SSL certificates can be valid for at most 199 days. From 15 March 2027 the limit becomes 99 days. Read more →

Domain Validation

Before a Certificate Authority (CA) issues your SSL certificate, they must confirm that you control the domain. There are five methods. Choose the one that suits your situation.

For multi-domain certificates you can use different methods for each domain name.

1

Email validation

Fastest method: click an approval link

The CA sends an email to a predefined address on the domain. You click a link and approve the issuance.

You can only choose from these 5 addresses:

admin@ administrator@ webmaster@ hostmaster@ postmaster@

The addresses must exist on the domain itself, e.g. admin@fairssl.dk. For subdomains, the address can be on the main domain or the subdomain.

Advantages

  • Fast, typically completed in minutes
  • No changes to DNS or the server required
  • Works for all certificate types including wildcards

Limitations

  • Only 5 fixed addresses, you cannot use others
  • Requires the email address to actually receive mail
  • Not suitable for automation (ACME)
2

DNS validation (TXT or CNAME)

Create a DNS record that proves domain control

The CA gives you a unique code. You create a TXT record or CNAME record in the domain's DNS with this code. The CA verifies that the record is available.

Note: This is not the same as AutoDNS (method 3). Here you create a new record per validation, at renewal you must create a new record again.

Example: DNS TXT record

_dnsauth.fairssl.dk.  IN  TXT  "unique-validation-code-from-ca"

Advantages

  • No web server required, only DNS access
  • Works for wildcards
  • Supported by all CAs

Limitations

  • New record required at every renewal
  • Requires access to the DNS panel
  • DNS propagation can take time (minutes to hours)
3

AutoDNS (recommended)

One permanent CNAME: we validate automatically forever

AutoDNS is FairSSL's recommended method. You create one permanent CNAME record pointing _dnsauth.yourdomain.com to a unique destination at FairSSL. We then handle all validation automatically, including at renewal.

You never need to touch DNS again after the initial setup.

Example: AutoDNS CNAME record

_dnsauth.fairssl.dk.  IN  CNAME  abcd1234.autodns.fairssl.dk.

The unique destination is specific to your account and domain.

Supported CAs

AutoDNS works with the DigiCert brands: Thawte, RapidSSL, GeoTrust and DigiCert. GlobalSign and Sectigo use standard DNS TXT validation (method 2).

Advantages

  • Set and forget: create once, validation happens automatically
  • Perfect for ACME automation
  • Works for wildcards
  • No DNS API keys required
  • Servers need no inbound internet access

Limitations

  • DigiCert brands only (Thawte, RapidSSL, GeoTrust, DigiCert)
  • Requires DNS access for the initial setup
4

Persistent DNS validation

One permanent record, instant issuance

Persistent DNS validation is a CA/Browser Forum method, DNS-PERSIST-01, approved on 8 November 2025 and part of the Baseline Requirements. Instead of a new token for every order, you publish one permanent TXT record on your own domain. The record approves a specific certificate account for the domain, and the CA reads it every time you order, so there is nothing to create per order.

The record is set on the base domain and covers its subdomains. Once it is in place, certificates are issued immediately, both in the FairSSL portal and through FairSSL's ACME solution. Your ACME client needs no changes and no new challenge type.

You create the record yourself

_validation-persist.yourdomain.com.  IN  TXT  "digicert.com; accounturi=https://digicert.com/account/<account-id>"

FairSSL gives you the exact value. We never create the record for you: it is the proof that the domain is yours, and that proof has to come from you.

Who can use it

The record approves an entire certificate account for the domain. We therefore offer it only where that account means one customer:

  • Your own DigiCert account. If you hold your own DigiCert account through FairSSL, the account value approves only you, and it works for every DigiCert brand.
  • OV and EV with your own organization. There DigiCert issues a value unique to your organization and the individual domain. That one works on our shared account.

On FairSSL's shared DigiCert account with a DV certificate we do not offer it: the account value would be the same string for every customer on that account. Use AutoDNS there instead - it validates per order and is just as automatic. Talk to us if you want to know which applies to you.

The record must stay in DNS

Never delete the record after setting it up. The approval renews itself for as long as it stays in DNS. Remove it and future orders fall back to per-order validation, or stall until the record is created again. Certificates already issued keep working.

Benefits

  • Immediate issuance: the domain is already approved when you order
  • Set it up once, no tokens per order and none on renewal
  • Applies to portal orders and ACME orders alike
  • One record covers the base domain and its subdomains

Limitations

  • DigiCert brands only (DigiCert, GeoTrust, Thawte, RapidSSL)
  • Requires your own DigiCert account, or OV/EV with your own organization
  • The record must never be deleted
  • If the account value changes, you update the TXT record yourself

Background on the method: DigiCert on DNS-PERSIST-01 ↗

5

HTTP/URL validation

Place a file on the web server

The CA gives you a unique code. You create a file containing the code at a specific URL path on your web server. The CA checks that the file is accessible via HTTP or HTTPS.

Example: HTTP validation file

http://fairssl.dk/.well-known/pki-validation/fileauth.txt
Contents: unique-validation-code-from-ca

Important rules for HTTP validation

  • ! All names must respond simultaneously. Each domain name in the certificate must respond with the validation code at its own URL. If one name is missing, the certificate or that name may be blocked.
  • ! No redirects. The file must respond directly on the specified domain, not via a redirect to another domain.
  • ! No wildcards. HTTP validation is not supported for wildcard certificates.

Advantages

  • No DNS access required
  • Only web server access needed

Limitations

  • Does not support wildcards
  • All names must respond simultaneously, no exceptions
  • No redirects allowed
  • Requires a running web server with public access

Comparison of validation methods

Email DNS TXT/CNAME AutoDNS Persistent DNS HTTP/URL
Wildcards
Automatic renewal Manual ✓ automatic ✓ automatic ACME possible
Requires Email address DNS access DNS (once) DNS (once) Web server
All CAs DigiCert brands DigiCert brands
Best for Quick manual validation Servers without web ACME, automation Instant issuance Simple web servers

Frequently asked questions about domain validation

Find answers to the most common questions about SSL certificates and FairSSL.

Persistent DNS validation is the fastest, because the permanent record is already in place when you order: the certificate is issued immediately. Among the per-order methods, email validation is typically the fastest. You receive an email and click an approval link. DNS and HTTP can also be completed in minutes, but require access to DNS or the web server.
Yes. For multi-domain (SAN) certificates, each domain name can be validated with its own method. For example, email for one domain and DNS for another.
With DNS TXT you manually create a new TXT record for each validation (and at every renewal). With AutoDNS you create one permanent CNAME record pointing to FairSSL, and we handle all future validations automatically.
No. Wildcard certificates require DNS validation (TXT or AutoDNS CNAME). HTTP validation is not supported for wildcards.
All domain names in the certificate must respond with the validation code at the same time. If one name does not respond (e.g. due to a redirect or downtime), the certificate or that specific name may be blocked. Use DNS validation for names you do not have full control over.
AutoDNS supports the DigiCert brands: Thawte, RapidSSL, GeoTrust and DigiCert. GlobalSign and Sectigo use standard DNS TXT validation.
AutoDNS answers the validation challenge for each order on your behalf, so you never have to publish a token yourself. Persistent DNS validation removes the per-order challenge entirely for the DigiCert brands: one permanent record, which you create yourself, approves the certificate account, and the certificate is issued immediately. Because the record approves an entire account, we offer it only to customers with their own DigiCert account and for OV/EV with their own organization. The two use different hostnames, _dnsauth for AutoDNS and _validation-persist for persistent validation, and they work side by side. You only need the persistent record for instant issuance, and you keep the AutoDNS record for products that still use per-order tokens.

Ready to validate your domain?

Create a free account and order your first certificate. A DV certificate is issued in under 2 minutes.