Join our Newsletter — 33% off our NHI Course
Home› FAQ› Governance, Ownership & Risk› Should organisations use persistent DNS validation records or…
Governance, Ownership & Risk

Should organisations use persistent DNS validation records or recreate them every time?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated October 8, 2026 Domain: Governance, Ownership & Risk

Persistent records make repeat issuance easier, but they require stronger control over the DNS zone and any reusable tokens or delegated records. Recreating them each time reduces persistence but increases operational friction, so the choice should follow the organisation's renewal frequency and governance maturity.

When persistent DNS validation records make sense

Persistent DNS validation records are the practical choice when certificate issuance is frequent, multiple teams need a stable renewal path, or the DNS workflow is already tightly governed. They reduce churn and make automation easier, but they also create a standing dependency on the DNS zone and on any reusable tokens, delegated records, or automation that can update those records.

The core question is not whether persistence is “safer” in the abstract, but whether the organisation can keep that validation path tightly controlled over time. If the record is left in place, the security of the record, the zone, and the renewal process become part of the trust boundary for every future issuance.

That is why persistent records fit mature environments better than ad hoc ones. They work best when ownership is clear, DNS changes are logged and reviewed, and the same control assumptions will remain true across many renewals rather than a single event.

Why recreating validation records can reduce exposure

Recreating validation records for each issuance reduces persistence, which narrows the window in which a validation artifact can be reused or abused. That approach can be attractive when renewals are infrequent, when DNS administration is loosely controlled, or when the organisation wants each issuance to require a fresh, deliberate action.

The trade-off is operational friction. More manual steps mean more chances for renewal failures, delayed issuance, and inconsistent implementation across environments. If teams regularly miss renewal windows or reintroduce bespoke workarounds, the “safer” approach can become the more failure-prone one.

In practice, the choice is often about whether the organisation prefers a steady, governed automation path or a shorter-lived but more hands-on control pattern. Both can work, but each makes a different assumption about the maturity of DNS operations and change discipline.

Choosing the right pattern for your renewal and governance model

Persistent records are usually better when certificate turnover is predictable, DNS ownership is centralised, and the same record can be safely reused without broadening access beyond what is necessary. Recreated records are better when you want explicit renewal events, stronger separation between issuance cycles, or less standing exposure if a validation token or delegated record is compromised.

The deciding factor should be the combination of renewal frequency, blast radius, and operational control. If the validation record is long-lived but poorly governed, persistence is a liability. If it is long-lived and tightly controlled, persistence is often the more reliable design.

IANA is useful here because DNS validation depends on stable, correctly managed domain and record behaviour, and that stability only helps when the underlying zone administration is sound. For teams building a broader control baseline around DNS change management and access discipline, ISO/IEC 27002:2022 Information Security Controls provides the right implementation context for governed operational controls.

Risk and Threat Considerations

Persistent DNS validation records increase exposure if the zone, delegated update path, or reusable token is overexposed. An attacker or careless operator does not need to defeat the issuance system itself if they can alter the standing validation mechanism or abuse a long-lived record that was meant to be reused.

Failure mechanism: A durable validation record can become a reusable control point if DNS write access, token handling, or delegation is broader than intended, allowing unauthorized renewals or misdirection of validation.

Impact: Certificate issuance may continue on an insecure basis, renewal workflows may be silently trusted, and the organisation may lose confidence in the integrity of its domain validation process.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST SP 800-53 Rev 5IA-5 — Authenticator ManagementReusable validation tokens and credentials need lifecycle control.
Recommendation — Rotate and revoke reusable validation tokens on a defined schedule.
ISO/IEC 27001:2022A.5.15 — Access controlPersistent validation records depend on controlled DNS write access.
A.8.9 — Configuration managementDNS validation records are configuration items whose persistence affects trust.
Recommendation — Restrict DNS update paths to approved administrators and automation. Track validation records as managed configuration and review changes.
CIS Controls v8CIS-4 — Secure Configuration of Enterprise Assets and SoftwareDNS validation behaviour depends on hardened, controlled configuration.
Recommendation — Standardise DNS validation settings and audit deviations regularly.

Practitioner Guidance

Decision rule: Use persistent records only when the DNS zone owner can demonstrate tight change control, limited write access, and reliable monitoring of validation-related changes. If those conditions are not present, favour recreating the record or redesigning the renewal workflow.

What to verify: Confirm who can update the record, whether any delegated token or automation credential is reusable, and whether the record is protected by review, logging, and rotation discipline. The answer is not just “can this be automated,” but “can it stay trustworthy after six months of normal operations.”

Practitioner takeaway: Persist only what you can govern for the full life of the certificate, because a convenient validation record is a control if and only if its reuse remains tightly bounded and observable.

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on October 8, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org