Domain-validated certificate


A domain validated certificate is an X.509 digital certificate typically used for Transport Layer Security where the domain name of the applicant is validated by proving some control over a DNS domain.
Domain validated certificates were first distributed by GeoTrust in 2002 before becoming a widely accepted method.

Issuing criteria

The sole criterion for a domain validated certificate is proof of control over whois records, DNS records file, email or web hosting account of a domain. Typically control over a domain is determined using one of the following:
A domain validated certificate is distinct from an Extended Validation Certificate in that this is the only requirement for issuing the certificate. In particular, domain validated certificates do not assure that any particular legal entity is connected to the certificate, even if the domain name may imply a particular legal entity controls the domain.

User interface

Most web browsers may show a lock and a DNS domain name. A legal entity is never displayed, as domain validated certificates do not include a legal entity in their subject.
As the low assurance requirements allow domain validated certificates to be issued quickly without requiring human intervention, domain validated certificates have a number of unique characteristics: