Domain Authentication is Step 4 in the Organization Validation (OV) process for your SSL certificate. At this stage the Certificate Authority (CA) needs to confirm that your organisation actually controls the exact domain name you asked to secure. It is a separate check from confirming that your company exists and is who it claims to be, which is handled in the earlier steps.

OV validation runs as a short sequence of checks. Domain Authentication sits fourth in that sequence:

  1. Step 1: Organization Authentication - confirming your company is a real, registered legal entity.
  2. Step 2: Locality Presence - confirming your business address and location.
  3. Step 3: Telephone Verification - confirming a listed, reachable business phone number.
  4. Step 4: Domain Authentication - proving your organisation controls the domain on the certificate (this step).
  5. Step 5: Final Verification Call - a closing call from the CA to confirm the request before issuance.
1 Organization 2 Locality 3 Telephone 4 Domain Auth 5 Final Call

How domain control is proved

The CA will ask you to demonstrate control of the domain using one of a few standard methods. You only need to complete one of them, and your validation guide will list the exact value to use:

  • Email approval - the CA sends a link to an approved address on the domain, such as admin@ or webmaster@, or to the contact shown in the domain registration record. You click the link to approve.
  • DNS record - you add a specific TXT or CNAME record to the domain's DNS zone. The CA queries public DNS to confirm it is present.
  • File-based check - you upload a small text file with a given name and contents to a set path on the site, and the CA fetches it over HTTP.

For domain names that use privacy protection or a role-based registrant, the email method may not surface a usable address, so the DNS or file method is usually the smoother choice. If your site is hosted with us on a dedicated IP, adding a DNS record or uploading a file is straightforward from your control panel. You can review your certificate and its coverage on our SSL certificates page.

Practical tips

  • Complete Domain Authentication for the precise domain and any subdomains listed on the request. A record set for the wrong host will not validate.
  • DNS changes need time to propagate before the CA can see them, so allow a short wait after adding a TXT or CNAME record.
  • Keep the approval email or the added record in place until the certificate is issued. Removing it early can stall the process.
  • If an approval link expires before you act, request a fresh one rather than reusing the old message.

Domain control checks like these follow well-defined public standards; if you want the underlying detail, the Let's Encrypt documentation explains the common HTTP and DNS challenge types clearly, and the same concepts apply to OV validation.

Once Domain Authentication is confirmed, the process moves on to Step 5, the Final Verification Call, after which your certificate can be issued. For the other steps and related questions, see our SSL certificates FAQ. If any check will not complete or you are unsure which value to use, our team can walk you through it.

Hai trovato utile questa risposta? 24 Utenti hanno trovato utile questa risposta (92 Voti)