Add and validate a domain using Persistent DNS TXT record
Add a domain to CertCentral and use the Persistent DNS TXT record domain control validation (DCV) method to demonstrate control over the domain.
Notice
Note: Currently, Verified Mark (VMC) and Common Mark (CMC) certificates don’t support the Persistent DNS TXT DCV method. Use a different DCV method to validate domains for these certificates.
With this method, you create a persistent DNS TXT record for the domain and add the required persistent URI value. After you add the record and it's publicly available, DigiCert checks the domain's DNS TXT records for the required hostname and persistent URI. You leave the record and URI in place afterward. The same values are reused for future revalidations, making them faster and reducing manual DNS updates.
Persistent DNS TXT automatic domain revalidation
Persistent DNS TXT domain validation is reusable for nine days before it must be revalidated. CertCentral's Persistent DNS TXT automatic domain revalidation solves this by automatically revalidating the domain every five days. So, you never have to manually resubmit the domain for validation, and the domain stays valid without manual intervention.
If an error occurs during domain revalidation, you must resolve the problem and manually validate the domain to restart automatic revalidation.
Warning
Important: Don’t delete the persistent DNS TXT record after the domain is validated. Keep the record and its persistent URI in place so you can reuse it for future persistent DNS TXT domain validations.
Before you begin
You must be a CertCentral Administrator to add and validate domains.
Before adding and validating the domain, make sure you have:
At least one organization added to your CertCentral account. When you add a domain, you must assign the domain to an organization. See Add an organization to CertCentral.
Access and permission to create or modify DNS TXT records for the domain.
Enabled the Persistent DNS TXT record DCV method.
Enable the Persistent DNS TXT record DCV method
DigiCert added the Persistent DNS TXT record DCV method to all CertCentral accounts but didn’t enable it by default. To use this DCV method to validate your domains, you need to enable it first. If you don't enable it, the Persistent DNS TXT record DCV method doesn't appear as an option when adding and validating domains.
In the CertCentral menu, go to Settings > Preferences.
On the Preferences page, expand Advanced Settings.
In the Domain Control Validation (DCV) section, select Persistent DNS TXT Record (Recommended).
At the bottom of the page, select Save Settings.
The Persistent DNS TXT record DCV method now appears as an option when adding and validating your domains and requesting TLS, Qualified Website Authentication Certificates (QWAC)/QWAC PSD2, PKIo Private Services Server, and X9 PKI for TLS certificates.
Step 1: Add the domain and select the DCV method
In CertCentral, go to the Domains page and select New Domain.
Enterprise, Partner, and legacy accounts: In the left menu, go to Certificates > Domains.
Subscription accounts: In the left menu, go to Validation > Domains.
On the New Domain page, under Domain details, complete the following fields:
In the Domain name box, enter the domain name.
In the Organization menu, select the organization you want to assign the domain to.
Under Domain control validation (DCV) method, select Persistent DNS TXT Record.
Select Submit for validation.
Step 2: Copy your persistent URI
On the domain details page, in the Domain control validation (DCV) method section, go to User actions.
Under User actions, CertCentral displays the two persistent URI values. You can use the Account URI or the Unique URI.
CertCentral checks your persistent DNS TXT record for both URIs, so you can use either one to successfully validate your domain.
Domain validation works for OV and EV TLS, Qualified Website Authentication Certificates (QWAC) and QWAC PSD2, PKIo Private Services Server, X9 PKI for TLS, and Secure Email for Employee and Secure Email for Organization certificates.
Account URI: Use the same persistent URI to validate any domain in your CertCentral account.
Unique URI:
The Unique URI is specific to a base domain and all its subdomains.
It's generated from the base domain itself, not from the individual domain record. That's why the base domain and all its subdomains share the same Unique URI value.
Use it when you don't want multiple unrelated domains to share the same TXT value. This helps prevent linking your domains through DNS records.
Copy the persistent URI value you want to use. Add it to the persistent DNS TXT record in the next step.
Step 3: Create a persistent DNS TXT record for the domain
Go to your DNS provider's site and create a persistent DNS TXT record for the domain.
For provider-specific instructions, refer to your DNS provider’s documentation for creating or updating DNS TXT records.
In the record Type field, or its equivalent, select TXT.
In the Name field, sometimes labeled Host or Hostname, enter
_validation-persist.Some DNS providers automatically append your domain name. Others may require the complete hostname, for example:
_validation-persist.example.comIn the Value field, sometimes labeled Content or TXT value, enter the persistent URI value you copied from CertCentral.
Example:
digicert.com; accounturi=https://digicert.com/account/{{your_persistent_uri_value}}Select a Time-to-Live (TTL) value or use your DNS provider's default TTL value.
Save the persistent TXT record.
Step 4: Complete domain validation in CertCentral
After you set up your persistent DNS TXT record, you can select Check TXT on the domain details page to validate the domain immediately, or wait for CertCentral to check your DNS TXT record automatically. Automatic checks run for up to 10 days after you submit the domain for validation. If that window closes before the record is found, the checking stops and doesn't restart on its own. Select Check TXT to validate the domain manually.
In CertCentral, return to the Domains page and in the Domain name column, select the domain link.
Enterprise, Partner, and legacy accounts: In the left menu, go to Certificates > Domains.
Subscription accounts: In the left menu, go to Validation > Domains.
On the domain details page, in the Domain control validation (DCV) method section under User actions, select Check TXT.
What's next
You've validated the domain and started the automatic domain revalidation.
Warning
Important: You're done, but don't delete the persistent DNS TXT record now that the domain is validated. Keep the record and its persistent URI value in place so DigiCert can reuse it for future revalidations.
Troubleshoot Persistent DNS TXT domain validation issues
If validation doesn't complete, confirm that the DNS TXT record is publicly resolvable and contains the exact persistent TXT value displayed in CertCentral.
Issue | What to check |
|---|---|
TXT record created on the wrong hostname | Confirm the hostname value matches the domain being validated. |
Hostname value was omitted or misspelled | Confirm the hostname uses the following format: Some DNS providers automatically append your domain name. Others may require the complete hostname. |
Persistent URI was copied incorrectly or modified | Copy the exact persistent URI from CertCentral without changing it. |
Extra characters added to the record value | The TXT value field must contain exactly what is shown in CertCentral with nothing added or removed. |
DNS propagation incomplete | Allow time for DNS propagation before checking the record. |