寄送電子郵件至 DNS CAA 聯絡人地址
Email to DNS CAA Contact
Confirming the Applicant’s control over the ADN by sending a Random Value via email and then receiving a confirming response utilizing the Random Value. The Random Value MUST be sent to a DNS CAA Email Contact. The relevant CAA Resource Record Set MUST be found using the search algorithm defined in RFC 8659, Section 3.
藉由透過電子郵件寄送隨機值(Random Value),並接收使用該隨機值的確認回覆,以確認申請者(Applicant)對經授權網域名稱(Authorization Domain Name,ADN)的控管權。隨機值應(MUST)寄送至 DNS CAA 電子郵件聯絡人(DNS CAA Email Contact)的地址。相關的 CAA 資源紀錄集(Resource Record Set)應(MUST)使用 RFC 8659 第 3 節 定義的搜尋演算法尋找。
Each email MAY confirm control of multiple ADNs, provided that each email address is a DNS CAA Email Contact for each ADN being validated. The same email MAY be sent to multiple recipients, provided that each email address is a DNS CAA Email Contact for each ADN being validated.
每一封電子郵件得(MAY)確認多個經授權網域名稱(ADN)的控管權,前提是每個電子郵件地址皆為每一個待驗證之經授權網域名稱(ADN)的 DNS CAA 電子郵件聯絡人的地址。同一封電子郵件得(MAY)寄送至多個收件者,前提是每個電子郵件地址皆為每一個待驗證之經授權網域名稱(ADN)的 DNS CAA 電子郵件聯絡人的地址。
The Random Value SHALL be unique in each email. The email MAY be re-sent in its entirety, including the re-use of the Random Value, provided that its entire contents and recipient(s) SHALL remain unchanged. The Random Value SHALL remain valid for use in a confirming response for no more than 30 days from its creation. The CPS MAY specify a shorter validity period for Random Values.
隨機值在每封電子郵件中應(SHALL)是唯一的。電子郵件得(MAY)全文重寄,包括重複使用隨機值,前提是其全文內容及收件者應(SHALL)保持不變。隨機值自建立之日起,用於確認回覆的有效期限應(SHALL)不超過 30 日。憑證實務作業基準(Certification Practice Statement,CPS)得(MAY)規定更短的隨機值有效期限。
CAs performing validations using this method MUST implement Multi-Perspective Issuance Corroboration as specified in Section 3.2.2.9. To count as corroborating, a Network Perspective MUST observe the same selected contact address used for domain validation as the Primary Network Perspective.
使用此方法進行驗證的 CA 應(MUST)實施第 3.2.2.9 節所規範之多視角簽發佐證(Multi-Perspective Issuance Corroboration)。若要算作有效佐證,其他網路視角(Network Perspective)應(MUST)觀察到與主要網路視角(Primary Network Perspective)相同的網域驗證之聯絡人資訊。
Effective March 15, 2026, this method SHOULD NOT be used to issue Subscriber Certificates.
自 2026-03-15 起,此方法不宜(SHOULD NOT)用於簽發用戶憑證。
Effective March 15, 2028:
- The CA MUST NOT rely on this method.
- Prior validations using this method and validation data gathered according to this method MUST NOT be used to issue Subscriber Certificates.
自 2028-03-15 起:
- CA 不得(MUST NOT)依賴此方法。
- 先前使用此方法進行的驗證,以及依據此方法蒐集的驗證資料,不得(MUST NOT)用於簽發用戶憑證。