- Newest
- Most votes
- Most comments
I understand your concern about not receiving important emails regarding your SSL certificates managed by AWS Certificate Manager (ACM). Let's address your issues and provide some guidance:
-
Automatic Renewal: ACM attempts to renew certificates automatically 60 days before expiration. However, for the renewal to be successful, certain conditions must be met, such as the certificate being associated with an AWS service and meeting validation requirements.
-
Email Notifications: ACM begins sending renewal notices to the email addresses associated with the domain 45 days before expiration. These emails come from no-reply-aws@amazon.com, not from no-reply@sns.amazonaws.com which you mentioned receiving.
-
Troubleshooting Steps:
- Check your spam or junk mail folder for emails from no-reply-aws@amazon.com.
- Ensure your email client isn't applying rules that automatically move these messages to a different folder.
- Add no-reply-aws@amazon.com to your address book or Safe Senders list.
- Ask your system administrator to whitelist incoming email from no-reply-aws@amazon.com.
-
Email Validation: If your certificates use email validation, ACM sends emails to common system addresses like administrator, hostmaster, postmaster, webmaster, and admin@yourdomain.com. Ensure these addresses are set up and monitored.
-
Assigning Additional Users: Unfortunately, ACM doesn't have a direct way to "assign" additional users to receive emails. The notifications are sent to the email addresses associated with the domain ownership validation.
-
Alternative Solution: Since nahuel@rebill.to is receiving the notifications, you could set up an email forwarding rule on that account to forward ACM-related emails to your address (ruben@rebill.com).
-
Checking Certificate Status: Regularly check the ACM console, use the ACM API, AWS CLI, or AWS Health Dashboard to monitor the status of your certificates.
To prevent future issues, ensure your domain's WHOIS information is up-to-date, monitor the email addresses used for validation, and regularly check the ACM console for certificate statuses. If problems persist, consider switching to DNS validation for your certificates if possible, as it can be more reliable than email validation.
Sources
Check a certificate's renewal status - AWS Certificate Manager
Verifying an email address - Amazon Simple Email Service
AWS Certificate Manager email validation - AWS Certificate Manager
Troubleshoot managed certificate renewal - AWS Certificate Manager
Troubleshoot email validation problems - AWS Certificate Manager
You can configure the alternate contacts for your account in the AWS console as described in the AWS Account Management documentation.
If this is configured, and you believe your configured account is missing emails it should be receiving, you may want to open a support case. See AWS Support Documentation
answered 2 years ago
Relevant content
asked 4 years ago
asked 3 years ago
