Updated on 2026-10-10 GMT+08:00

Manual DNS Verification

According to the CA requirements, if you applied for an SSL certificate, you must prove that the domain name to be associated with the certificate belongs to you.

For manual DNS verification, you add a record to the record set configured for the domain name for verification. If the CA verifies that the added record can be resolved, the verification is successful.

If you select manual DNS verification when applying for a certificate, perform the operations described in this section.

Applicable Certificate Types

  • DV certificate:
    • When you apply for a DV certificate, bind a single domain name and select manual DNS verification.
    • When you apply for a DV certificate, bind a name domain option other than a single domain name.

Notes and Constraints

Manual DNS verification can be performed only on your domain name management platform by following the instructions provided by the domain name service provider.

Prerequisites

You have completed real-name authentication.

Pre-Operation Confirmation

When you use DNS to verify your domain ownership, the DNS records can be resolved only on the platform managing your domain name. Determine the verification steps based on the domain name management platform.

Domain Name Management Platform

Verification Procedure

The domain name management platform is Huawei Cloud.

Perform all the subsequent steps. For details, see Step 1: Obtaining Verification Information, Step 2: Performing Verification Using Huawei Cloud DNS, Step 3: Checking Whether Domain Ownership Verification Takes Effect, and Step 4: Review the DNS Verification Result.

Platforms other than our platform

Are you sure you want to migrate the domain name from another service provider to Huawei Cloud DNS?
  • If your answer is "Yes", perform the following steps:
    1. Migrate the domain name from another DNS service provider to Huawei Cloud DNS.
    2. Complete all subsequent steps.
  • If your answer is "No", perform the verification on the corresponding platform. For example, if your domain is hosted on Alibaba Cloud, perform the verification on Alibaba Cloud.

Step 1: Obtaining Verification Information

  1. Log in to the CCM console.
  2. In the navigation pane on the left, choose SSL Certificate Manager > SSL Certificates. In the row containing the desired certificate, click Verify Domain Name in the Operation column. The Verify Domain Name page is displayed.
  3. On the Verify Domain Name page, view the content for Host Record, Record Type, and Record Value. Figure 1 shows an example.

    If Host Record, Record Type, and Record Value are not displayed, log in to the mailbox to view. The mailbox is the one you provide during certificate application.
    Figure 1 Viewing a host record


Step 2: Performing Verification Using Huawei Cloud DNS

  • If your domain names are not managed on Huawei Cloud, skip this step and manually add a CNAME or TXT record at your DNS provider to verify domain ownership.
  • If your domain names are managed on Huawei Cloud, you need to manually add a CNAME or TXT record on DNS to verify the domain name ownership.
  1. Log in to the CCM console.
  2. Click in the upper left corner of the page and choose Networking > Domain Name Service. In the navigation pane on the left, choose Public Zones to go to the Public Zones page.
  3. In the public zone list, click the domain name you want to add a record set for. In the upper left corner of the page, click Add Record Set.

    • Different types of record sets should be added for DNS verification of different domain name types.
      • For a single-domain certificate, if the domain name does not contain www, add a record set for the domain name. If the domain name contains www, add a record set for the corresponding higher level domain name. For example, if your certificate is used for domain name www.example.com, add a record set for example.com.
      • For a multi-domain certificate, add record sets for all domain names associated with the certificate.
      • For a wildcard-domain certificate, add a record set for the higher level domain name corresponding to the wildcard domain.

        For example, if your certificate is used for domain name *.example.com, add a record set for example.com.

    • If there is a DNS record of the corresponding type in the domain name list, click Modify in the Operation column. Modify the record in the displayed Modify Record Set dialog box.
      Figure 2 Adding a record set

      Table 1 Parameters for adding a record set

      Parameter

      Description

      Example Value

      Name

      Host record returned by the domain name service provider on the domain name verification page of the certificate.

      Note that host records returned by domain name service providers are different. Ensure that the host record is correct.

      • If the host record returned by the domain name service provider is _dnsauth.example.com, set Name to _dnsauth.
      • If the host record returned by the domain name service provider is example.com, leave the host record empty.

      Type

      Record type returned by the domain name service provider on the domain name verification page. The involved record types are TXT and CNAME. For details about the differences between the two types, see Table 2.

      TXT

      Alias

      Whether to associate the record set with a cloud resource.

      Unlike a CNAME record set, an alias supports second-level domain names.

      This function is disabled by default.

      The following record types support alias: A, MX, AAAA, TXT, SRV, and CAA.

      No

      Line

      Type of the line for resolution. The DNS server will return the IP address of the specified line, depending on where the visitor comes from.

      The default value is Default.

      • Default: Returns the default resolution result, regardless of the visitor's location or network.
      • ISP: Returns the resolution result based on visitors' carrier networks. For details, see Configuring ISP Lines for Record Sets.
      • Region: Returns the resolution result based on visitors' geographical locations. For details, see Configuring Region Lines.
      • Custom line: Returns a specific IP address based on the IP address range of visitors. For details, see Configuring Custom Lines.

      Default

      TTL (s)

      How long a local DNS server caches the DNS record. It is measured in seconds.

      Default value: 300

      Value range: 1 to 2147483647

      If your service address changes frequently, set TTL to a smaller value. Otherwise, set TTL to a larger value.

      5 min

      Value

      Record value returned by the domain name service provider on the domain name verification page of the certificate. Record values must be quoted with quotation marks and then pasted in the text box.

      The domain name returned for DNS resolution, which is usually another domain name that maps the target IP address.

      You can enter a maximum of 50 unique addresses, each on a separate line.

      www.example.com

      Retain other settings.

      Table 2 Comparison between TXT and CNAME record types

      Item

      TXT

      CNAME

      Application Scenario

      Digital authentication certificate, SPF records for anti-spam protection, and domain ownership verification

      Digital authentication certificates, website resolution, CDN, enterprise mailbox, enterprise portal, web application firewall, object storage, and live streaming.

      How it works

      The verification code is published so that the verification information can be submitted to the CA server for validation. That is, the CA directly queries and verifies the information.

      A DNS alias record is added to temporarily grant the domain ownership verification permission to the background system of the CA. That is, the verification permission is granted to the CA.

      Verification validity

      One-time configuration. Verification is valid for a single use and must be reconfigured for subsequent attempts.

      One-time configuration, permanently valid.

      Applicable brand

      GlobalSign, vTrus

      DigiCert, GeoTrust, CFCA

  4. Click OK.

    If the status of the record set is Normal, the record set is added successfully.

    The time it takes for the DNS record set to take effect depends on the Time to Live (TTL) of the record set on the local DNS server. A lower TTL allows changes to apply faster, but it shortens the DNS cache duration, which may affect the domain name resolution speed. For details about how to check whether the domain name verification takes effect, see Step 3: Checking Whether Domain Ownership Verification Takes Effect.

    • Before the certificate is issued, do not delete the DNS record set.
    • After the certificate is issued, you are advised to delete the DNS resolution record to prevent conflicts with future records. Deleting the DNS resolution record does not affect the services of the issued certificate.

Step 3: Checking Whether Domain Ownership Verification Takes Effect

  1. On the Windows menu, click Start and enter cmd to start the command dialog box.
  2. Check whether the DNS configuration takes effect by running the corresponding command listed in Table 3.

    Table 3 Verification commands

    Type

    Verification Commands

    TXT

    nslookup -q=TXT xxx

    CNAME

    nslookup -q=CNAME xxx

    xxx indicates the Host Record value returned by the domain name service provider.

    • If the record value in the command output (value of text) is the same as that returned by the domain name service provider, the configuration of domain name ownership verification has taken effect. Figure 3 shows an example.
      Figure 3 Effective configuration of domain name ownership verification
    • If the command output does not contain any records and Non-existent domain is displayed, the configuration does not take effect.
      Figure 4 Non-effective domain name verification configuration

  3. If the configuration of DNS verification does not take effect, rectify the fault based on the following possible causes until the verification takes effect:

    Table 4 Troubleshooting

    Probable Cause

    Procedure

    A wrong domain name management platform was selected.

    DNS verification can be performed only on the platform where your domain name is hosted. Check whether the platform you select is the right one.

    The old record set is not deleted.

    The record added can be deleted once the current certificate is issued. If the record added for the previous certificate is not deleted, the record added for the current certificate will not take effect. Check whether the record added last time is deleted.

    NOTE:

    Do not delete the added domain name resolution records before the certificate is issued. Otherwise, the certificate will fail to be issued.

    The record configuration is incorrect.

    Check settings of Host Record, Type or Value.

    Figure 5 Adding a record

    It requires a long period of time for the configuration to take effect.

    Check whether the effective time (TTL) is too long. It is recommended that you set the TTL to 5 minutes. This value varies depending on the DNS service provider. In Huawei Cloud DNS, the default value is 5 minutes, so the configuration takes effect in 5 minutes by default.

    If the configured effective time does not arrive, verify after the time is right.

    Figure 6 Setting TTL

Step 4: Review the DNS Verification Result

  • OV and EV certificates

    After you complete the verification, it still takes 2 to 3 working days for the CA to validate your DNS verification. The CA will not issue the certificate until they validate your DNS verification.

    If the verification fails or other problems occur, contact the CA using the information provided in the CA's validation email. If you need to reconfigure the email address, see Withdrawing an SSL Certificate Application. To check whether your application is withdrawn, check the status or application progress of the SSL certificate on the SSL Certificates tab in CCM.

  • DV certificates
    You can manually verify the result on the domain name verification page.
    1. Log in to the CCM console.
    2. In the navigation pane on the left, choose SSL Certificate Manager. In the row containing the desired certificate, click Verify Domain Name in the Operation column. The Verify Domain Name page is displayed.
    3. Click Verify to verify the DNS resolution configuration.
      • If the system displays "Verification succeeded. Your certificate is on the way.", the certificate will be issued within 1 minute. Refresh the page to view the certificate status then.
      • If the verification fails, fix issues by referring to Why Did the DNS Verification for a DV Certificate Fail? Then, perform the verification again 3 to 5 minutes later.

Why Did the DNS Verification for a DV Certificate Fail?

Failure Message

Solution

Too many verification requests. Try again later.

You may submit too many verification requests in a short time. Wait for 3 to 5 minutes and then perform the verification.

When you click the domain name verification button, if an error message is displayed on the console, indicating that the certificate type or status does not support this operation and that you can troubleshoot the fault based on the error code, check whether the certificate has been issued on the CCM console. If it has, you do not need to click the verification button on the DNS verification page.

DNS records do not match.

The DNS record value is incorrect. Obtain the correct record value by referring to Step 1: Obtaining Verification Information and reconfigure the DNS record value.

DNS verification failed. Try again later.

Check whether the following problems exist:

  • Problem 1: The DNS record does not take effect.

    Solution: The configured DNS record does not take effect immediately, which depends on the TTL time set on your DNS server. So, wait for 3 to 5 minutes and then perform the verification again.

  • Problem 2: DNS records are correctly configured, but the verification still fails.

    Solution: The CA verification server is located outside China. There might be network errors sometimes. Try again about 1 to 2 hours later.

  • Problem 3: The domain name has not been licensed or passed the real-name authentication.

    Solution: Have the domain name licensed and complete real-name authentication first. Then, verify the domain name ownership again.

  • Problem 4: The domain name has a CAA record set.

    Solution: Delete all CAA records from the domain name resolution record sets.

  • Problem 5: The CA verification server does not find the DNS resolution record.

    Solution: The CA verification server is located outside China. So, you need to allow servers outside China to access the domain name temporarily.