Can the _acme-challenge.domain.com record be deleted?

Hello! I am wondering if the acme challenge TXT record can be deleted once a certificate is issued? We're currently looking into automating the whole process with cert-manager using DNS validation, and when we used to do it with certbot we would keep the acme challenge record in our DNS Zone in our Google Cloud Platform project.

In order to properly test cert-manager we would let it request a certificate from Let's Encrypt, have it create a new challenge record and present it so that it can be properly queried and verified. We're just wondering if there are any risks involved with letting the previous acme challenge record be overwritten or deleted. I've heard that this record is one-time use and that it should get deleted afterwards anyway. Is that correct?

Thank you!

2 Likes

You should delete it immediately after the validation has succeeded.

It's only needed for a few minutes/seconds.

5 Likes

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.