DigiCert Policy Update: Domain Validation Changes and DNSSEC Validation (2026)
By Pacific Internet – March 06, 2026

1. Domain Validation Reuse Period Shortened
Effective Date: 24 February 2026
In accordance with CA/Browser Forum Ballot SC081v3, the maximum period that a domain validation can be reused has been shortened.
Previously, domain validation could be reused for up to 397 days. This reuse window will now gradually decrease over the coming years to improve overall certificate security standards.
If the previous validation exceeds the allowed reuse period, customers will need to re-complete domain validation before certificates can be issued, reissued, or renewed.
Updated Domain Validation Reuse Timeline
The CA/Browser Forum is gradually reducing the maximum period that domain validation can be reused. DigiCert follows this schedule but sets its reuse period one day shorter to ensure compliance.
Before 24 February 2026
Maximum domain validation reuse: 397 days
24 February 2026 – Early 2027
Maximum domain validation reuse: 199 days
Early 2027 – Early 2029
Maximum domain validation reuse: 99 days
After Early 2029
Maximum domain validation reuse: 9 days
Note: DigiCert sets its maximum validation reuse period one day shorter than the CA/Browser Forum requirement to ensure compliance with the permitted reuse window.
What this means for customers
Domain validation may need to be performed more frequently
This requirement applies to certificate issuance, reissuance, and renewal
Failure to complete the required validation may delay certificate issuance
___________________________________________________________________________________________________________________________________________________________
2. DNSSEC Validation Update
Effective Date: 3 March 2026, 17:00 UTC
DigiCert will begin validating DNSSEC signatures during domain validation checks when DNSSEC is enabled for a domain.
This validation will apply when DigiCert performs:
Domain Control Validation (DCV)
Certification Authority Authorization (CAA) checks
Key Points
DNSSEC is optional and not required for SSL certificate issuance.
If your domain does not use DNSSEC, no action is required.
If DNSSEC is enabled, DigiCert’s DNS resolvers will validate DNSSEC signatures.
If DNSSEC validation fails due to configuration issues, certificate issuance may be blocked.
Customers using DNSSEC should ensure their DNSSEC configuration is correctly set up to avoid disruptions.

