Pending validation ☁️ AWS

ACM certificate stuck in Pending validation

ACM is waiting to see the DNS (or email) validation record — it wasn’t created, was created in the wrong DNS zone, or has a typo.

Seen on: AWS

Meaning

DNS validation needs the exact CNAME from ACM in the authoritative DNS for the domain. Common errors: adding the record in a Route 53 zone that isn’t the one the registrar uses, a DNS provider appending the domain twice, or CAA records forbidding Amazon. CloudFront certificates must be in us-east-1.

Common causes

  • CNAME not created or created in the wrong zone/provider
  • Domain appended twice (name.example.com.example.com)
  • CAA record blocks amazon.com
  • Certificate requested in the wrong region for CloudFront

⚡ Quick fix

  1. Copy the CNAME exactly into the authoritative DNS
  2. Check with dig CNAME _abc.example.com
  3. Request CloudFront certificates in us-east-1

Detailed fix by platform

Shell

  1. bash
    dig +short NS example.com
    dig +short CNAME _3f2a1c9d.example.com
    dig +short CAA example.com

How to diagnose

  1. Authoritative DNS — Which provider answers NS?
  2. Record — Resolves to the ACM value?
  3. Region — us-east-1 for CloudFront

🔧 Still not fixed?

Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:

🧠 Still stuck? Analyze your error

Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.