Reading ACM certificate renewal notices

Mail about certificates from AWS Certificate Manager (ACM) comes in three broad kinds: it renewed, the renewal needs validation, and it is about to expire. Most of them only need reading. The awkward part is that the one you cannot leave — the one that takes HTTPS down if nobody acts — arrives from the same sender with much the same subject as the rest.

Last updated: 2026-09-22

The kinds of mail ACM sends

A certificate issued by ACM renews itself before it expires, as long as the CNAME record for DNS validation is still in place and the certificate is attached to an AWS resource. What lands in the mailbox then is a renewal confirmation like “Your certificate is renewed”, and there is nothing to do.

When the CNAME record has gone, when the certificate uses email validation, or when it is attached to no resource at all, the automatic renewal cannot happen and a mail marked “Action required” asks you to validate. That one needs action: miss the date and the certificate expires. If the expiry date gets close and the renewal still has not gone through, a warning about the coming expiry follows.

How to tell them apart

As a rule of thumb: “Action required”, “requires validation” or “expire” in the subject means something has to be done; “renewed” or “has been issued” means it is there to be read. The body carries the domain name and the certificate's ARN — which contains the account ID — so it tells you which customer and which site it is about.

The hard case is the week when certificates for several customers' domains renew at once and a dozen mails with the same subject line arrive together. One “Action required” among them is easy to miss.

What Sabaki does with them

Sabaki pulls the account ID out of the ARN in the body, files the notification under that customer, and marks a renewal confirmation “Info” and a validation request “Action required”, with the date it is due. Even in a row of identically titled notifications, the summary tells them apart at a glance: “nothing needs doing” versus “add the DNS record by such-and-such a date”. Unlike marketing mail, these are delivered to Slack and email as well.

Example: the mail that arrives, and what Sabaki shows

The subject and body imitate a real notification. Account IDs and dates are fictional.

The mail that arrives (English)
From
Amazon Web Services <no-reply@certificates.amazon.com>
Subject
Your certificate is renewed

Greetings from Amazon Web Services,

Your certificate for domain shop.example.co.jp (ARN: arn:aws:acm:ap-northeast-1:123456789012:certificate/1a2b3c4d-5e6f-7a8b-9c0d-1e2f3a4b5c6d) has been renewed and is ready for use. No action is required on your part.

This certificate is associated with 2 AWS resources.

What Sabaki shows (English)
InfoCompany A (online shop)123456789012 (Company A, production)

The ACM certificate for shop.example.co.jp renewed successfully. Nothing needs doing.

The DNS validation record was still valid, so ACM renewed the certificate before it expired. The new certificate is pushed automatically to the two resources it is attached to (a load balancer or CloudFront, for example). HTTPS on the site carries on unchanged.

A mail from the same ACM with a subject like “Action required: Your certificate renewal requires validation” comes out as “Action required” instead, with the expiry date and, in the explanation, which DNS record to add.

When action really is needed

There are only a few reasons an automatic renewal fails. Read the explanation, work out which one applies, and if the work falls on the customer's side, the summary goes straight into the message you send them.

  • The CNAME record for DNS validation is gone, lost in a domain transfer or a rebuilt zone.
  • The certificate uses email validation, and nobody answered the approval mail sent to admin@ or webmaster@.
  • The certificate is attached to no AWS resource at all, which puts it outside automatic renewal (if nothing needs it, delete it).

Keeping a lot of certificates moving

Renewal confirmations can be searched by subject in the inbox, selected all at once and archived together. Leaving only the one that needs action and following it in the ledger keeps the whole round short.

Forward one AWS notification and it comes back explained

The Free plan covers one account and one seat, with no credit card. Nothing changes on the AWS side, and no access keys are registered.

Related questions

Related guides

If this helps, pass it on to someone who needs it.