AWS announced that AWS Certificate Manager will discontinue support for email-validated public certificates and directed customers to migrate to DNS validation. AWS also said it is updating the UpdateCertificateOptions API to support in-place migration without changing certificate ARNs.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See what this changes for your reporting obligations and which controls it puts on the clock.
3 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcehelpnetsecurity.com
Open sourceaws.amazon.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.