ACME domain validation with 217 DNS providers
Before an ACME authority signs, it wants proof that you control the name. aethercert answers the challenge automatically - with a DNS record, a file on the web server or a TLS handshake - on every issuance and every renewal.
DNS-01, HTTP-01 and TLS-ALPN-01 are available on every plan. Verified domains: 1 on Community, 5 on Standard, 25 on Pro, 5 per MSP organization. See plans and limits
present_acme-challenge.example.com TXT "gfj9Xq...Rg85nM"present_acme-challenge.example.com TXT "ZL2w1o...KSq7uE"propagatevisible on all authoritative servers · 41svalidatedns-01 valid for example.com, *.example.comcleanup2 TXT records removedWhat it does
You verify each domain once with a TXT record, then connect the DNS provider that hosts it. From then on, every certificate for that domain or its subdomains - including wildcards - is validated with DNS-01: the agent publishes the _acme-challenge record through the provider's API, waits for it to propagate, and removes it afterwards.
When DNS-01 is not an option, the agent can answer HTTP-01 by writing the challenge file into the web server's webroot, or TLS-ALPN-01 on port 443. A certificate whose names live in different zones or different provider accounts is validated name by name, with the right credentials for each.
How it works
- 01
Verify the domain
A one-time TXT record proves the domain belongs to your organization.
- 02
Connect the provider
Choose one of 217 DNS providers and enter an API credential. It is stored encrypted and handed to the agent only during issuance.
- 03
Answer the challenge
The agent creates the record, checks propagation with generous timeouts, and lets the CA validate.
- 04
Clean up
Challenge records and files are removed after validation.
Key capabilities
217 DNS providers
Cloudflare, AWS Route 53, Azure DNS, Google Cloud DNS, Hetzner, IONOS, OVHcloud, Infoblox, BlueCat and many more - plus ACME-DNS, a generic webhook and a custom script.
Wildcard certificates
ACME requires DNS-01 for *.example.com; the agent answers it like any other challenge.
Cross-zone SANs
One certificate can cover names in several zones or provider accounts; each name is matched to its own credentials.
HTTP-01 and TLS-ALPN-01
For hosts reachable from the internet where DNS automation is not possible.
Port preflight
Before HTTP-01 or TLS-ALPN-01, a reachability check tells you whether the CA will be able to connect.
IPv4 and IPv6
Choose per agent whether it uses dual stack, IPv4 only or IPv6 only for outbound connections.
Compared with validating by hand
| By hand | With aethercert |
|---|---|
| Copy a TXT value from the CA into the DNS console and wait. | The agent publishes and removes the record through the provider API. |
| Wildcard renewals need a person every time. | Wildcards renew like any other certificate. |
| Names in two zones mean two consoles and two logins. | Each name is validated with the credentials of its own zone. |
Supported DNS providers and authorities
Domain validation applies to ACME authorities. Internal CAs behind the CA connector authorize requests through the certificate template instead.
Security considerations
Credentials released per issuance
DNS API credentials are encrypted at rest and passed to the agent only for an issuance; the agent does not persist them.
Domain ownership first
A domain must be verified with a TXT record before certificates can be requested for it.
Least-privilege tokens
Where the provider supports it, use a token limited to the zone and to TXT records.
Example: a wildcard certificate
*.example.com and example.com, DNS hosted at Cloudflare.
orderThe agent opens an ACME order for both names.presentTwo TXT values are published at _acme-challenge.example.com via the Cloudflare API.propagateThe agent polls until the records are visible, up to five minutes.validateThe CA checks the records and signs the certificate.cleanupBoth TXT values are removed.
Frequently asked questions
Domain validation
Is my DNS provider supported?
Probably - aethercert supports 217 DNS providers. If yours is not listed, use ACME-DNS with a CNAME delegation, the generic webhook, or a custom script on the agent host.
Do I need DNS-01 for internal names?
Only with an ACME authority. Certificates from AD CS through the CA connector are authorized by the certificate template and need no public DNS record.
Can I use HTTP-01 behind a firewall?
HTTP-01 and TLS-ALPN-01 require the certificate authority to reach the host on port 80 or 443. The preflight check tells you whether it can; otherwise use DNS-01.
Automate your DNS challenges
Verify a domain, connect its DNS provider, and wildcard renewals stop needing a person.
Community plan, no card required. Open registration - your account is ready in a few minutes.