How to Validate Your Domain by Email

· Guide

Email validation (email DCV) is one of three methods available when purchasing a certificate for a domain. The logic is simple: the Certificate Authority (CA) sends a confirmation email to a specific address on that domain, and you prove ownership by clicking the link inside it.

Which Addresses Are Accepted?

This is where most confusion happens: under the CA/Browser Forum's Baseline Requirements (the shared rulebook followed by browsers and certificate authorities), email validation cannot be done with a personal or arbitrary address. Only one of the following five "role addresses" is accepted, on the domain you're validating (or its base domain):

For example, if you're getting a certificate for shop.example.com, both [email protected] and [email protected] (the base domain) are accepted. But an address like [email protected] or [email protected] — no matter how real or legitimately yours — is not accepted. This is a security rule every CA must follow to make sure the certificate is actually being requested by the domain's owner.

When you choose the email method at PekiSSL checkout, we automatically list the valid addresses for the domain you entered — no guessing required.

What If You Don't Have a Dedicated admin@ Mailbox?

Most small businesses don't keep a dedicated "admin@" mailbox on their domain — they use a general address like Gmail or Outlook instead. You have two options:

1. Create the role address: In your email provider (Google Workspace, Microsoft 365, cPanel Email, etc.), you can add [email protected] as an alias to your existing mailbox — this routes incoming mail to your current inbox without opening a separate one. Setup usually takes just a few minutes.
2. Choose a different method: If you'd rather not set up a mailbox, pick DNS TXT or HTTP File at checkout — neither requires any mailbox at all.

Step-by-Step Process

1. On the PekiSSL checkout page, select Email under "Domain Validation Method."
2. The system lists the five valid addresses for the domain you entered.
3. After your order, the CA sends a confirmation email to the listed address(es) — this can take a few minutes; check your spam folder too.
4. Click the confirmation link in the email.
5. Your certificate activates automatically, and you'll receive a separate "certificate ready" email.

Common Issues

In short, email is fast and familiar, but if you don't have a suitable role address, DNS TXT or HTTP File are often a lower-friction alternative.

All blog posts