| Important: This is a dynamic article. We will update it as more information becomes available. Save this page and check back periodically for the latest information. |
| On August 17, 2026, DigiCert added a new MPIC agent IP address: 13.232.96.181. If you use allowlists, regional restrictions, or DNS query limits, review the Update your allowlists section below. |
Between October 19 and November 30, 2026: DigiCert will increase the remote MPIC agents per domain query up to six unique agents (currently four unique agents).
December 1, 2026:
DigiCert will enforce the next phase of the CA/Browser Forum MPIC requirements and settle on six remote network perspectives across at least two Regional Internet Registry (RIR) regions. The enforcement will happen in advance of the December 15, 2026, deadline. See Corroboration requirements per the CA/Browser Forum below.
MPIC verifies domain control and performs CAA checks from multiple remote network locations. Domain validation or certificate issuance may fail if:
Review your environment for any controls that could restrict MPIC traffic. If you don’t use network controls that restrict DNS queries or website traffic, no action is required.
If you restrict DNS queries or website traffic by IP address, region, query volume, or rate, review your configuration to ensure it does not block MPIC traffic.
These network controls can affect:
If you use the HTTP Practical Demonstration DCV methods and restrict website traffic, do one of the following:
DigiCert DCV/1.1 and DigiCert DCV Bot/1.1 to your allowlist.If your DNS infrastructure restricts queries by IP address, allow all MPIC agent IP addresses.
The following table lists the MPIC agent IP addresses and the date each IP address becomes active.
Table 1: MPIC agent IP addresses
| Effective date | IP address | Location |
|---|---|---|
| August 17, 2026 | 13.232.96.181 | India |
| June 18, 2026 | 54.169.250.231 | Singapore |
| June 18, 2026 | 18.166.173.162 | Hong Kong |
| June 18, 2026 | 56.228.59.9 | Sweden |
| February 24, 2026 | 52.78.185.62 | South Korea |
| February 24, 2026 | 52.197.215.146 | Japan |
| September 1, 2025 | 18.193.239.14 | Germany |
| September 1, 2025 | 52.17.48.104 | Ireland |
| September 1, 2025 | 202.65.16.4 | Netherlands |
| September 1, 2025 | 13.58.90.0 | United States |
| September 1, 2025 | 54.185.245.130 | United States |
| September 1, 2025 | 54.241.89.140 | United States |
| September 1, 2025 | 54.227.165.213 | United States |
| September 1, 2025 | 216.168.240.4 | United States |
| September 1, 2025 | 216.168.247.9 | United States |
Verify that your DNS records are accessible and return consistent responses from multiple network locations.
Check the following:
Also verify that:
If domain validation or certificate issuance fails:
If necessary, contact your DNS provider to verify that your DNS infrastructure is accessible from multiple network locations.
Corroboration means that DigiCert validates information from multiple independent network locations before validating a domain or issuing a certificate.
This redundancy helps protect against security threats that could cause DigiCert to receive incorrect domain validation or CAA information from a single network perspective. By comparing results from multiple network perspectives, DigiCert can detect inconsistent results before validating a domain or issuing a certificate.
DigiCert performs its standard domain validation check from its primary network. DigiCert then repeats the check from multiple remote network perspectives.
The MPIC domain validation process affects these certificate types that include a domain name or IP address:
The corroboration requirements apply to each DCV method listed below.
If an insufficient number of remote network perspectives corroborate the primary network’s validation data, domain validation fails and the certificate cannot be issued.
MPIC applies to all common domain control validation (DCV) methods, including:
Learn more about these domain control validation (DCV) methods.
MPIC also applies to the DNS CAA record checks. Before issuing a certificate, DigiCert performs its standard CAA record check from its primary network and repeats the check from multiple remote network perspectives.
The MPIC CAA check affects these types of public certificates:
Learn more about the DNS CAA resource record check.
The CA/Browser Forum MPIC requirements define the phased rollout timeline, including the minimum number of remote network perspectives CAs must use and their geographic distribution. They also define the number of non-corroborations allowed based on the number of remote network perspectives used. See the CA/Browser Forum TLS Baseline Requirements for the complete requirements.
Beginning in December 2026, DigiCert will use 6 remote network perspectives. When 6 or more remote network perspectives are used, the CA/Browser Forum quorum requirements allow up to 2 non-corroborations.
| Effective date | Minimum number of remote network perspectives |
|---|---|
| March 15, 2025 | At least 2 |
| September 15, 2025 | At least 2 |
| March 15, 2026 | At least 3, with corroborating perspectives across at least 2 RIR service regions |
| June 15, 2026 | At least 4, with corroborating perspectives across at least 2 RIR service regions |
| December 15, 2026 | At least 5, with corroborating perspectives across at least 2 RIR service regions |
| Number of remote network perspectives used | Allowed non-corroborations |
|---|---|
| 2–5 | 1 |
| 6 or more | 2 |