ACM lets you switch validation from email to DNS
🔐 AWS Certificate Manager now allows changing domain validation on existing public TLS certificates from e-mail to DNS without reissuing or changing the ARN. ACM will phase out email validation through 2027 per CA/B Forum mandates; it will stop issuing email-validated certs on March 31, 2027 and stop renewing them on September 30, 2027. Use the console or UpdateCertificateOptions API to switch and add provided CNAME records within 72 hours.
