Domain validation fails with CNAME format error after SSL removal in AEM

In Adobe Experience Manager (AEM) Cloud Manager, domain validation fails after removing an SSL certificate and domain mappings when the system shows a CNAME format error, and domains remain Not Verified. The platform displays updated CNAME values after re-adding domains, but validation does not succeed until DNS records match the latest values. To resolve the issue, update DNS CNAME records to the latest values.

Description description

Environment

Adobe Experience Manager (AEM) Cloud Manager (all versions)

Issue/Symptoms

  • Domain validation fails after removing an SSL certificate and associated domain mappings.
  • The domain status displays as Not Verified in Domain Settings.
  • The system displays the following error during validation: Dns CNAME record must have the following format : < random-32> .cm-verify.adobe.com
  • Domains show incorrect or outdated CNAME values in Domain Settings.
  • Re-adding domains generates new CNAME values, but validation still fails.

Steps to Reproduce

  1. Access the Cloud Manager platform.
  2. Navigate to Domain Settings.
  3. Identify domains with the status Not Verified.
  4. Attempt to verify a domain.
  5. Observe the CNAME format error notification.

Cause

Incorrect or outdated DNS CNAME records prevented domain validation. Removing and re-adding domains generated new CNAME values, which must be reflected in DNS for successful verification.

Resolution resolution

Follow the steps below to address the issue:

  1. In Cloud Manager, review the CNAME values displayed for each domain in Domain Settings, and note the latest generated values.
  2. For each domain with the status Not Verified, update the DNS provider configuration to match the exact CNAME record format <random-32>.cm-verify.adobe.com.
  3. Wait for DNS propagation, which may take up to 24 hours depending on the provider.
  4. Retry the domain validation process in Cloud Manager and confirm that the status updates successfully.
  5. After successful verification, proceed to create SSL certificates and configure domain mappings as required.
recommendation-more-help
experience-cloud-kcs-help-kbarticles