Skip to main content

What is the Certificate Authority (CA)'s polling frequency for certificate validation (checking DNS resolution records)?

Regarding when CAs check the configuration status of domain resolution records (such as TXT records), the following points should be noted:

  1. No fixed time points: CAs typically do not publicly disclose their specific inspection schedules and frequency mechanisms. This process is affected by various dynamic factors, including internal server load, order queue status, and overall customer request volume.

  2. Observed typical patterns: Based on our analysis of historical data from a large number of certificate issuance processes, CA inspection behavior generally follows the patterns below (with frequency decreasing in sequence):

    • Early window: Inspections usually occur within 3–5 minutes after the order is submitted.

    • Subsequent windows: Inspections usually occur within 20–30 minutes and within 1 hour after the order is submitted.

  3. Decreasing frequency: The frequency of validation attempts generally decreases over time. That is, validations are most frequent in the first few minutes after order submission, and the interval between attempts may gradually lengthen afterward.

  4. Core recommendation: We strongly recommend that you complete the configuration of required DNS resolution records (such as TXT records) immediately after submitting a certificate request order, and ensure they take effect globally. This is the most reliable way to ensure the certificate validation process is completed smoothly and efficiently.

Summary: The timing of CA DNS record checks is not fixed, but historical data shows typical inspection windows at 3–5 minutes, 20–30 minutes, and within 1 hour after submission, with decreasing detection frequency. To ensure application efficiency, be sure to correctly configure DNS records as soon as possible after submitting your order.

Common reasons for failed validation
  1. DNS record values, host records, etc. are not properly configured;
  2. Records are configured but not detected — check whether there are network whitelist restrictions;
  3. Delays on international routes for DNS validation;
  4. Firewall restrictions;
Validity period of DNS resolution values

Sectigo, sslTrus, and PositiveSSL values remain permanently valid; Digicert, Geotrust, Rapid, Thawte, and Globalsign values are valid for 30 days; CFCA values are valid for 15 days