Add a domain, authorize the domain for certificates, and use HTTP practical demonstration as the validation method

Before you begin

Validation Note: Before you can pre-validate a domain for TLS/SSL validation, you must first submit the organization to be pre-validated. Additionally, if you want the domain to be used for OV, EV, and/or Private SSL certificates, you must submit its organization for those matching validation types.

This validation method allows you to demonstrate control over your domain by hosting a .txt file containing a randomly generated token value at a predetermined location on your website. Once the file is created and placed on your site, DigiCert visits the specified URL to confirm the presence of your verification token. Make sure to avoid some of the more Common mistakes: HTTP practical demonstration DCV method.

Step I: Add and Authorize a Domain for TLS/SSL Certificate

  1. In your CertCentral account, in the sidebar menu, click Certificates > Domains.

  2. On the Domains page, click New Domain.

  3. On the New Domain page, under Domain Details, enter the following domain information:

    1. Domain Name
      In the box, enter the domain name the certificates will secure (for example,
    2. Organization
      In the drop-down list, select the organization you want to assign the domain to.
  4. Under Validate This Domain For, check the validation types for which the domain must be validated.

    • OV - Normal Organization Validation
      Use this option so you can order Standard SSL, Secure Site SSL, Wildcard SSL, Secure Site Wildcard SSL, Multi-Domain SSL, and Secure Site Multi-Domain SSL Certificates for this domain.
    • EV - Extended Organization Validation (EV)
      Use this option so you can order EV SSL, Secure Site EV SSL, EV Multi-Domain SSL, and Secure Site EV Multi-Domain SSL Certificates for this domain.
    • Private SSL - DigiCert Private SSL Certificate
      Use this option so you can order Private SSL certificates for this domain.
  5. Under Domain Control Validation (DCV) Method, select HTTP Practical Demonstration.

Note: The default DCV method is by verification email.

  1. When you are finished, click Submit for Validation.

Step II: Use HTTP Practical Demonstration to Demonstrate Control Over the Domain

Create Your .txt File:

  1. Create your .txt file:

    1. Under User Actions, in the Your unique verification token box, copy your verification token.
      To copy the value to your clipboard, single click in the text field.
      Note: The unique verification token expires after thirty days. To generate a new token, click the Generate New Token link.
    2. Open a text editor (such as Notepad) and paste in Your unique verification token.
    3. In Your HTTP token URL, the string after pki-validation/ is the name of your .txt file.
      For example, if Your HTTP token URL is, then, your file name is c7e2ff0c848e4707594066cc860.txt
    4. Save the .txt file under this name (for example, c7e2ff0c848e4707594066cc860.txt).
  1. Create the .well-known/pki-validation/ directory:

    Create the .well-known/pki-validation/ directory on your site and place your .txt file in it.

Note: On Windows-based servers, the .well-known folder must be created via command line (mkdir .well-known).

  1. Verify the HTTP token

    1. In your CertCentral account, in the sidebar menu, click Certificates > Domains.
    2. On the Domains page, in the Domain Name column, click the link for the domain.
    3. On the domain information page (e.g.,, at the bottom of the page, click Check HTTP Token.

Troubleshooting tips

Verify the URL matches exactly, making sure that the URL for your web page matches the DigiCert provided URL.


Where matches the domain that you are validating, and [filename].txt matches the unique hash provided by DigiCert under Your HTTP token URL (for example, c7e2ff0c848e4707594066cc860.txt).

If you are missing a period, a number, or a letter, validation cannot be completed.