Domain Verification
Domain verification is the most important step after payment. The Certificate Authority must confirm that you control the domain before it can issue the certificate. This section explains how to complete it.

What You See When You Expand Domain Verification
Click on the '3. Domain Verification' row (or the + expand icon on the left). The section expands to show:
Total Domains: the number of domains that need to be verified (1 for DV SSL and Wildcard; your selected count for UCC variants).
Under Domain Control Validation (DCV): your domain name(s) listed, each with a Verify button and a CAA button.
The CAA button is for advanced DNS checks - typically for IT teams only. Use the Verify button.
How to Start - Click the Verify Button
Click the orange Verify button next to your domain name. A popup window titled:
'Domain Control Validation ([your domain]) - #[Order ID]'
opens.
⚠️ IMPORTANT
Note shown in the popup:
"This is technical in nature (if you are not the right person, please contact your IT / Domain administrator)."
If you are not the person who manages your domain's DNS settings or web server, stop here. Copy the portal URL from your browser address bar and forward it to your IT or domain administrator. Ask them to complete the domain verification step on your behalf.
Choosing a Domain Control Validation (DCV) Method
The popup shows a DCV Method dropdown. Two methods are available:
Method 1 - DNS TXT Record (Most Preferred - Recommended for All Variants)
This method proves you control the domain by adding a special text record to your domain's DNS settings. It is recommended for all DV variants and is the only suitable method for Wildcard certificates.

Select 'DNS TXT Record (Most Preferred)' from the DCV Method dropdown.
The popup shows:
Record Type: TXT
Host: Your domain name (or a specific validation subdomain). Use the Copy button to copy the exact value.
Value: A unique alphanumeric token generated for your order (e.g., 5A27BFFF4R95F80945F8D5491A8FFC98). Use the Copy button - even a single character difference will cause verification to fail.
Step-by-Step Instructions for DNS TXT Record
Log in to your domain registrar or DNS provider (e.g., GoDaddy, Cloudflare, Namecheap, Google Domains, AWS Route 53).
Navigate to the DNS Management section for your domain.
Add a new TXT record:
Host/Name: Paste the Host value copied from the popup.
Value/Content: Paste the long alphanumeric token copied from the popup.
TTL: Set to the minimum available (e.g., 300 seconds / 5 minutes) for fastest propagation.
Save the DNS record.
Wait 5–30 minutes for the DNS record to propagate. In rare cases, propagation can take up to 48 hours.
Return to the DCV popup in the emSign Subscriber Portal and click the orange 'Verify Now' button.
If successful, a green confirmation popup appears.
💡 TIP
You can check if your DNS record has propagated using a free tool such as dnschecker.org. Search for your domain and the TXT record type. Once the value appears worldwide, click Verify Now.
Method 2 - HTTP/HTTPS File-Based Validation (For DV SSL and DV UCC Only)
This method proves domain control by uploading a small text file to your web server at a specific URL. The CA then checks that the file exists and contains the correct token.
⚠️ IMPORTANT
File-based validation is NOT suitable for Wildcard certificates (DV Wildcard SSL and DV Wildcard UCC). For Wildcard domains, use the DNS TXT Record method only.
Note shown in the popup:
"File-based (HTTP/HTTPS URL) DCV method can only be used to prove domain ownership over Fully Qualified Domain Names (FQDNs), exactly as named."

The popup shows:
File Name: A specific filename (e.g., 084984170207f94FB0482A1A70BF9A82.txt). Use the Copy button.
File Content: A unique token string (e.g., 30924A299885503882D10144825CD4F5). Use the Copy button.
Download File link: Click this to download the ready-made .txt file - saves you creating it manually.
Full Path: The exact URL where the file must be accessible (e.g., http://yourdomain.com/.well-known/pki-validation/filename.txt).
Step-by-Step Instructions for File-Based Validation
Click Download File in the popup to download the ready-made file.
Upload the file to your web server at exactly this path:
http://[yourdomain.com]/.well-known/pki-validation/[filename].txt
Do not change the filename or its contents.
Verify the file is accessible:
Open the URL in a browser.
If you see the token text displayed or the file downloads, it is accessible.
A 404 error means the file is not in the correct location.
Once the file is accessible at the correct URL, click Verify Now in the popup.
💡 TIP
To upload the file, use:
Your hosting control panel's File Manager (cPanel, Plesk)
An FTP client such as FileZilla
Your hosting provider's file upload service
Choose the one applicable to your scenario based on the above description
Variant Differences - Domain Verification
DV SSL Certificate
DNS TXT Record (recommended)
HTTP/HTTPS File-Based
DV Wildcard SSL Certificate
DNS TXT Record ONLY
DV UCC SSL Certificate
DNS TXT Record (recommended)
HTTP/HTTPS File-Based
DV Wildcard UCC SSL Certificate
DNS TXT Record ONLY for each wildcard domain
📌 InCommon Note
The DNS TXT Record method is recommended for all InCommon institutional certificates.
If your domain DNS is managed by your institution's IT department:
Provide them with the Host and Value shown in the popup.
Ask them to add the TXT record.
For UCC variants with multiple domains from different departments, each domain administrator may need to be contacted separately.
After Domain Verification Succeeds
Once you click Verify Now and the CA confirms your domain control, a green success popup appears:
📌 NOTE
"Thank you for proving the domain ownership for [your domain]. Domain Verification is completed successfully. Please track your order and complete your pending actions to speed up the certificate issuance process."
Click OK.
The Order Actions list updates:
Domain Verification now shows a green Completed status.
Steps 1, 2, and 3 will all display green Completed indicators.
⚠️ IMPORTANT
Reminder about Administrator Approval
Even after domain verification is complete, the certificate will NOT be issued until the CERTInext Account Administrator approves the order.
If the Certificate Status remains Pending for Approver for an extended period after domain verification:
Contact your IT department.
Request that the order be approved in CERTInext.
Last updated
