# 200-Day SSL Certificates and DCV Reuse: What It Means for AutoSSL

Source: https://srvscripts.com/guides/ssl-200-day-dcv-reuse/
Updated: 2026-10-06
Publisher: srvScripts (https://srvscripts.com/)

**Short answer:** Since 15 March 2026, publicly trusted TLS certificates may last at most 200 days, and a CA may reuse a completed domain control validation (DCV) for at most 200 days. Both drop to 100 days on 15 March 2027, and on 15 March 2029 certificates drop to 47 days and DCV reuse to just 10 days. For AutoSSL and ACME users the lifetime change matters less than the DCV change: soon almost every renewal needs a fresh, successful HTTP or DNS validation, so broken DCV, DNSSEC errors, CAA records and geo-blocking firewalls now cause failed renewals.

Rules checked against the CA/Browser Forum TLS Baseline Requirements version 2.3.1 (dated 4 October 2026) on 6 October 2026. We read the AutoSSL and ACME renewal settings on our lab servers (AlmaLinux 9.8 with cPanel & WHM 11.138 and DirectAdmin 1.712) the same day. For the certificate-lifetime side in more depth, see our [47-day SSL certificate lifetime guide](/guides/47-day-ssl-certificate-lifetime/).

## The schedule

| Certificates issued on or after | Maximum certificate validity | Maximum DCV reuse (domain names and IPs) |
| --- | --- | --- |
| before 15 Mar 2026 | 398 days | 398 days |
| 15 Mar 2026 | 200 days | 200 days |
| 15 Mar 2027 | 100 days | 100 days |
| 15 Mar 2029 | 47 days | 10 days |

Identity information for OV and EV certificates (organization name, address and so on) can be reused for 398 days since 15 March 2026, down from 825 days. The Baseline Requirements also say certificates should not be issued for the full maximum by default, so a CA’s “200-day” product may be a day or two shorter.

These are maximums. CAs can and do use shorter periods. Let’s Encrypt issues 90-day certificates with 30-day authorization reuse today, moving to 64 days and 10-day reuse in February 2027 and to 45 days and 7 hours in February 2028.

## What “DCV reuse” means in practice

When you prove control of `example.com` (by an HTTP file, a DNS TXT record, an email link and so on), the CA records that validation. Within the reuse period it can issue more certificates for that name without asking you to prove control again. Today, a successful validation in April covers a renewal in September. From March 2029, a validation more than 10 days old is useless, so every renewal effectively includes a new validation.

For a hosting server with hundreds of domains, this changes what failure looks like. A domain whose validation broke months ago could still renew on an old authorization; that safety net is shrinking. Any DCV problem will show up at the next renewal.

## Validation methods that are being retired

The same set of ballots removes older validation methods. The ones hosting customers still meet:

| Method (BR section) | Typical use | Status |
| --- | --- | --- |
| Email to a constructed address: admin@, administrator@, webmaster@, hostmaster@, postmaster@ (3.2.2.4.4) | Approver email for paid DV/OV certificates | Should not be used from 15 Mar 2026; CAs must not rely on it from 15 Mar 2028 |
| Email to DNS CAA or DNS TXT contact (3.2.2.4.13, 3.2.2.4.14) | Email validation using an address published in DNS | Should not be used from 15 Mar 2026; must not from 15 Mar 2028 |
| Phone contact via DNS TXT or CAA (3.2.2.4.16, 3.2.2.4.17) | Phone validation | Should not be used from 15 Mar 2026; must not from 15 Mar 2027 |
| WHOIS-based email and phone (3.2.2.4.2, 3.2.2.4.15) | Old WHOIS approver emails | CAs must not rely on them since 15 Jul 2025 |
| IP address method (3.2.2.4.8) | Validating a domain by its IP | Not allowed since 15 Mar 2026 |

What stays: HTTP file validation (including ACME HTTP-01), DNS change validation (including ACME DNS-01), TLS-ALPN, and the new DNS TXT record with persistent value (3.2.2.4.22), which uses a long-lived `_validation-persist` record. Even with the persistent record, the Baseline Requirements cap reuse of that validation at 10 days; the benefit is that the DNS record does not need to change. If you still renew paid certificates by approver email, move those customers to HTTP or DNS validation before 2028.

## Other DCV rules that now cause failures

- **DNSSEC is validated.** Since 15 March 2026 CAs must perform DNSSEC validation on all DNS queries for domain validation and CAA, and a DNSSEC error such as SERVFAIL must not be treated as permission to issue. A domain with a broken DS record or expired signatures cannot get a certificate. Check with our [DNSSEC Checker](/tools/dnssec-checker/).

- **Multi-perspective validation.** Since 15 March 2025 CAs must confirm validation and CAA results from several network locations at least 500 km apart. A firewall that blocks whole countries or continents on port 80 (for example CSF country blocks) can make the remote checks fail even though validation from one location works.

- **CAA records are enforced** for each name. If `example.com` has a CAA record that allows only one CA, AutoSSL with a different CA fails. From 15 March 2027 CAs must also process the RFC 8657 `accounturi` and `validationmethods` CAA parameters. Check with our [CAA and TLSA Checker](/tools/caa-and-tlsa-checker/).

## Impact on cPanel AutoSSL

On our cPanel 11.138 lab, the Let’s Encrypt AutoSSL provider starts renewing when a certificate has 29 days left, and cPanel’s Sectigo provider at 15 days:

```
$ grep -n DAYS_TO_REPLACE /var/cpanel/perl/Cpanel/SSL/Auto/Provider/LetsEncrypt/Constants.pm /usr/local/cpanel/Cpanel/SSL/Auto/Provider/cPanel.pm
/var/cpanel/perl/Cpanel/SSL/Auto/Provider/LetsEncrypt/Constants.pm:27:    DAYS_TO_REPLACE => 29,
/usr/local/cpanel/Cpanel/SSL/Auto/Provider/cPanel.pm:33:    DAYS_TO_REPLACE => 15,
```

Both windows still fit inside a 47-day certificate. The weak point is DCV. Before the reuse period shrinks further:

- Open WHM **Manage AutoSSL** and fix every domain listed with DCV errors, or run our [AutoSSL DCV Failures Report](/scripts/autossl-failure-report/) across the server.

- Make sure `/.well-known/acme-challenge/` (Let’s Encrypt) and `/.well-known/pki-validation/` (Sectigo) are reachable over plain HTTP from anywhere, not redirected to another host, blocked by a WAF, or hidden behind a Cloudflare challenge.

- Remove CAA records that do not list the CA AutoSSL uses, and check the provider’s validity period on the Providers tab of Manage AutoSSL.

- Remove domains from certificates when their DNS has moved away. They fail DCV every time and fill the logs.

## Impact on DirectAdmin and other ACME clients

DirectAdmin 1.711 and later renew after a share of the certificate’s lifetime rather than a fixed number of days. On our 1.712 lab the setting was `acme_cert_lifetime_renew_threshold=0.65` with `acme_cert_lifetime_renew_jitter=0.1`, which DirectAdmin’s changelog describes as renewing after 65% of the lifetime plus up to 10% random jitter. That adapts automatically to 200-, 100- or 47-day certificates. Update older DirectAdmin builds to get it.

For Certbot, acme.sh and similar clients, use ARI if supported, or renew at about two thirds of the lifetime, as Let’s Encrypt recommends. Fixed schedules such as “renew 30 days before expiry” work for 90 days but not for 47.

## Paid certificates installed by hand

This is where the 200-day limit bites first. A certificate issued after 15 March 2026 cannot be valid for more than 200 days, so a one-year purchase now means at least two certificates. Each one needs a DCV within the reuse period and someone to install it. With 100-day certificates from 2027 that means three or four manual installs a year per site. Use the CA’s ACME support where it exists (DirectAdmin 1.711 and later can use paid ACME CAs through external account binding) so paid certificates renew like free ones.

## Check that it worked

- List certificates on the server with fewer than 30 days left and confirm each renews on the next AutoSSL or ACME run.

- From an outside network, request `http://example.com/.well-known/acme-challenge/test` and confirm you get a 404 from your server, not a redirect to another host or a firewall block page.

- Check DNSSEC and CAA for every domain on the server, not just the main one.

- Set alerts for certificates expiring within 14 days. Our [SSL Certificate Checker](/tools/ssl-certificate-checker/) shows a single host, and our [SSL Expiry Check script](/scripts/ssl-expiry-check/) covers many hosts from cron.

**Official documentation:** [CA/Browser Forum TLS Baseline Requirements](https://cabforum.org/working-groups/server/baseline-requirements/requirements/) · [Ballot SC-081v3: schedule of reducing validity and data reuse periods](https://cabforum.org/2025/04/11/ballot-sc081v3-introduce-schedule-of-reducing-validity-and-data-reuse-periods/) · [Let’s Encrypt: decreasing certificate lifetimes to 45 days](https://letsencrypt.org/2025/12/02/from-90-to-45) · [cPanel docs: Manage AutoSSL](https://docs.cpanel.net/whm/ssl-tls/manage-autossl/)

**Related:** [47-Day SSL Certificate Lifetime: Critical Automation for Hosts](/guides/47-day-ssl-certificate-lifetime/) · [AutoSSL Failed cPanel: Fix DCV, CAA and CDN Problems](/guides/autossl-failed-cpanel-dcv-caa-cdn/) · [DirectAdmin External Account Binding: Paid CA Setup in 1.711+](/guides/directadmin-external-account-binding-eab/) · [CAA and TLSA Checker: Free CAA Record and DANE Test](/tools/caa-and-tlsa-checker/) · [AutoSSL DCV Failures Report](/scripts/autossl-failure-report/)

**See also:** [ERR_CERT_COMMON_NAME_INVALID on cPanel: Wrong Certificate Served](/guides/cpanel-err-cert-common-name-invalid/) · [Let’s Encrypt Changes 2025 to 2028: What Hosting Admins Must Do](/guides/lets-encrypt-2026-changes/)

## Frequently asked questions

### What is the maximum SSL certificate validity in 2026?

200 days for certificates issued from 15 March 2026. It drops to 100 days on 15 March 2027 and to 47 days on 15 March 2029.

### What is DCV reuse?

The period during which a CA may reuse a completed domain control validation to issue new certificates without validating again. It is 200 days from March 2026, 100 days from March 2027 and 10 days from March 2029.

### Can I still validate a certificate by approver email?

For now, but the Baseline Requirements say email to admin@, webmaster@ and similar addresses should not be used since 15 March 2026, and CAs must stop relying on it on 15 March 2028.

### Does the 200-day limit affect Let’s Encrypt?

Not directly, because Let’s Encrypt certificates are already 90 days. Its own schedule shortens them to 64 days in 2027 and 45 days in 2028.

### Why do AutoSSL renewals fail more often now?

Shorter reuse periods mean renewals need fresh validation, and CAs now check DNSSEC and validate from several network locations. Broken DNSSEC, CAA records or geo-blocking firewalls stop issuance.

### Does this apply to BIMI mark certificates?

No. The CA/Browser Forum TLS Baseline Requirements cover publicly trusted TLS server certificates. Mark certificates for BIMI follow separate rules.
