Domain Verification Instructions
Domain verification is a core step in SSL certificate requests. It confirms domain control rights through DNS records, file upload, or email verification. Its core purpose is to prevent unauthorized use, ensuring that only legitimate domain owners can request certificates.
I. Why Domain Verification Is Required
Domain verification is one of the necessary procedures in the SSL certificate issuance process, mainly for the following reasons:
1. Verify Domain Management Rights
By adding DNS resolutions, completing file verification, or using email verification, applicants obtain recognition of their domain management authority from Certificate Authorities (CAs). This verifies that applicants have control over the domain and prevents malicious third parties from fraudulently obtaining certificates under others' identities.
2. Prevent Phishing Attacks
The domain verification process can effectively stop attackers from forging legitimate domains to create phishing sites, protecting users from the risk of sensitive information leakage.
3. Meet Security Standards
Major browsers require websites to use SSL certificates that have passed domain verification; otherwise, they will be marked as "Not Secure". Domain verification demonstrates the compliance of SSL certificates.
II. How to Complete Domain Verification
There are mainly three methods as follows:
1. DNS Resolution Record Verification
Log in to the domain management platform and add the verification record value provided by the CA (usually of TXT or CNAME type) to the domain's DNS resolutions.
2. File Verification
Create a specified path in the website root directory and place the corresponding content there. The specific verification content is provided by the CA.
3. Email Verification
The CA sends a verification email to the administrator email reserved during domain registration (such as administrator@domain, webmaster@domain, hostmaster@domain, postmaste@domain). Customers need to log in to the email inbox, check the verification email, and click the link to confirm, after which domain verification is completed.
III. Domain Verification Operations for Major Certificate Brands
- Intranet or self-signed certificates do not require domain verification
1. Sectigo/Positive/sslTrus
-
DNS resolution: Two record types are available: CNAME and TXT
-
File verification: Only supports verification via
80/443port -
Email verification: WHOIS email (unavailable after 2025.6.15) or administrator email
Information- For sslTrus, Sectigo, and Positive, to add TXT records, you need to contact Racent customer service to obtain them. The default resolution type is
CNAME
- For sslTrus, Sectigo, and Positive, to add TXT records, you need to contact Racent customer service to obtain them. The default resolution type is
2. Digicert/Geotrust/Thawte
- DNS resolution: Type is TXT, with a fixed host record:
_dnsauth - File verification: Only supports verification via
80/443port - Email verification: Administrator email; WHOIS email is unavailable after 2025.5.8
3. CFCA
- DNS resolution: Type is TXT
- File verification: Supports verification via
80/443port - Email verification: Administrator email
- Starting from July 15, 2025, emails obtained through WHOIS queries can no longer be directly used for Domain Control Validation (DCV). You must use administrator emails in the form of admin@, administrator@, webmaster@, hostmaster@, postmaster@ + the primary domain for email verification.
- As currently required by CBA and specified in the CP/CPS rules on CFCA's official website, HTTP or HTTPS methods must be used, and the ports must be authorized ports (i.e., 80 and 443). This requirement will take effect on August 1, 2025.
4. Globalsign
- DNS resolution: Type is TXT, and the host record can be left blank
- File verification: Only supports verification via
80/443port - Email verification: Administrator email
5. RapidSSL
- The default DNS resolution value is for subdomains. If you want to add it to the primary domain, the resolution value needs to be regenerated.