@techreport{ietf-acme-dns-persist-01, number = {draft-ietf-acme-dns-persist-01}, type = {Internet-Draft}, institution = {Internet Engineering Task Force}, publisher = {Internet Engineering Task Force}, note = {Work in Progress}, url = {https://datatracker.ietf.org/doc/draft-ietf-acme-dns-persist/01/}, author = {Shiloh Heurich and Henry Birge-Lee and Michael Slaughter}, title = {{Automated Certificate Management Environment (ACME) Challenge for Persistent DNS TXT Record Validation}}, pagetotal = 30, year = 2026, month = mar, day = 23, abstract = {This document specifies "dns-persist-01", a new validation method for the Automated Certificate Management Environment (ACME) protocol. This method allows a Certification Authority (CA) to verify control over a domain by confirming the presence of a persistent DNS TXT record containing CA and account identification information. This method is particularly suited for environments where traditional challenge methods are impractical, such as multi-tenant hosting platforms, enterprise DNS environments, and IoT deployments. The validation method is designed with a strong focus on security and robustness, incorporating widely adopted industry best practices for persistent domain control validation. This design aims to make it suitable for Certification Authorities operating under various policy environments, including those that align with the CA/Browser Forum Baseline Requirements.}, }