How to Validate Your Domain by Uploading an HTTP File
· Guide
HTTP file-based validation is the third way to prove domain ownership, alongside DNS TXT and email. With this method, the Certificate Authority (CA) gives you a specific file, and you upload it to your web server so it's reachable at a public URL.
When Should You Choose This?
- You don't have access to your DNS panel (e.g., DNS is managed by a different team or agency).
- You have FTP, cPanel File Manager, or hosting panel access to your site.
- You don't have a role mailbox like admin@yourdomain.
Note: The HTTP method cannot be used for wildcard certificates (*.example.com) — wildcard certificates require the DNS TXT method, since validation must cover the entire domain rather than a single fixed URL.
Step 1 — View the File Details
After completing your order, the "Domain Validation Pending" card on Panel > My Certificates shows the exact file location (path + filename) and its required content, each with a copy button.
Step 2 — Upload the File to Your Server
Upload the file, with exactly the given content, to the specified location. It usually looks like this:
http://example.com/.well-known/pki-validation/ABCDEF123456.txt
- Using FTP/SFTP: connect and create the .well-known/pki-validation folder (if it doesn't exist) in your site's root directory (public_html, www, htdocs, etc.), then upload the file inside it.
- Using cPanel: use File Manager to create the same folder structure, add a "New File," and paste in the content.
- If you're using a hosting panel or CMS, check the setting for hiding dotfiles — some file managers hide folders starting with a dot (.) by default.
Step 3 — Verify It's Reachable
After uploading, visit the URL directly in your browser. Confirm the content matches exactly what the CA provided (no extra spaces or line breaks). If it's reachable, PekiSSL's automatic check will see the same result within a few minutes and activate your certificate.
Common Issues
- The .well-known folder may be blocked by your web server configuration (some Nginx/Apache rules block dot-prefixed folders by default) — temporarily remove any such rule.
- A CDN or firewall (WAF) may be blocking access to this path — purge the CDN cache or add the path to your exception list.
- The file content may have an accidental extra line break or space — we recommend using the copy button.
- Even if your site auto-redirects to HTTPS, the CA typically checks over HTTP (port 80) first; make sure your server doesn't fully reject HTTP requests.
Since the check runs automatically and continuously, there's nothing else to do once the file is in place — you'll get an email as soon as your certificate is ready.