How to Validate Your Domain by Email
· Guide
Email validation (email DCV) is one of three methods available when purchasing a certificate for a domain. The logic is simple: the Certificate Authority (CA) sends a confirmation email to a specific address on that domain, and you prove ownership by clicking the link inside it.
Which Addresses Are Accepted?
This is where most confusion happens: under the CA/Browser Forum's Baseline Requirements (the shared rulebook followed by browsers and certificate authorities), email validation cannot be done with a personal or arbitrary address. Only one of the following five "role addresses" is accepted, on the domain you're validating (or its base domain):
For example, if you're getting a certificate for shop.example.com, both [email protected] and [email protected] (the base domain) are accepted. But an address like [email protected] or [email protected] — no matter how real or legitimately yours — is not accepted. This is a security rule every CA must follow to make sure the certificate is actually being requested by the domain's owner.
When you choose the email method at PekiSSL checkout, we automatically list the valid addresses for the domain you entered — no guessing required.
What If You Don't Have a Dedicated admin@ Mailbox?
Most small businesses don't keep a dedicated "admin@" mailbox on their domain — they use a general address like Gmail or Outlook instead. You have two options:
1. Create the role address: In your email provider (Google Workspace, Microsoft 365, cPanel Email, etc.), you can add [email protected] as an alias to your existing mailbox — this routes incoming mail to your current inbox without opening a separate one. Setup usually takes just a few minutes.
2. Choose a different method: If you'd rather not set up a mailbox, pick DNS TXT or HTTP File at checkout — neither requires any mailbox at all.
Step-by-Step Process
1. On the PekiSSL checkout page, select Email under "Domain Validation Method."
2. The system lists the five valid addresses for the domain you entered.
3. After your order, the CA sends a confirmation email to the listed address(es) — this can take a few minutes; check your spam folder too.
4. Click the confirmation link in the email.
5. Your certificate activates automatically, and you'll receive a separate "certificate ready" email.
Common Issues
- The email may have landed in spam/junk — the sender is usually the official address of the CA (Sectigo, DigiCert, etc.).
- If the address you enter isn't one of the five role addresses, PekiSSL warns you before you can complete the order.
- If you just created the role alias, propagation can take a few minutes — wait and check again if it doesn't arrive immediately.
In short, email is fast and familiar, but if you don't have a suitable role address, DNS TXT or HTTP File are often a lower-friction alternative.