Security1 publisher3 min readPublished
AWS gives email-validated certificates three 2027 deadlines, and the last one is a renewal cliff
ACM stops offering email validation in new Regions on Jan 1 2027, blocks new requests on March 31, and stops renewing on Sept 30. The in-place switch to DNS keeps the certificate ARN.
The Watch · Security desk
Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

What happened
- Help Net Security published its report on the ACM email validation phaseout on August 14, 2026.
- AWS Certificate Manager (ACM) will phase out email validation for public certificates throughout 2027.
- The CA/Browser Forum, which sets standards browsers and certificate authorities follow for publicly trusted certificates, will bar public certificate authorities from using email-based domain validation to issue or renew publicly trusted certificates from March 15, 2028.
- Certificates issued before March 15, 2028 will remain valid until they expire.
- AWS will begin phasing out email validation on January 1, 2027, when ACM will stop offering the method in new AWS Regions.
Compiled by The WatchSomething wrong?How this is made
Why it matters
AWS Certificate Manager has published a three-step schedule for retiring email validation on public certificates, ending with a hard stop on renewals on September 30, 2027 [1][4][5][6]. A certificate that stops renewing is an outage with a calendar entry attached, which makes this an inventory-and-migrate project rather than a policy notice to file. The sequence is straightforward. From January 1, 2027, ACM stops offering email validation in new AWS Regions [4]. From March 31, 2027, email validation is no longer available for new certificate requests in any Region [5]. From September 30, 2027, ACM stops renewing existing email-validated certificates, and AWS recommends migrating those certificates to DNS validation before that date [6][7]. That leaves a six-month window in which existing certificates still renew but no new ones can be issued by the old method [2]. The driver is upstream. The CA/Browser Forum, which sets the rules browsers and certificate authorities follow for publicly trusted certificates, bars public CAs from using email-based domain validation to issue or renew from March 15, 2028 [2]. Certificates issued before that date stay valid until they expire [3]. AWS is pulling its own renewal cutoff roughly five and a half months ahead of the industry deadline [1], which is the usual pattern: a provider that has to reissue at scale wants the tail to clear before the standard bites. Finding the affected certificates is the part worth scheduling first. In the ACM console, set the Validation method filter to Email and the Type filter to Amazon Issued; anything returned needs to move before September 30, 2027 [8]. The same inventory is available from the AWS CLI, which lists Amazon-issued certificates in a selected Region along with their validation method, with EMAIL marking the ones in scope [9]. Note the per-Region framing on the CLI path [9]: multi-Region estates need to iterate, and a single console glance is not an audit. The migration itself is less disruptive than most deprecations of this type. According to Adam Aboudi, Senior Technical Product Manager on the ACM team, and Poojil Tripathi, Solutions Architect at AWS, ACM is updating the UpdateCertificateOptions API so a certificate can be switched from email to DNS validation in place, keeping the same Amazon Resource Name so that resources referencing the certificate need no changes [10]. Operationally that matters more than the validation method itself, because ARN churn is what usually forces changes to load balancers, distributions and templates. The switch also fails safe. After a customer initiates it, ACM issues a CNAME record that must be added to the domain's DNS within 72 hours, and the certificate keeps operating on email validation during that window [11]. If the record does not land in time, the certificate stays active on email validation and the migration can be retried [12]. Once DNS validation completes, ACM renews automatically before expiry, provided the validation record stays in place [13] - which is the new standing dependency to monitor, since deleting that record later quietly removes automatic renewal. In the console, the path is Update validation method, then adding the CNAME records ACM provides; the records can be downloaded as CSV for other DNS providers, and Route 53 users can create them directly from the console [14]. After email validation is gone, ACM supports DNS validation for general requests and HTTP validation for certificates used with CloudFront, with AWS recommending DNS for most cases [15]. HTTP validation works by hosting a token ACM supplies at a well-known URL path, is limited to CloudFront certificates, and like DNS removes the manual approval step and permits automatic renewal [16]. What to watch: whether teams treat the January 1, 2027 Region change as the real start date [4], since it is roughly four and a half months out from AWS's announcement [3] and is the point at which new-Region builds silently lose the option.