Validation Delays From DNS Configuration

Once you add a Domain Name System (DNS) record to validate your domain, there can be a short wait before your SSL Certificate is issued. This is normal, and it almost always comes down to how long your Domain Name System (DNS) answers are cached, or where the record was placed. Learn About The Validation Procedure 🔗

Knowing how caching works makes the delay predictable, and two simple settings remove most of it.

Record Caching Explained

Every Domain Name System (DNS) record carries a Time to Live (TTL), which is the length of time an answer may be cached and reused before the authoritative server is checked again. If your Time to Live (TTL) is set to four hours, an answer can be trusted for up to four hours before a fresh lookup is made.

The Certificate Authority (CA) that issues your SSL Certificate is subject to the same caching. If it looks up your record while an earlier answer is still within its Time to Live (TTL), it continues to see that earlier state until the period has passed.

Delay During Validation

When you place an order, the Certificate Authority (CA) queries your Domain Name System (DNS) to confirm you control the domain. If the new record was not yet visible at that first check, or an earlier answer was cached, the Certificate Authority (CA) honors your Time to Live (TTL) and does not look again until that period has passed.

This is a security requirement, not a limitation we are able to set aside. Your Time to Live (TTL) is an instruction stating how long an answer may be trusted, and a Certificate Authority (CA) is not permitted to ignore it and query again early. Doing so would undermine the integrity of the Domain Name System (DNS) answers used to prove control of a domain.

Lowering Your Caching Period

The most effective step is to lower your Time to Live (TTL), ideally before you make the change. A short value, such as five minutes, means a new record is seen almost immediately rather than after several hours.

Lowering it in advance matters, because the older, longer Time to Live (TTL) has to expire before the shorter one takes full effect. Once your validation is complete, you are free to raise it again.

Correct Record Placement

The other common cause is the record being placed at the wrong level. A validation record can usually be accepted in one of two places : on the domain being secured, or on its root domain. The tracking system shows which options are accepted for your order, so you can confirm where the record belongs.

Some products expect the record on the exact domain being secured, while others also accept it on the root domain. Where both are accepted, adding the record in both places gives the fullest coverage and avoids a level being missed.

There is also a way to work around caching. If the Certificate Authority (CA) has cached an earlier answer for one level, adding the record at the other accepted level can help, because that level may not have been queried yet and is therefore not cached, so the new record can be detected sooner.

The tracking system is also where you review the exact records expected for your order, and where the validation method can be changed if a different one suits you better. Learn About The Tracking System 🔗

Validating Every Secured Domain

The SSL Certificate license you purchase can also affect how many records you place. Some licenses secure an additional domain name free of charge, added as a Subject Alternative Name (SAN), such as the root domain being included when you order the www version, and the www being included when you order the root domain.

Where a free Subject Alternative Name (SAN) is included, add a validation record for every domain name the license secures, not only the one named on your order. Each secured name is validated in its own right, so each needs its own record.

If the record for a free Subject Alternative Name (SAN) is missing, that name may not be issued alongside the one on your order. This is normal, because a missing record is taken as a sign that you do not want that name included.

Most Popular Questions

Frequently asked questions covering why validation can be delayed by Domain Name System (DNS) caching, how the Time to Live (TTL) controls how long an answer is cached, why the Certificate Authority (CA) must honor it, how to have new records picked up quickly, correct record placement, reviewing records in the tracking system, and why every secured domain needs its own validation record

Common Validation Delays

A delay usually comes from Domain Name System (DNS) caching. Your record carries a Time to Live (TTL) that controls how long an answer is cached, and the Certificate Authority (CA) continues to see the earlier state until that period passes. Placing the record at the wrong level is the other common cause.

Record Caching Period

A Time to Live (TTL) is the length of time a Domain Name System (DNS) answer may be cached and reused before a fresh lookup is made. If your Time to Live (TTL) is four hours, an answer can be trusted for up to four hours, which is how long the Certificate Authority (CA) may keep seeing an earlier result.

Honoring Your Caching Period

The Certificate Authority (CA) is required to honor your Time to Live (TTL) for security reasons. It is an instruction stating how long an answer may be trusted, and ignoring it to query again early would undermine the integrity of the Domain Name System (DNS) answers used to prove control of a domain.

Faster Record Updates

Lower your Time to Live (TTL) before you make the change, to a short value such as five minutes, so a new record is seen almost immediately. Adding the record on both the domain being secured and its root domain also helps, since a cached level can be bypassed by the one that is not cached.

Correct Record Placement

A validation record can usually be accepted on the domain being secured or on its root domain, and the tracking system shows which options apply to your order. Adding it in both places gives the fullest coverage, and if one level has already been cached, adding it at the other can be detected sooner.

Reviewing Your Records

The tracking system shows the exact records expected for your order, and which placement options are accepted. You can also change the validation method there if a different one suits you better.

Validating Included Domains

Some SSL Certificate licenses secure an additional domain name free of charge, added as a Subject Alternative Name (SAN), such as the root domain alongside the www. Add a validation record for every domain name the license secures, because a missing record is taken as a sign that you do not want that name, so the free one may not be issued.