{"id":18210,"date":"2025-01-06T09:57:23","date_gmt":"2025-01-06T14:57:23","guid":{"rendered":"https:\/\/www.thesslstore.com\/blog\/?p=18210"},"modified":"2025-09-10T12:33:01","modified_gmt":"2025-09-10T16:33:01","slug":"whois-domain-control-validation-will-phase-out-starting-jan-8","status":"publish","type":"post","link":"https:\/\/www.thesslstore.com\/blog\/whois-domain-control-validation-will-phase-out-starting-jan-8\/","title":{"rendered":"WHOIS Domain Control Validation Will Phase Out Starting Jan. 8"},"content":{"rendered":"\n<h2 class=\"wp-block-heading\" id=\"h-if-you-ve-used-whois-based-validation-for-your-ssl-tls-certificates-it-s-time-to-change-to-another-validation-method-asap\">If you\u2019ve used WHOIS-based validation for your SSL\/TLS certificates, it\u2019s time to change to another validation method ASAP<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Changes are coming down the pike regarding WHOIS-based domain validation in the first half of 2025.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In August 2024, researchers at <a href=\"https:\/\/labs.watchtowr.com\/we-spent-20-to-achieve-rce-and-accidentally-became-the-admins-of-mobi\/\">WatchTowr Labs discovered a vulnerability<\/a> relating to use of legacy WHOIS systems for domain control validation (DCV) that industry leaders were concerned could lead to fraudulent email-based validations for <a href=\"https:\/\/www.thesslstore.com\/products\/ssl.aspx\">SSL\/TLS certificates<\/a>. Although the scope of the specific vulnerability was limited, it brought up questions about the industry\u2019s reliance on certain legacy resources for validation.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">On Dec. 14, the CA\/Browser Forum (CA\/B Forum) adopted a <a href=\"https:\/\/cabforum.org\/2024\/11\/14\/ballot-sc-80v3-sunset-the-use-of-whois-to-identify-domain-contacts-and-relying-dcv-methods\/#voting-results\">phased sunset for WHOIS-based methods of domain ownership valida<\/a><a href=\"https:\/\/github.com\/cabforum\/servercert\/pull\/549\">tion<\/a> after <a href=\"https:\/\/lists.cabforum.org\/pipermail\/servercert-wg\/\">s<\/a><a href=\"https:\/\/lists.cabforum.org\/pipermail\/servercert-wg\/2024-September\/004825.html\">everal months of discussion<\/a>. But what do these changes mean to you as a domain owner and to the certification authorities (CAs) you rely on?<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Let\u2019s hash it out.<span id=\"newline\"><\/span><\/p>\n\n\n<span style=\"--tl-form-height-m:150.25px;--tl-form-height-t:121.4583px;--tl-form-height-d:121.4583px;\" class=\"tl-placeholder-f-type-shortcode_12753 tl-preload-form\"><span><\/span><\/span>\n\n\n<h2 class=\"wp-block-heading\" id=\"h-an-overview-of-what-s-happening-amp-a-whois-dcv-end-of-life-timeline\">An Overview of What\u2019s Happening &amp; a WHOIS DCV End-of-Life Timeline<\/h2>\n\n\n\n<div class=\"wp-block-advanced-gutenberg-blocks-notice is-variation-info has-icon\" data-type=\"info\"><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"24\" height=\"24\" viewBox=\"0 0 24 24\" fill=\"none\" stroke=\"currentColor\" stroke-width=\"2\" stroke-linecap=\"round\" stroke-linejoin=\"round\"><circle cx=\"12\" cy=\"12\" r=\"10\"><\/circle><line x1=\"12\" y1=\"16\" x2=\"12\" y2=\"12\"><\/line><line x1=\"12\" y1=\"8\" x2=\"12\" y2=\"8\"><\/line><\/svg><p class=\"wp-block-advanced-gutenberg-blocks-notice__title\">Updated Deadline-Related Information from Sectigo<\/p><p class=\"wp-block-advanced-gutenberg-blocks-notice__content\"><strong>Editor\u2019s Note:<\/strong> This article has been updated on Jan. 8, 2025 to include updated information received via email from Sectigo about its phased rollout.<\/p><\/div>\n\n\n\n<p class=\"wp-block-paragraph\">Industry leaders will begin a phased elimination of WHOIS-based DCV methods. As a result, the <a href=\"https:\/\/datatracker.ietf.org\/doc\/html\/rfc3912\">WHOIS protocol<\/a> or HTTPS server query data will no longer be used as a way to 1) identify domain contacts, or 2) verify an entity\u2019s control over a domain.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-phase-one-jan-15-2025\">Phase One: Jan. 15, 2025<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Basically, CAs will be prohibited from relying on domain contact info gathered through manual or automated WHOIS lookup methods. The sunsetting will affect three <a href=\"https:\/\/cabforum.org\/working-groups\/server\/baseline-requirements\/documents\/\">SSL\/TLS security baseline requirements<\/a>: 3.2.2.4.2 (\u201cEmail, Fax, SMS, or Postal Mail to Domain Contact\u201d), 3.2.2.4.12 (\u201cValidating Applicant as a Domain Contact\u201d), and 3.2.2.4.15 (\u201cPhone Contact with Domain Contact\u201d).<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-phase-two-july-15-2025\">Phase Two: July 15, 2025<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">This is the date by which publicly trusted CAs MUST NOT rely on any WHOIS-related domain validation methods to issue new leaf certificates or allow prior authorization reuse (even during a valid reuse period). In particular, this phase affects SSL\/TLS BRs 3.2.2.4.2 and 3.2.2.4.15.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>But wait, why does the article title say Jan. 8 if the first phase of the baseline requirement changes doesn\u2019t begin until Jan. 15?<\/strong> It\u2019s because some CAs are rolling out the changes ahead of the deadline to avoid any last-minute issues during implementation that could result in revocation.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-major-cas-are-implementing-these-changes-ahead-of-the-deadlines\">Major CAs Are Implementing These Changes Ahead of the Deadlines<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/knowledge.digicert.com\/alerts\/end-of-life-for-whois-based-email-dcv-method\">DigiCert<\/a> and <a href=\"https:\/\/sectigo.status.io\/\">Sectigo<\/a> announced that customers using WHOIS-based DCV methods should migrate to alternative methods ASAP. Here\u2019s an overview of the company\u2019s phased rollout deadlines:<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><tbody><tr><td>&nbsp;<\/td><td><strong>Sectigo<\/strong><\/td><td><strong>DigiCert<\/strong><\/td><\/tr><tr><td>Phase One<\/td><td><strong>Jan. 15, 2025<\/strong> \u2014 Sectigo\u2019s first phase of the rollout will involve prohibiting the use of WHOIS-based email validation for <em>.nl<\/em> top-level domains.<\/td><td><strong>Jan. 8, 2025<\/strong> \u2014 DigiCert will stop supporting manual and HTTPS web-based WHOIS lookups for domain validations and prior use authorizations based on these methods.<\/td><\/tr><tr><td>Phase Two<\/td><td><strong>June 15, 2025<\/strong> \u2014 Sectigo will no longer support WHOIS-based email DCV and will invalidate any pre-existing DCV records. This means no certificates can be issued or re-issued using these unsupported WHOIS-based DCV methods.<\/td><td><strong>May 8, 2025<\/strong> \u2014 DigiCert will no longer accept automated WHOIS-based domain validations\/IANA referrals for new domain validations. It will, however, still accept WHOIS protocol-based DCVs.<\/td><\/tr><tr><td>Phase Three<\/td><td>&nbsp;<\/td><td><strong>July 2025<\/strong> \u2014 DigiCert will no longer allow the reuse of existing WHOIS-based domain validations of any kind, regardless of the time left in a reuse period.<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Here&#8217;s a quick timeline graphic that shows the rollout of these changes:<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"453\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2025\/01\/whois-dcv-discontinuation-timeline-updated-1024x453.png\" alt=\"Timeline illustration that shows the CA\/B Forum's changes to the WHOIS domain control validation (DCV) process and the phased rollouts by DigiCert and Sectigo\" class=\"wp-image-18220\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2025\/01\/whois-dcv-discontinuation-timeline-updated-1024x453.png 1024w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2025\/01\/whois-dcv-discontinuation-timeline-updated-300x133.png 300w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2025\/01\/whois-dcv-discontinuation-timeline-updated-768x340.png 768w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2025\/01\/whois-dcv-discontinuation-timeline-updated-1536x679.png 1536w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2025\/01\/whois-dcv-discontinuation-timeline-updated.png 1770w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\"><em>Image caption: A timeline that illustrates the rollout of phased changes to the WHOIS domain control validation methods over the next 6 months.<\/em><\/figcaption><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">For more information about Sectigo&#8217;s changes and timeline, keep an eye on <a href=\"https:\/\/www.sectigo.com\/whois-email-dcv-deprecation\">Sectigo&#8217;s WHOIS Email DCV Deprecation page<\/a> for updates.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-what-does-all-of-this-mean-for-your-organization\">What Does All of This Mean for Your Organization?<\/h2>\n\n\n\n<p class=\"has-central-palette-5-background-color has-background wp-block-paragraph\"><strong>NOTE:<\/strong> This issue only impacts companies who used WHOIS contact data to get their SSL\/TLS certificates issued.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This change will have little to no impact for the overwhelming majority of our customers.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-if-you-don-t-use-whois-data-for-domain-control-validation\">If You Don\u2019t Use WHOIS Data for Domain Control Validation<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">If a method other than WHOIS web-based lookups was used to validate your domain\u2014 for example, DNS TXT records, file validation, or constructed email (e.g., administrator@domain.com) verification \u2014 then this has no impact on you or your certificates. You\u2019re right as rain and you don\u2019t have to worry about any of these changes.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-if-you-did-use-whois-data-for-your-domain-control-validation-process\">If You Did Use WHOIS Data for Your Domain Control Validation Process<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">If you used WHOIS-listed email address to validate your domain when getting a <a href=\"https:\/\/www.thesslstore.com\/blog\/what-is-a-website-security-certificate-and-what-does-it-do-for-your-business\/\">website security certificate<\/a>, you\u2019ll need to change validation methods when requesting a new SSL\/TLS certificate. This is true even for customers who are within the allowed prior authorization reuse period.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The easiest method for most customers will be to use one of the \u201cconstructed\u201d or pre-approved validation email addresses:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>admin@yourdomain.com<\/li>\n\n\n\n<li>administrator@yourdomain.com<\/li>\n\n\n\n<li>webmaster@yourdomain.com<\/li>\n\n\n\n<li>hostmaster@yourdomain.com<\/li>\n\n\n\n<li>postmaster@yourdomain.com<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Alternative methods of domain control validation include file and <a href=\"https:\/\/www.thesslstore.com\/knowledgebase\/ssl-validation\/how-to-complete-txt-record-verification\/\">DNS-based validation methods<\/a>:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/www.digicert.com\/kb\/ssl-support\/validation\/dns-txt-dcv-method.htm\">DNS TXT records<\/a><\/li>\n\n\n\n<li>DNS CNAME (canonical name) records that link an alias to one or more other domains<\/li>\n\n\n\n<li>HTTP file authentication<\/li>\n<\/ul>\n\n\n\n<div class=\"wp-block-advanced-gutenberg-blocks-notice is-variation-info has-icon\" data-type=\"info\"><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"24\" height=\"24\" viewBox=\"0 0 24 24\" fill=\"none\" stroke=\"currentColor\" stroke-width=\"2\" stroke-linecap=\"round\" stroke-linejoin=\"round\"><circle cx=\"12\" cy=\"12\" r=\"10\"><\/circle><line x1=\"12\" y1=\"16\" x2=\"12\" y2=\"12\"><\/line><line x1=\"12\" y1=\"8\" x2=\"12\" y2=\"8\"><\/line><\/svg><p class=\"wp-block-advanced-gutenberg-blocks-notice__title\">Learn About Multi-Perspective Issuance Corroboration (MPIC)<\/p><p class=\"wp-block-advanced-gutenberg-blocks-notice__content\">Learn about the role of <a href=\"https:\/\/www.thesslstore.com\/blog\/multi-perspective-issuance-corroboration-mpic\/\">MPIC for website and email domain validation<\/a>, which adds another layer of authenticity by relying on multiple remote network perspectives.<\/p><\/div>\n\n\n<span style=\"--tl-form-height-m:801.312px;--tl-form-height-t:638.344px;--tl-form-height-d:638.344px;\" class=\"tl-placeholder-f-type-shortcode_12763 tl-preload-form\"><span><\/span><\/span>\n\n\n<h2 class=\"wp-block-heading\" id=\"h-background-what-led-to-these-industry-dcv-changes\">Background: What Led to These Industry DCV Changes<\/h2>\n\n\n\n<div class=\"wp-block-advanced-gutenberg-blocks-notice is-variation-info has-icon\" data-type=\"info\"><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"24\" height=\"24\" viewBox=\"0 0 24 24\" fill=\"none\" stroke=\"currentColor\" stroke-width=\"2\" stroke-linecap=\"round\" stroke-linejoin=\"round\"><circle cx=\"12\" cy=\"12\" r=\"10\"><\/circle><line x1=\"12\" y1=\"16\" x2=\"12\" y2=\"12\"><\/line><line x1=\"12\" y1=\"8\" x2=\"12\" y2=\"8\"><\/line><\/svg><p class=\"wp-block-advanced-gutenberg-blocks-notice__title\">TL;DR: An Overview of the Issue and Why Changes Were Deemed Necessary<\/p><p class=\"wp-block-advanced-gutenberg-blocks-notice__content\">WatchTowr Labs researchers discovered WHOIS systems using hardcoded legacy servers that allowed attackers to insert themselves as admin contacts for targeted domains. Thankfully, the WHOIS issue isn\u2019t thought to be a widespread problem.<\/p><\/div>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/labs.watchtowr.com\/we-spent-20-to-achieve-rce-and-accidentally-became-the-admins-of-mobi\/\">WatchTowr Labs researchers<\/a> discovered that specific WHOIS systems relied on hardcoded server addresses, some of which were decommissioned (legacy) domains. Unfortunately, these systems were pointing to legacy domains that were up for sale. This gave whoever bought the domains (in the case, the WatchTowr Labs researchers) the ability to insert fraudulent email contact information in WHOIS server responses for domains requesting SSL\/TLS certificates.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In this case, researchers bought the decommissioned domain <em>dotmobiregistry.net<\/em> (<em>whois.dotmobiregistry.net<\/em>), which should have been (but wasn\u2019t) once a new server (<em>whois.nic.mobi<\/em>) was instituted. As such, the vulnerability would impact all domains with the .mobi top level domain (TLD), giving bad guys the ability to issue fraudulent website security certificates.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-how-widespread-is-the-issue\">How Widespread Is the Issue?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Because WHOIS failed to renew the legacy domain <em>dotmobiregistry.net<\/em>, WatchTowr Labs researchers were able to take control and found the server was communicating with 135,000+ unique systems and received 2.5+ million WHOIS queries over a six-day observation period. That\u2019s nearly 420,000 queries per day to the exploitable legacy system.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">However, it\u2019s important to recognize in this situation that <em>not all WHOIS validations are innately flawed<\/em>. Although WatchTowr researchers said the issues impact WHOIS queries, which historically have been sent by mail servers, several major domain registrars, and some CAs, the \u201conly\u201d affected domains were those with .mobi TLDs.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The key takeaway of the situation is that it brought to light the concern of relying on legacy WHOIS validation methods and outdated resources. <strong>It\u2019s for this reason, and because WHOIS-based DCV methods typically are no longer used by most organizations, that industry leaders want to nip the issue in the bud once and for all and eliminate risks associated with these validation methods.<\/strong><\/p>\n","protected":false},"excerpt":{"rendered":"<p>If you\u2019ve used WHOIS-based validation for your SSL\/TLS certificates, it\u2019s time to change to another validation method ASAP Changes are coming down the pike regarding WHOIS-based domain validation in the&#8230;<\/p>\n","protected":false},"author":17,"featured_media":18212,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":"","tve_updated_post":"","tve_custom_css":"","tve_user_custom_css":"","tve_globals":{},"tcb2_ready":0,"tcb_editor_enabled":0,"tve_landing_page":"","_tve_header":"","_tve_footer":""},"categories":[13107,17,10200],"tags":[13311,13310],"class_list":["post-18210","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-beyond-hashed-out","category-industry-lowdown","category-monthly-digest","tag-domain-control-validation","tag-whois-dcv","post-with-tags"],"views":5880,"jetpack_featured_media_url":"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2025\/01\/whois-dcv-feature2.jpg","_links":{"self":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts\/18210","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/users\/17"}],"replies":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/comments?post=18210"}],"version-history":[{"count":0,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts\/18210\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/media\/18212"}],"wp:attachment":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/media?parent=18210"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/categories?post=18210"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/tags?post=18210"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}