---
格式版本: 2
标题: "AWS Certificate Manager supports switching from e-mail to DNS validation"
原文链接: "https://aws.amazon.com/cn/about-aws/whats-new/2026/08/AWS-Certificate-Manager-Email-DNS-Switch/"
发布日期: "2026-08-13"
发布时间校准状态: "found"
发布时间需复核: "否"
发布时间来源: "llm:local:original_script_field"
发布时间证据: "postDateTime: 2026-08-13T15:00:00Z"
发布时间校准原因: "页面脚本字段中的postDateTime明确标注了文章发布时间，无其他候选冲突。"
发布时间校准置信度: "1"
发布时间候选数量: 1
发布时间严格候选数量: 0
发布时间原页读取状态: "source template page reused from URL open"
发布时间未找到原因: ""
发布时间校准时间: "2026-08-14T18:48:51+08:00"
发布时间仲裁状态: "confirmed"
发布时间仲裁尝试次数: 1
发布时间仲裁耗时毫秒: 22923
发现时间: "2026-08-14T18:47:18+08:00"
入库时间: "2026-08-14T10:49:16.866Z"
来源平台: "固定入口"
搜索渠道: "fixed_url"
搜索词: "https://aws.amazon.com/new"
匹配关键词:
  []
相关厂家:
  - "AWS"
相关专家:
  []
内容类型: "网页"
抓取工具: "Free Fetch + Defuddle"
清洗工具: "Defuddle Markdown + Defuddle/Readability 正文提取"
原始附件:
  []
AI优质: "否"
AI打分: 5
AI分档: "非优质"
AI质检状态: "不通过"
AI打分理由: "内容为AWS证书管理服务功能变更，与超节点/AI Rack/机柜级AI基础设施完全无关，不涉及任何相关技术或落地信息。"
AI质检模型: "ali-deepseek-v4-flash"
AI质检时间: "2026-08-14T18:49:42+08:00"
AI主题相关性: 0
AI来源权威性: 5
AI新颖性: 0
AI技术细节: 0
AI商业部署信号: 0
AI完整性: 5
AI摘要: "AWS Certificate Manager（ACM）现支持将现有公有TLS证书的域名验证方式从电子邮件改为DNS，无需重新签发证书或更改ARN，现有集成不受影响。"
AI摘要模型: "ali-deepseek-v4-flash"
AI摘要时间: "2026-09-07T03:31:27.317Z"
采集批次: "2026年8月14日18点30分41秒"
采集批次ID: "20260814-183041-680"
去重键: "https://aws.amazon.com/cn/about-aws/whats-new/2026/08/AWS-Certificate-Manager-Email-DNS-Switch"
---

AWS Certificate Manager (ACM) now enables you to change the domain validation method on your existing ACM issued public TLS certificates from e-mail to DNS, without reissuing the certificate or changing its existing Amazon Resource Name (ARN). Due to the [Certification Authority/Browser (CA/B) Forum's](https://cabforum.org/) mandated deprecation of email-based domain validation for publicly trusted certificates, effective March 15, 2028, ACM will phase out its support for email validation throughout 2027. ACM will no longer issue email-validated certificates starting March 31 2027, and stop renewing email-validated certificates on September 30 2027. More details on ACM's deprecation of email validation can be found on the [AWS Security Blog](https://aws.amazon.com/blogs/security/aws-certificate-manager-will-discontinue-email-validation-to-prove-domain-validation-for-certificates). By switching to DNS validation now, you can transition ahead of that deadline and enable fully automated renewals through DNS validated certificates.

Your certificate ARN remains unchanged after switching from e-mail to DNS validation, so existing ARN references in your CI/CD pipelines, load balancer configurations, and other AWS service integrations continue to work without modification. To switch the validation method, use the ACM console or the [UpdateCertificateOptions](https://docs.aws.amazon.com/acm/latest/APIReference/API_UpdateCertificateOptions.html) API. ACM provides a CNAME record for each domain in the certificate (the same mechanism used when provisioning new certificates with DNS validation) and you have up to 72 hours to add the records to your DNS configuration. You can monitor the validation status of each domain via the console or the [ListCertificateDomainValidations](https://docs.aws.amazon.com/acm/latest/APIReference/API_ListCertificateDomainValidations.html) API. We recommend DNS validation for new certificates, and [HTTP validation](https://docs.aws.amazon.com/acm/latest/userguide/http-validation.html) for Amazon CloudFront distributions..

This feature is available in all AWS Regions where ACM certificates are available. To get started, refer to [Migrating from email to DNS validation](https://docs.aws.amazon.com/acm/latest/userguide/email-to-dns-migration.html) in the *AWS Certificate Manager User Guide.*
