ACM certificate stuck in Pending validation
ACM is waiting to see the DNS (or email) validation record — it wasn’t created, was created in the wrong DNS zone, or has a typo.
Meaning
DNS validation needs the exact CNAME from ACM in the authoritative DNS for the domain. Common errors: adding the record in a Route 53 zone that isn’t the one the registrar uses, a DNS provider appending the domain twice, or CAA records forbidding Amazon. CloudFront certificates must be in us-east-1.
Common causes
- CNAME not created or created in the wrong zone/provider
- Domain appended twice (name.example.com.example.com)
- CAA record blocks amazon.com
- Certificate requested in the wrong region for CloudFront
⚡ Quick fix
- Copy the CNAME exactly into the authoritative DNS
- Check with dig CNAME _abc.example.com
- Request CloudFront certificates in us-east-1
Detailed fix by platform
Shell
- bash
dig +short NS example.com dig +short CNAME _3f2a1c9d.example.com dig +short CAA example.com
How to diagnose
- Authoritative DNS — Which provider answers NS?
- Record — Resolves to the ACM value?
- Region — us-east-1 for CloudFront
🔧 Still not fixed?
Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:
Similar errors
Most viewed in AWS
Other ways to find it
🧠 Still stuck? Analyze your error
Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.
Report a correction or suggest an improvement
Last updated 8 Oct 2026