When you request a certificate from Let’s Encrypt, our servers validate that you control the hostnames in that certificate using ACME challenges . For subscribers who need wildcard certificates or who prefer not to expose infrastructure to the public Internet, the DNS-01 challenge type has long been the only choice. DNS-01 works well.
DNS-PERSIST-01: A New Model for DNS-based Challenge Validation
calendar_today
February 18, 2026
domain
lets-encrypt