# CAs MUST NOT use local policy to disable DNSSEC validation on any DNS query associated with the validation of domain authorization or control. — TLS certificate and CA requirement effective dates (CA/Browser Forum, Chrome, Mozilla)

For CAs MUST NOT use local policy to disable DNSSEC validation on any DNS query associated with the validation of domain authorization or control., requirement is CAs MUST NOT use local policy to disable DNSSEC validation on any DNS query associated with the validation of domain authorization or control; effective date is 2026-03-15; baseline requirements section is 3.2.2.4; authority is CA/Browser Forum TLS Baseline Requirements; scope is all publicly-trusted CAs issuing TLS server certificates, recorded from its source on 2026-08-05.

- **Requirement:** CAs MUST NOT use local policy to disable DNSSEC validation on any DNS query associated with the validation of domain authorization or control. _(verified: appears in the quote below)_
- **Effective date:** 2026-03-15 _(verified: appears in the quote below)_
- **Baseline Requirements section:** 3.2.2.4 _(verified: appears in the quote below)_
- **Authority:** CA/Browser Forum TLS Baseline Requirements _(our reading, not quoted from the source)_
- **Scope:** all publicly-trusted CAs issuing TLS server certificates _(our reading, not quoted from the source)_

## What the source says

> 2026-03-15 | 3.2.2.4 | CAs MUST NOT use local policy to disable DNSSEC validation on any DNS query associated with the validation of domain authorization or control.

## Source

- https://cabforum.org/working-groups/server/baseline-requirements/requirements/

Last verified: 2026-08-05. Review by: 2026-11-03.
Part of [TLS certificate and CA requirement effective dates (CA/Browser Forum, Chrome, Mozilla)](https://referencesource.org/tls-certificate-requirement-effective-dates/).
