Skip to content

Changes to Domain Validation for SSL/TLS Certificates

To overview
News

Starting January 1, 2025, it will no longer be possible to use email addresses from the WHOIS database for domain validation when applying for SSL/TLS certificates. This change applies to all Certificate Authorities (CAs) and is already being implemented by Sectigo, one of the largest CAs.

Why is this method changing?

WHOIS-based domain validation was used for years to verify the rightful owner of a domain via email addresses in WHOIS records. However, due to stricter privacy regulations, such as the GDPR, and the use of anonymous WHOIS data, this method has become less effective. That is why CAs now offer more modern and secure alternatives, such as:

  • Validation via generic email addresses (such as admin@, webmaster@)
  • Validation via DNS records
  • Validation via specific files on the web server (HTTP/HTTPS)

What does this mean for your customers?

As a reseller using our fully white-label solutions, it’s important to stay informed about these changes so you can keep your customers well-informed. At OXXA.com, we support you throughout this process and ensure that you—and, by extension, your customers—can transition smoothly to the new validation methods.

How does SSL validation work from now on?

When renewing SSL certificates via the customer portal, we use admin@ email addresses by default for domain validation. Would you like to use a different email address? You can easily change this in the “pending orders” section of your reseller portal.

Support for You as a Reseller

We understand that changes can impact your business processes. That’s why our support team is ready to help you. Whether you have questions about the new validation methods or need assistance guiding your customers through the transition, you can count on us.

Do you have any questions? Feel free to contact us at 088-750 7070.

To overview