Skip to main content

Validate domains on a domain validation (DV) TLS certificate order

Validate each domain included in a DV TLS certificate order before DigiCert issues the certificate. Domain validation must be complete for all domains in the order before the certificate can be issued.

Important

  • DV certificates don’t support domain prevalidation or domain validation reuse.

  • Each DV certificate order requires domain validation, including renewals and reissues.

When you order a DV certificate, you must select a DCV method to validate all the domains on the certificate. CertCentral takes you to the certificate's pending Order # details page to complete domain validation. You can switch validation methods if needed.

Supported DCV methods for DV certificates

With DV certificate orders, you must use one DCV method to validate all domains on the order.

DCV type

DCV methods

Email-based

Email to DNS TXT record contact, Email to DNS CAA record contact, and Constructed Email

DNS-based

Persistent DNS TXT record, DNS TXT record, and DNS CNAME record

Website-based

HTTP Practical Demonstration

Note: DV certificates don’t support the HTTP Practical Demonstration with unique filename DCV method.

For detailed steps for each method, see the relevant topic in this chapter.

IP address and wildcard domain constraints

DigiCert recommends that you don’t include wildcard domains and IP addresses on the same DV certificate.

Consider the following limitations when adding IP addresses and wildcard domains to DV certificates:

  • If the certificate includes an IP address, you must use HTTP Practical Demonstration to validate it.

  • If the certificate includes a wildcard domain, you can’t use HTTP Practical Demonstration to validate it.