Copyright 2026 © GeoCerts, Inc.
Celebrating our 23rd year!
2221 Peachtree Rd NE, Suite D236, Atlanta, GA 30309
Industry-wide Multi-Perspective Issuance Corroboration (MPIC) requirements affect SSL/TLS certificates issued by DigiCert (GeoTrust) and Sectigo (PositiveSSL).
The next phase of MPIC enforcement went into effect on February 24, 2026, and is now fully active.
What’s Changing?
As of February 24, 2026, DigiCert and Sectigo require:
If DNS or CAA results are inconsistent across locations, certificate issuance cannot proceed.
The new requirement only applies to new orders, renewals, and reissues processed on or after February 24, 2026. Certificates already issued are NOT affected.
For additional technical details on how DigiCert performs MPIC validation, see:
https://knowledge.digicert.com/solution/using-mpic-to-verify-domain-control
Sectigo has published similar guidance, including a helpful MPIC FAQ: https://www.sectigo.com/mpic-faq
Recommended: Verify Global DNS Propagation
Because domain validation now occurs from multiple global locations, it’s important that DNS changes are visible worldwide.
You can use a public DNS propagation checker such as: https://www.whatsmydns.net.This tool allows you to confirm that TXT, CNAME, CAA, and other DNS records are resolving from multiple locations.
Important for HTTP DCV Users
If you use the HTTP Practical Demonstration DCV method for domain validation, DigiCert has:
DigiCert DCV /1.1 and DigiCert DCV Bot/1.1 )Please review firewall or WAF allowlists to prevent validation failures.
What You Should Do
Most customers won’t need to take action. However, we recommend:
These updates strengthen protection against DNS manipulation and fraudulent issuance.
If you have questions or would like help reviewing your environment, GeoCerts is here to assist.
The GeoCerts Team
Copyright 2026 © GeoCerts, Inc.
Celebrating our 23rd year!
2221 Peachtree Rd NE, Suite D236, Atlanta, GA 30309