Security1 distinct publisher3 min readUpdated
ACM stops offering email validation in new Regions on Jan 1 2027, blocks new requests on March 31, and stops renewing on Sept 30. The in-place switch to DNS keeps the certificate ARN.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
AWS Certificate Manager has published a three-step schedule for retiring email validation on public certificates, ending with a hard stop on renewals on September 30, 2027 [1][4][5][6]. A certificate that stops renewing is an outage with a calendar entry attached, which makes this an inventory-and-migrate project rather than a policy notice to file. The sequence is straightforward. From January 1, 2027, ACM stops offering email validation in new AWS Regions [4]. From March 31, 2027, email validation is no longer available for new certificate requests in any Region [5]. From September 30, 2027, ACM stops renewing existing email-validated certificates, and AWS recommends migrating those certificates to DNS validation before that date [6][7]. That leaves a six-month window in which existing certificates still renew but no new ones can be issued by the old method [2]. The driver is upstream. The CA/Browser Forum, which sets the rules browsers and certificate authorities follow for publicly trusted certificates, bars public CAs from using email-based domain validation to issue or renew from March 15, 2028 [2]. Certificates issued before that date stay valid until they expire [3]. AWS is pulling its own renewal cutoff roughly five and a half months ahead of the industry deadline [1], which is the usual pattern: a provider that has to reissue at scale wants the tail to clear before the standard bites. Finding the affected certificates is the part worth scheduling first. In the ACM console, set the Validation method filter to Email and the Type filter to Amazon Issued; anything returned needs to move before September 30, 2027 [8]. The same inventory is available from the AWS CLI, which lists Amazon-issued certificates in a selected Region along with their validation method, with EMAIL marking the ones in scope [9]. Note the per-Region framing on the CLI path [9]: multi-Region estates need to iterate, and a single console glance is not an audit. The migration itself is less disruptive than most deprecations of this type. According to Adam Aboudi, Senior Technical Product Manager on the ACM team, and Poojil Tripathi, Solutions Architect at AWS, ACM is updating the UpdateCertificateOptions API so a certificate can be switched from email to DNS validation in place, keeping the same Amazon Resource Name so that resources referencing the certificate need no changes [10]. Operationally that matters more than the validation method itself, because ARN churn is what usually forces changes to load balancers, distributions and templates. The switch also fails safe. After a customer initiates it, ACM issues a CNAME record that must be added to the domain's DNS within 72 hours, and the certificate keeps operating on email validation during that window [11]. If the record does not land in time, the certificate stays active on email validation and the migration can be retried [12]. Once DNS validation completes, ACM renews automatically before expiry, provided the validation record stays in place [13] - which is the new standing dependency to monitor, since deleting that record later quietly removes automatic renewal. In the console, the path is Update validation method, then adding the CNAME records ACM provides; the records can be downloaded as CSV for other DNS providers, and Route 53 users can create them directly from the console [14]. After email validation is gone, ACM supports DNS validation for general requests and HTTP validation for certificates used with CloudFront, with AWS recommending DNS for most cases [15]. HTTP validation works by hosting a token ACM supplies at a well-known URL path, is limited to CloudFront certificates, and like DNS removes the manual approval step and permits automatic renewal [16]. What to watch: whether teams treat the January 1, 2027 Region change as the real start date [4], since it is roughly four and a half months out from AWS's announcement [3] and is the point at which new-Region builds silently lose the option.
Follow any of these and your For You feed starts watching them — no settings page required.
Ranked by verification strength, evidence, and original report placement.
Help Net Security published its report on the ACM email validation phaseout on August 14, 2026.
AWS Certificate Manager (ACM) will phase out email validation for public certificates throughout 2027.
The CA/Browser Forum, which sets standards browsers and certificate authorities follow for publicly trusted certificates, will bar public certificate authorities from using email-based domain validation to issue or renew publicly trusted certificates from March 15, 2028.
Certificates issued before March 15, 2028 will remain valid until they expire.
AWS will begin phasing out email validation on January 1, 2027, when ACM will stop offering the method in new AWS Regions.
From March 31, 2027, email validation will no longer be available for new certificate requests in any AWS Region.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Specific and internally consistent, but single-publisher
Every material assertion is a dated, checkable schedule item or a documented console/CLI/API procedure, and the central migration mechanic is carried as a direct quote from two named AWS staff on the ACM team. The limitation is breadth rather than precision: one trade publication restating a vendor notice, with no primary AWS announcement, changelog, or second outlet in the cluster to corroborate the dates.
No usage or migration data supplied
The cluster documents a vendor roadmap and tooling but contains no measure of how many ACM certificates, domains, or customers currently use email validation, and no data on how many have migrated to DNS or HTTP validation. Adoption cannot be scored without inventing figures the source does not provide.
Close to aligned, mildly sharpened framing
The reporting stays inside what the vendor documented: dates, filters, API behaviour and remaining validation methods, with no capability claims beyond automatic renewal once DNS validation is in place. The slight positive reading comes from framing the September 30, 2027 renewal stop as a cliff while no evidence of affected-fleet size or lapse impact is offered, so the urgency is asserted rather than quantified.
Vendor-sourced guidance steering to first-party tooling
The only attributed voices are AWS employees on the ACM team, and the recommended remediation path highlights AWS-native conveniences such as the in-place UpdateCertificateOptions switch and one-click Route 53 record creation. That is a clear vendor interest in channelling customers to DNS validation inside AWS, though the underlying driver is an industry-wide CA/Browser Forum rule that AWS does not control, which caps how self-serving the schedule can be read as.
Confident on the schedule, blind on exposure
High confidence that the dates, tooling and remaining validation methods are reported as AWS stated them, because they are specific and quoted with named attribution. Confidence is held down by the single-source cluster, the absence of a primary AWS document, and the total lack of data on how many certificates are affected, which leaves the practical severity unmeasured.
security
ToxicPanda 2.0 Widens From 16 Apps to 140, and From Overlays to ADB Shell3 distinct publishers
security
CDN Tsunami: the protocol translation you pay for is the amplifier1 distinct publisher
build
Once the question needs a cube, you own the parser1 distinct publisher
build
Two Actions, One Loose Policy: The Bedrock Wildcards That Widen A Least-Privilege Grant1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 14, 2026