> For the complete documentation index, see [llms.txt](https://docs.certinext.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.certinext.io/documentation/certificate-lifecycle-management/ordering-a-certificate/as-a-customer/ordering-dv-public-trust-certificates/phase-2-steps-via-email-and-emsign/domain-verification.md).

# Domain Verification

Domain verification is the most important step after payment. The Certificate Authority must confirm that you control the domain before it can issue the certificate. This section explains how to complete it.

<figure><img src="/files/0klD0wFfiDGBOPrv3EYa" alt=""><figcaption></figcaption></figure>

### What You See When You Expand Domain Verification

*Click on the **'3. Domain Verification'** row (or the + expand icon on the left).* The section expands to show:

* Total Domains: the number of domains that need to be verified (1 for DV SSL and Wildcard; your selected count for UCC variants).
* Under Domain Control Validation (DCV): your domain name(s) listed, each with a Verify button and a CAA button.
* The CAA button is for advanced DNS checks - typically for IT teams only. Use the Verify button.

### How to Start - Click the Verify Button

*Click the orange Verify button next to your domain name. A popup window titled:*

***'Domain Control Validation (\[your domain]) - #\[Order ID]'***

*opens.*

⚠️ **IMPORTANT**

Note shown in the popup:

*"This is technical in nature (if you are not the right person, please contact your IT / Domain administrator)."*

If you are not the person who manages your domain's DNS settings or web server, stop here. Copy the portal URL from your browser address bar and forward it to your IT or domain administrator. Ask them to complete the domain verification step on your behalf.

## Choosing a Domain Control Validation (DCV) Method

The popup shows a DCV Method dropdown. Two methods are available:

### Method 1 - DNS TXT Record (Most Preferred - Recommended for All Variants)

This method proves you control the domain by adding a special text record to your domain's DNS settings. It is recommended for all DV variants and is the only suitable method for Wildcard certificates.

<figure><img src="/files/5IB9Eq1nrvnpnbrBKWUz" alt=""><figcaption></figcaption></figure>

*Select **'DNS TXT Record (Most Preferred)'** from the DCV Method dropdown.*

*The popup shows:*

* ***Record Type:** TXT*
* ***Host:** Your domain name (or a specific validation subdomain). Use the Copy button to copy the exact value.*
* ***Value:** A unique alphanumeric token generated for your order (e.g., 5A27BFFF4R95F80945F8D5491A8FFC98). Use the Copy button - even a single character difference will cause verification to fail.*

### Step-by-Step Instructions for DNS TXT Record

1. *Log in to your domain registrar or DNS provider (e.g., GoDaddy, Cloudflare, Namecheap, Google Domains, AWS Route 53).*
2. *Navigate to the DNS Management section for your domain.*
3. *Add a new TXT record:*
   * *Host/Name: Paste the Host value copied from the popup.*
   * *Value/Content: Paste the long alphanumeric token copied from the popup.*
   * *TTL: Set to the minimum available (e.g., 300 seconds / 5 minutes) for fastest propagation.*
4. *Save the DNS record.*
5. *Wait 5–30 minutes for the DNS record to propagate. In rare cases, propagation can take up to 48 hours.*
6. *Return to the DCV popup in the emSign Subscriber Portal and click the orange **'Verify Now'** button.*
7. *If successful, a green confirmation popup appears.*

💡 **TIP**

You can check if your DNS record has propagated using a free tool such as dnschecker.org. Search for your domain and the TXT record type. Once the value appears worldwide, click Verify Now.

## Method 2 - HTTP/HTTPS File-Based Validation (For DV SSL and DV UCC Only)

This method proves domain control by uploading a small text file to your web server at a specific URL. The CA then checks that the file exists and contains the correct token.

⚠️ **IMPORTANT**

File-based validation is **NOT suitable for Wildcard certificates** (DV Wildcard SSL and DV Wildcard UCC). For Wildcard domains, use the DNS TXT Record method only.

Note shown in the popup:

*"File-based (HTTP/HTTPS URL) DCV method can only be used to prove domain ownership over Fully Qualified Domain Names (FQDNs), exactly as named."*

<figure><img src="/files/nWidfO2ObhnZksboamsA" alt=""><figcaption></figcaption></figure>

The popup shows:

* **File Name:** A specific filename (e.g., 084984170207f94FB0482A1A70BF9A82.txt). Use the Copy button.
* **File Content:** A unique token string (e.g., 30924A299885503882D10144825CD4F5). Use the Copy button.
* **Download File link:** Click this to download the ready-made .txt file - saves you creating it manually.
* **Full Path:** The exact URL where the file must be accessible (e.g., <http://yourdomain.com/.well-known/pki-validation/filename.txt>).

### Step-by-Step Instructions for File-Based Validation

1. *Click **Download File** in the popup to download the ready-made file.*
2. *Upload the file to your web server at exactly this path:*

*`http://[yourdomain.com]/.well-known/pki-validation/[filename].txt`*

3. *Do not change the filename or its contents.*
4. *Verify the file is accessible:*

* *Open the URL in a browser.*
* *If you see the token text displayed or the file downloads, it is accessible.*
* *A 404 error means the file is not in the correct location.*

5. *Once the file is accessible at the correct URL, click **Verify Now** in the popup.*

💡 **TIP**

To upload the file, use:

* Your hosting control panel's File Manager (cPanel, Plesk)
* An FTP client such as FileZilla
* Your hosting provider's file upload service

***Choose the one applicable to your scenario based on the above description***

## Variant Differences - Domain Verification

#### DV SSL Certificate

* DNS TXT Record (recommended)
* HTTP/HTTPS File-Based

#### DV Wildcard SSL Certificate

* DNS TXT Record ONLY

#### DV UCC SSL Certificate

* DNS TXT Record (recommended)
* HTTP/HTTPS File-Based

#### DV Wildcard UCC SSL Certificate

* DNS TXT Record ONLY for each wildcard domain

📌 **InCommon Note**

The DNS TXT Record method is recommended for all InCommon institutional certificates.

If your domain DNS is managed by your institution's IT department:

* Provide them with the Host and Value shown in the popup.
* Ask them to add the TXT record.

For UCC variants with multiple domains from different departments, each domain administrator may need to be contacted separately.

## After Domain Verification Succeeds

*Once you click **Verify Now** and the CA confirms your domain control, a green success popup appears:*

📌 **NOTE**

*"Thank you for proving the domain ownership for \[your domain]. Domain Verification is completed successfully. Please track your order and complete your pending actions to speed up the certificate issuance process."*

*Click **OK**.*

*The Order Actions list updates:*

* *Domain Verification now shows a green **Completed** status.*
* *Steps 1, 2, and 3 will all display green Completed indicators.*

⚠️ **IMPORTANT**

**Reminder about Administrator Approval**

Even after domain verification is complete, the certificate will **NOT** be issued until the CERTInext Account Administrator approves the order.

If the Certificate Status remains **Pending for Approver** for an extended period after domain verification:

* Contact your IT department.
* Request that the order be approved in CERTInext.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.certinext.io/documentation/certificate-lifecycle-management/ordering-a-certificate/as-a-customer/ordering-dv-public-trust-certificates/phase-2-steps-via-email-and-emsign/domain-verification.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
