AWS Certificate Manager will phase out email domain validation. From March 31, 2027, new requests cannot use it, and renewals stop on September 30, 2027. Teams need to move to DNS validation, or HTTP validation for certain CloudFront cases, before existing certificates approach expiry.

The short answer

DateChange
January 1, 2027Email validation is unavailable in new AWS regions.
March 31, 2027New email-validated requests end.
September 30, 2027Renewals of email-validated certificates end.
March 15, 2028Broader CA/Browser ecosystem deadline.

Why email is disappearing

Email validation sends approval to predictable administrative addresses on a domain. It relies on a monitored inbox, spam filtering and repeated human intervention. A missed message can allow a certificate to expire while the service itself remains healthy.

DNS validation proves control through a CNAME record. Once retained, ACM can renew automatically without asking a person. The model is easier to automate and audit and follows changing public-certificate rules.

Migration can preserve the ARN

AWS says UpdateCertificateOptions can change the validation method of an eligible certificate without requesting a new ARN. ACM then provides the CNAME to publish, with a 72-hour window to complete validation.

Keeping the ARN avoids reconfiguring every load balancer, distribution or gateway referencing it. Still test the process on a noncritical certificate and monitor status. DNS mistakes, proxies hiding records or forgotten delegation can block proof.

Inventory before changing anything

List ACM certificates in every region and account. Record validation method, covered names, expiry and attached resources. Do not forget us-east-1, commonly used by CloudFront, or historical accounts owned by a former team.

Group domains by DNS provider. Route 53 zones in the same environment are straightforward to automate. For external DNS, document ownership and verify support for the required CNAME records, including subdomains.

Infrastructure as code should own those records. A manually created CNAME removed during cleanup can break renewal months later.

Verify renewal, not just issuance

After switching to DNS, wait for validation status and later verify an early renewal cycle. Add alerts for expiry and for certificates still using email. Immediate migration success does not prove the DNS record will remain published.

AWS HTTP validation applies to certificates used with CloudFront and is not a general ACM replacement. DNS remains the broadest choice.

The deprecation is easy to ignore because the deadline looks distant. Inventory and option changes are simple; finding the owner of a DNS zone days before expiry is not.