hamburger icon
  • language
back icon Back
Choose your language
Content Type

Knowledge Base

DigiCert Using MPIC to Verify Domain Control and Perform CAA Checks

Solution ID : SO499
Last Modified : 09/23/2026
Important: This is a dynamic article. We will update it as more information becomes available. Save this page and check back periodically for the latest information.
On August 17, 2026, DigiCert added a new MPIC agent IP address: 13.232.96.181. If you use allowlists, regional restrictions, or DNS query limits, review the Update your allowlists section below.



What's changing

Between October 19 and November 30, 2026: DigiCert will increase the remote MPIC agents per domain query up to six unique agents (currently four unique agents).

December 1, 2026:
DigiCert will enforce the next phase of the CA/Browser Forum MPIC requirements and settle on six remote network perspectives across at least two Regional Internet Registry (RIR) regions. The enforcement will happen in advance of the December 15, 2026, deadline. See Corroboration requirements per the CA/Browser Forum below.
 

Impact

MPIC verifies domain control and performs CAA checks from multiple remote network locations. Domain validation or certificate issuance may fail if:

  • DNS responses used for domain validation are inconsistent across authoritative nameservers.
  • HTTP validation results differ across network locations.
  • Network controls, such as allowlists, regional restrictions, or DNS query limits, prevent MPIC agents from accessing your website or DNS infrastructure.
  • DNS CAA record responses are inconsistent across network locations.


In this article


What do you need to do?

Review your environment for any controls that could restrict MPIC traffic. If you don’t use network controls that restrict DNS queries or website traffic, no action is required.
 

Update your allowlists

If you restrict DNS queries or website traffic by IP address, region, query volume, or rate, review your configuration to ensure it does not block MPIC traffic.

These network controls can affect:

  • CAA checks: To complete the CAA check so DigiCert can issue your certificate, MPIC agents must receive consistent CAA record responses from your DNS name servers for every domain in your certificate.
  • DNS-based DCV methods: To complete the domain validation, MPIC agents must receive consistent DCV method responses from your DNS name servers.
  • HTTP Practical Demonstration validation: To complete the domain validation, MPIC agents must be able to access your website where the domain validation file is located and return consistent responses.
     

HTTP Practical Demonstration validation

If you use the HTTP Practical Demonstration DCV methods and restrict website traffic, do one of the following:

  • DigiCert User-Agent strings (recommended): Add both DigiCert DCV/1.1 and DigiCert DCV Bot/1.1 to your allowlist.
    (Note: The User Agent is a request header that identifies the DigiCert software that performs the HTTP Practical Demonstration website DCV lookups.)
  • MPIC agent IP addresses: Add all MPIC agent IP addresses to your allowlist.
     

DNS-based validation and CAA checks

If your DNS infrastructure restricts queries by IP address, allow all MPIC agent IP addresses.
The following table lists the MPIC agent IP addresses and the date each IP address becomes active.
 

Table 1: MPIC agent IP addresses

Effective date IP address Location
August 17, 2026 13.232.96.181 India
June 18, 2026 54.169.250.231 Singapore
June 18, 2026 18.166.173.162 Hong Kong
June 18, 2026 56.228.59.9 Sweden
February 24, 2026 52.78.185.62 South Korea
February 24, 2026 52.197.215.146 Japan
September 1, 2025 18.193.239.14 Germany
September 1, 2025 52.17.48.104 Ireland
September 1, 2025 202.65.16.4 Netherlands
September 1, 2025 13.58.90.0 United States
September 1, 2025 54.185.245.130 United States
September 1, 2025 54.241.89.140 United States
September 1, 2025 54.227.165.213 United States
September 1, 2025 216.168.240.4 United States
September 1, 2025 216.168.247.9 United States



Verify DNS record responses

Verify that your DNS records are accessible and return consistent responses from multiple network locations.
Check the following:

  • DNS CAA records
  • DNS TXT records
  • DNS CNAME records
  • DNS records used for Email to DNS TXT contact
  • DNS CAA records used for Email to CAA contact

Also verify that:

Troubleshooting MPIC validation issues

If domain validation or certificate issuance fails:

  1. Confirm that allowlists or regional restrictions are not blocking MPIC requests.
  2. Verify that DNS query limits are not preventing MPIC lookups.
  3. Verify that authoritative nameservers return consistent DNS responses.
  4. Confirm that HTTP validation files are accessible from multiple network locations.
  5. Verify that CAA records return consistent responses from multiple network locations.

If necessary, contact your DNS provider to verify that your DNS infrastructure is accessible from multiple network locations.


What corroboration means

Corroboration means that DigiCert validates information from multiple independent network locations before validating a domain or issuing a certificate.

  • For domain control validation (DCV), DigiCert compares the validation data retrieved from multiple network perspectives.
  • For Certificate Authority Authorization (CAA) checks, DigiCert compares the CAA information retrieved from multiple network perspectives.

This redundancy helps protect against security threats that could cause DigiCert to receive incorrect domain validation or CAA information from a single network perspective. By comparing results from multiple network perspectives, DigiCert can detect inconsistent results before validating a domain or issuing a certificate.


How MPIC works

Domain control validation (DCV)

DigiCert performs its standard domain validation check from its primary network. DigiCert then repeats the check from multiple remote network perspectives.

The MPIC domain validation process affects these certificate types that include a domain name or IP address:

  • TLS
  • Secure Email (S/MIME)
  • Verified Mark / Common Mark
  • Qualified Website Authentication Certificate (QWAC) / QWAC PSD2
  • PKIO Private Services Server
  • X9 PKI for TLS

The corroboration requirements apply to each DCV method listed below.
If an insufficient number of remote network perspectives corroborate the primary network’s validation data, domain validation fails and the certificate cannot be issued.

MPIC applies to all common domain control validation (DCV) methods, including:

  • Persistent DNS TXT Record
  • DNS TXT record
  • DNS CNAME record
  • Email to DNS TXT contact
  • Email to CAA contact
  • HTTP Practical Demonstration (only method that supports IPv4 and IPv6 address validation)
  • HTTP Practical Demonstration with a unique file name
  • ACME HTTP-01
  • ACME DNS-01

Learn more about these domain control validation (DCV) methods.
 

DNS Certificate Authority Authorization (CAA) check

MPIC also applies to the DNS CAA record checks. Before issuing a certificate, DigiCert performs its standard CAA record check from its primary network and repeats the check from multiple remote network perspectives.

The MPIC CAA check affects these types of public certificates:

  • TLS
  • Qualified Website Authentication Certificate (QWAC) / QWAC PSD2
  • Secure Email (S/MIME)

Learn more about the DNS CAA resource record check.
 

Corroboration requirements per the CA/Browser Forum

The CA/Browser Forum MPIC requirements define the phased rollout timeline, including the minimum number of remote network perspectives CAs must use and their geographic distribution. They also define the number of non-corroborations allowed based on the number of remote network perspectives used. See the CA/Browser Forum TLS Baseline Requirements for the complete requirements.

Beginning in December 2026, DigiCert will use 6 remote network perspectives. When 6 or more remote network perspectives are used, the CA/Browser Forum quorum requirements allow up to 2 non-corroborations.
 

Phased implementation timeline

Effective date Minimum number of remote network perspectives
March 15, 2025 At least 2
September 15, 2025 At least 2
March 15, 2026 At least 3, with corroborating perspectives across at least 2 RIR service regions
June 15, 2026 At least 4, with corroborating perspectives across at least 2 RIR service regions
December 15, 2026 At least 5, with corroborating perspectives across at least 2 RIR service regions



Quorum requirements

Number of remote network perspectives used Allowed non-corroborations
2–5 1
6 or more 2

Did you find this page helpful?

Thank you for your feedback!