- ACM now allows existing public TLS certificates to switch from email to DNS validation without reissuance, preserving the original ARN.
- Facilitates migration ahead of the CA/B Forum’s email‑validation deprecation scheduled for 2027, enabling fully automated DNS‑validated renewals.
- Switch via the ACM console or UpdateCertificateOptions API; ACM supplies DNS CNAME records and status can be tracked via the console or ListCertificateDomainValidations API.