aethercert
Domain validation

ACME domain validation with 217 DNS providers

Before an ACME authority signs, it wants proof that you control the name. aethercert answers the challenge automatically - with a DNS record, a file on the web server or a TLS handshake - on every issuance and every renewal.

DNS-01, HTTP-01 and TLS-ALPN-01 are available on every plan. Verified domains: 1 on Community, 5 on Standard, 25 on Pro, 5 per MSP organization. See plans and limits

A DNS-01 challenge answered through the DNS provider's API.
01Domain validation

What it does

You verify each domain once with a TXT record, then connect the DNS provider that hosts it. From then on, every certificate for that domain or its subdomains - including wildcards - is validated with DNS-01: the agent publishes the _acme-challenge record through the provider's API, waits for it to propagate, and removes it afterwards.

When DNS-01 is not an option, the agent can answer HTTP-01 by writing the challenge file into the web server's webroot, or TLS-ALPN-01 on port 443. A certificate whose names live in different zones or different provider accounts is validated name by name, with the right credentials for each.

How it works

  1. 01

    Verify the domain

    A one-time TXT record proves the domain belongs to your organization.

  2. 02

    Connect the provider

    Choose one of 217 DNS providers and enter an API credential. It is stored encrypted and handed to the agent only during issuance.

  3. 03

    Answer the challenge

    The agent creates the record, checks propagation with generous timeouts, and lets the CA validate.

  4. 04

    Clean up

    Challenge records and files are removed after validation.

Key capabilities

217 DNS providers

Cloudflare, AWS Route 53, Azure DNS, Google Cloud DNS, Hetzner, IONOS, OVHcloud, Infoblox, BlueCat and many more - plus ACME-DNS, a generic webhook and a custom script.

Wildcard certificates

ACME requires DNS-01 for *.example.com; the agent answers it like any other challenge.

Cross-zone SANs

One certificate can cover names in several zones or provider accounts; each name is matched to its own credentials.

HTTP-01 and TLS-ALPN-01

For hosts reachable from the internet where DNS automation is not possible.

Port preflight

Before HTTP-01 or TLS-ALPN-01, a reachability check tells you whether the CA will be able to connect.

IPv4 and IPv6

Choose per agent whether it uses dual stack, IPv4 only or IPv6 only for outbound connections.

Compared with validating by hand

By handWith aethercert
Copy a TXT value from the CA into the DNS console and wait.The agent publishes and removes the record through the provider API.
Wildcard renewals need a person every time.Wildcards renew like any other certificate.
Names in two zones mean two consoles and two logins.Each name is validated with the credentials of its own zone.

Supported DNS providers and authorities

Domain validation applies to ACME authorities. Internal CAs behind the CA connector authorize requests through the certificate template instead.

Security considerations

Credentials released per issuance

DNS API credentials are encrypted at rest and passed to the agent only for an issuance; the agent does not persist them.

Domain ownership first

A domain must be verified with a TXT record before certificates can be requested for it.

Least-privilege tokens

Where the provider supports it, use a token limited to the zone and to TXT records.

Example: a wildcard certificate

*.example.com and example.com, DNS hosted at Cloudflare.

  1. orderThe agent opens an ACME order for both names.
  2. presentTwo TXT values are published at _acme-challenge.example.com via the Cloudflare API.
  3. propagateThe agent polls until the records are visible, up to five minutes.
  4. validateThe CA checks the records and signs the certificate.
  5. cleanupBoth TXT values are removed.

Frequently asked questions

Domain validation

Is my DNS provider supported?

Probably - aethercert supports 217 DNS providers. If yours is not listed, use ACME-DNS with a CNAME delegation, the generic webhook, or a custom script on the agent host.

Do I need DNS-01 for internal names?

Only with an ACME authority. Certificates from AD CS through the CA connector are authorized by the certificate template and need no public DNS record.

Can I use HTTP-01 behind a firewall?

HTTP-01 and TLS-ALPN-01 require the certificate authority to reach the host on port 80 or 443. The preflight check tells you whether it can; otherwise use DNS-01.

Automate your DNS challenges

Verify a domain, connect its DNS provider, and wildcard renewals stop needing a person.

Community plan, no card required. Open registration - your account is ready in a few minutes.