Bobcares

All about AWS ACM email validation

by | Oct 25, 2021

AWS ACM email validation is not working? Our Support Team is here to help you out.

At Bobcares, we come up with solutions for every query as a part of our AWS Support Services.

Let’s take a look at how our talented Support Engineers resolved this specific issue.

What is AWS ACM email validation?

AWS Certificate Manager is responsible for sending validation emails to the 5 common system addresses provided that an MX record exists for the domain.

A domain validation email goes out to the email addresses are associated with the technical contact, domain registrant as well as administrative contact fields in the WHOIS listing.

Unfortunately, some domain registrars do not contain the contact information in WHOIS. The ACM certificate issue or renewal is affected if:

  • The contact email address is not present in your domain registrar WHOIS data.
  • Custom email addresses are used for certificate validation in WHOIS.

The WHOIS lookup searches for the email addresses in the technical contact, domain registrar, and administrative contact fields.

Our Support Engineers recommend verifying the listed email address with a WHOIS query. For instance, you will receive a similar reply of everything is in order:

Registrant Contact
Name: Data Protected Data Protected
Organization: Data Protected
Mailing Address: 124 Data Protected, Toronto ON M5K 3M1 CA
Phone: +1.0000000000
Ext:
Fax: +1.0000000000
Fax Ext:
Email:noreply@data-protected.net

How to resolve AWS ACM email validation error?

Our Support Team has come up with two ways to accomplish AWS ACM email validation. You can choose either one based on the effort required or preference.

AWS ACM email validation via email

It is always a good idea to verify at least one of the 5 default email addresses to ensure it is valid and monitored regularly. You can select the link in the validation email to proceed with the validation.

In case you have not received any email, you have to verify whether the domain has at least one existing MX record by running the following commands:

For Linux and macOS:

$dig mx example.com

For Windows:

$nslookup -q=mx example.com

The mail servers specified in the MX records will receive the validation emails as seen below:

;; ANSWER SECTION:
example.com.             599     IN      MX      10 mail1.example.com.
example.com.             599     IN      MX      20 mail2.example.com.

If you do not have an MX record or if your domain registrar does not support email forwarding, we have a solution for that as well. You can use Amazon Simple Email Service (Amazon SES) and Amazon Simple Notification Service (Amazon SNS) to get the job done.

AWS ACM email validation via DNS

In order to switch to DNS validation, our Support Techs recommend recreating the ACM certificate and selecting DNS for validation. Furthermore, DNS validation offers additional advantages over email validation.

  • You have to create one CNAME record for each domain name for DNS validation. Moreover, email validation sends up to 8 emails messages for each domain name.
  • ACM automatically renews validated certificates before they expire.
  • You can request additional ACM certificates for the FQDN.
  • Moreover, you can switch to DNS validation without any incurring additional costs.
  • Automation via DNS validation is less complex.

Furthermore, ensure you update services integrated with AWS Certificate Manager so that they use the new certificate. The new ACM certificate generates an ARN. Furthermore, the previous ARN will not be retained with a new ACM certificate.

Our Support Engineers would like to point out that you can establish the Region for the ACM certificate with the following command:

$aws acm describe-certificate --certificate-arn arn:aws:acm:region:12345678911:certificate/123456-1234-1234-1234-123456789 --output text |grep INUSEBY

[Looking for further assistance? Give us a call today. ]

Conclusion

At the end of the day, the Support Team at Bobcares demonstrated how to carry out AWS ACM email validation via email as well as how to switch to DNS validation.

PREVENT YOUR SERVER FROM CRASHING!

Never again lose customers to poor server speed! Let us help you.

Our server experts will monitor & maintain your server 24/7 so that it remains lightning fast and secure.

GET STARTED

0 Comments

Submit a Comment

Your email address will not be published. Required fields are marked *

Never again lose customers to poor
server speed! Let us help you.

Privacy Preference Center

Necessary

Necessary cookies help make a website usable by enabling basic functions like page navigation and access to secure areas of the website. The website cannot function properly without these cookies.

PHPSESSID - Preserves user session state across page requests.

gdpr[consent_types] - Used to store user consents.

gdpr[allowed_cookies] - Used to store user allowed cookies.

PHPSESSID, gdpr[consent_types], gdpr[allowed_cookies]
PHPSESSID
WHMCSpKDlPzh2chML

Statistics

Statistic cookies help website owners to understand how visitors interact with websites by collecting and reporting information anonymously.

_ga - Preserves user session state across page requests.

_gat - Used by Google Analytics to throttle request rate

_gid - Registers a unique ID that is used to generate statistical data on how you use the website.

smartlookCookie - Used to collect user device and location information of the site visitors to improve the websites User Experience.

_ga, _gat, _gid
_ga, _gat, _gid
smartlookCookie
_clck, _clsk, CLID, ANONCHK, MR, MUID, SM

Marketing

Marketing cookies are used to track visitors across websites. The intention is to display ads that are relevant and engaging for the individual user and thereby more valuable for publishers and third party advertisers.

IDE - Used by Google DoubleClick to register and report the website user's actions after viewing or clicking one of the advertiser's ads with the purpose of measuring the efficacy of an ad and to present targeted ads to the user.

test_cookie - Used to check if the user's browser supports cookies.

1P_JAR - Google cookie. These cookies are used to collect website statistics and track conversion rates.

NID - Registers a unique ID that identifies a returning user's device. The ID is used for serving ads that are most relevant to the user.

DV - Google ad personalisation

_reb2bgeo - The visitor's geographical location

_reb2bloaded - Whether or not the script loaded for the visitor

_reb2bref - The referring URL for the visit

_reb2bsessionID - The visitor's RB2B session ID

_reb2buid - The visitor's RB2B user ID

IDE, test_cookie, 1P_JAR, NID, DV, NID
IDE, test_cookie
1P_JAR, NID, DV
NID
hblid
_reb2bgeo, _reb2bloaded, _reb2bref, _reb2bsessionID, _reb2buid

Security

These are essential site cookies, used by the google reCAPTCHA. These cookies use an unique identifier to verify if a visitor is human or a bot.

SID, APISID, HSID, NID, PREF
SID, APISID, HSID, NID, PREF