Support >
  About cybersecurity >
  DV certificate verification passed but issuance delayed? Explanation of CA institution polling mechanism.

DV certificate verification passed but issuance delayed? Explanation of CA institution polling mechanism.

Time : 2026-07-12 10:24:25
Edit : DNS.COM

  When applying for a DV certificate, many people encounter a perplexing situation: the domain verification check shows "passed," and the verification files are confirmed to be accessible, but after waiting for several hours or even a day, the certificate status remains "pending issuance." Refreshing the page, resubmitting, changing verification methods—after all this trouble, nothing happens.

  This isn't your problem, nor is it a "malfunction" of the CA (Certificate Authority). It's because the DV certificate issuance mechanism itself isn't real-time—passing verification only gets you the "ticket"; the issuance process involves a polling process you might not be aware of.

  The Basic Timeline for DV Certificate Issuance

  First, understand how long a DV certificate issuance normally takes.

  According to the official statements of major cloud platforms, the average issuance time for a DV certificate, assuming correct information, is 1 to 15 minutes. After verification, the certificate is normally issued within about 20 minutes, and at most within a day.

  In other words, if the verification truly passes and the domain itself is correct, the certificate should be issued quickly. The problem is that there's a security audit hurdle between "verification passed" and "CA deems it problem-free."

  Why wait even after verification?

  The DV certificate issuance mechanism works like this: After verification, the CA system doesn't issue the certificate immediately; instead, it enters an automatic detection queue. The CA conducts a security review of the domain to determine if it poses any "risk."

  Domains deemed "risky" will be rejected by the CA. Some common reasons for rejection are publicly available in the documentation:

  The domain contains keywords related to banking or payment (e.g., bank, pay, fund, wallet).

  The domain contains well-known brand names (e.g., Google, Microsoft, Apple).

  The domain is on the CA's internal blacklist.

  The domain itself contains phishing or malicious records.

  If a DV certificate hasn't been issued within 24 hours of verification, you can only purchase an OV or EV certificate. The meaning is clear—not all verified domains will be issued a DV certificate; if the security audit fails, waiting is pointless.

  How exactly does a Certificate Authority's (CA) polling mechanism work?

  While the technical documentation doesn't explicitly define "polling," the DV certificate issuance process itself involves multiple rounds of automated checks.

  From the ACME protocol's working mechanism, applying for a DV certificate requires four stages: "Account Registration → Order Creation → Authorization Verification → Certificate Issuance." Authorization verification verifies your control over the domain name, which the CA confirms through HTTP-01 or DNS-01 challenges. After a successful challenge, the CA system enters an automated polling queue, periodically checking the domain's security status and the compliance of the certificate request.

  This "polling check" is conducted in batches. If you submit your application at the start of a batch, it might be issued in just a few minutes; if you submit your application just after a check cycle has passed, you'll have to wait for the next check window—this explains why, even after passing verification, some people receive their certificates in 10 minutes while others wait a long time.

  If the certificate is not issued within two calendar days, the review automatically fails. This indicates that the system isn't constantly "polling" you, but rather has a defined time window, automatically giving up after a timeout.

  What to do after successful verification

  If you encounter a "verification passed but not issued" situation, check the following in order:

  Step 1: Confirm if the verification method is truly usable. Use a third-party tool (such as myssl.com's DNS checker) to verify if your DNS records or files can actually be accessed by the CA. Sometimes your DNS provider's resolution is working, but the CA's DNS server hasn't synchronized yet. In this case, you need to wait a while and trigger manual verification again.

  Step 2: Check the domain name itself. Does your domain name contain words related to banks, payments, or well-known brands? If so, the DV certificate will most likely fail the security review. Don't wait; directly convert to OV or EV. Also, check if the domain name has been marked with malicious records.

  Step 3: Wait and monitor status changes. If everything above is fine, then you can only wait. The CA's polling mechanism has its own rhythm, and the user has very little room for intervention. It is recommended to refresh the console every half hour to check if the status has changed from "pending issuance" to "issued." Step 4: If no certificate is issued after 24 hours, decisively switch to another solution. This is not a problem that can be solved by "waiting a little longer." For certificates that haven't been issued after 24 hours, the only solution is to purchase an OV or EV certificate; continuing to wait will not yield results.

  Ultimately, the transition between "verification passed" and "final issuance" of a DV certificate is not an automatic state change, but rather a multi-stage process: "verification successful → entering the issuance queue → CA conducts security review → polling detection → issuance or rejection." The security review stage is opaque—CAs have their own rules and blacklists and will not tell you the specific reasons, only providing a "24-hour unissued" result.

  For individual website owners, all you can do is ensure the verification configuration is correct and the domain itself is fine, then wait patiently. If it still hasn't been issued after 24 hours, don't worry. Either change the domain and reapply, or directly use an OV certificate—this is determined by the DV certificate's working mechanism, and cannot be changed by your actions.

  Frequently Asked Questions

  Q: My DV certificate verification passed, why hasn't it been issued yet?

  A: Passing verification only confirms your control over the domain name; it doesn't mean the CA has approved its issuance. Before issuance, there's an automatic security review. The CA system checks if the domain contains sensitive words (like "bank" or "pay"), is on an internal blacklist, or has malicious records. If the review fails, it won't be issued, even if verification passes.

  Q: What is the CA's polling frequency? How often do they check?

  A: Each CA's specific polling strategy is not publicly disclosed. Based on the issuance time window in the documentation, CA checks typically complete one round of testing within 20 minutes to 2 hours after verification. If it's not detected within this window, you have to wait for the next round. This is why different users receive their certificates at vastly different times, even after passing verification.

  Q: If verification passed but it hasn't been issued after 24 hours, should I continue waiting?

  A: No, you shouldn't wait. The official documentation clearly states that if a DV certificate has not been issued after 24 hours of verification, it can be considered that the security review has failed, and continuing to wait will not yield any results. It is recommended to change the domain name and try again, or directly purchase an OV/EV certificate.

  Q: If a domain name contains the word "bank," does that mean I can't apply for a DV certificate at all?

  A: Most likely yes. To prevent phishing attacks, CA organizations will block domain names containing keywords related to finance, payment, or well-known brands and refuse to issue DV certificates. If you really need to use such a domain name, you can only go through the OV or EV certificate application process and submit your company qualifications for manual review.

DNS Amy
DNS Luna
DNS Anna
DNS NOC
Title
Email Address
Type
Information
Code
Submit