You can use (and I'd recommend) HTTP validation, which only needs the CNAME record to be in place. D

You can use (and I'd recommend) HTTP validation, which only needs the CNAME record to be in place. DNS validation, while recommended in the UI for some reason, needs manual intervention every time the cert has to be renewed, like you said
Was this page helpful?