DNSSEC Validation Now Enforced for DCV and CAA Checks by Sectigo
By Pacific Internet – April 06, 2026

DNSSEC Validation Now Enforced for DCV and CAA Checks by Sectigo
Effective 5 March 2026, Sectigo has implemented mandatory DNSSEC validation during Domain Control Validation (DCV) and Certificate Authority Authorization (CAA) checks, in alignment with updated CA/Browser Forum compliance requirements.
What This Means for Your Domain
DNSSEC itself remains optional — however, if your domain has DNSSEC enabled, successful validation is now a prerequisite for DCV and CAA checks to proceed. Should DNSSEC validation fail — for example, if a SERVFAIL response is returned — certificate issuance or reissuance will be suspended until the underlying issue is resolved. This may introduce delays in obtaining or renewing SSL/TLS certificates.
Recommended Action
If your domain is configured with DNSSEC, we strongly advise reviewing your DNSSEC setup to ensure it is correctly maintained. This includes monitoring key rollovers and confirming that your DNS configuration consistently passes validation checks. Proactive maintenance will help prevent unexpected interruptions to certificate issuance.
For full details on this compliance change, please refer to the Sectigo DCV Industry Compliance Changes page.



