Powered byPacific Internet

Asia Pacific's Trusted Internet Services Provider Since 1991

DNSSEC Validation Now Enforced for DCV and CAA Checks by Sectigo

By Pacific InternetApril 06, 2026
DNSSEC Validation Now Enforced for DCV and CAA Checks by Sectigo

DNSSEC Validation Now Enforced for DCV and CAA Checks by Sectigo

Effective 5 March 2026, Sectigo has implemented mandatory DNSSEC validation during Domain Control Validation (DCV) and Certificate Authority Authorization (CAA) checks, in alignment with updated CA/Browser Forum compliance requirements.

What This Means for Your Domain

DNSSEC itself remains optional — however, if your domain has DNSSEC enabled, successful validation is now a prerequisite for DCV and CAA checks to proceed. Should DNSSEC validation fail — for example, if a SERVFAIL response is returned — certificate issuance or reissuance will be suspended until the underlying issue is resolved. This may introduce delays in obtaining or renewing SSL/TLS certificates.

Recommended Action

If your domain is configured with DNSSEC, we strongly advise reviewing your DNSSEC setup to ensure it is correctly maintained. This includes monitoring key rollovers and confirming that your DNS configuration consistently passes validation checks. Proactive maintenance will help prevent unexpected interruptions to certificate issuance.

For full details on this compliance change, please refer to the Sectigo DCV Industry Compliance Changes page.

Chat With Us