Certificate DNS Authorization

DNS authorization lets AZExecute create the temporary TXT records required for ACME certificate orders and renewals. Each DNS authorization stores its own propagation delay, so use the value that matches the selected provider and zone.

Recommended propagation delays

Start with these values. They are deliberately conservative enough for normal certificate renewals without making every order unnecessarily slow.

DNS provider Recommended When to increase it
Azure DNS 60 seconds Increase to 120 seconds only if ACME still observes the previous DNS state.
Cloudflare 60 seconds Increase to 120 seconds if the selected zone propagates TXT changes more slowly.
Amazon Route 53 60 seconds Increase to 120 seconds for occasional propagation delays after provider confirmation.
Simply.com 60 seconds Use 120 seconds when the zone is consistently slower; use 180 seconds only if needed.
The propagation delay begins only after AZExecute has confirmed the TXT record through the provider API. Provider API confirmation and public DNS propagation are separate stages and are reported separately in the certificate activity log.

When should you change the delay?

Keep 60 seconds when renewals complete normally.

Try 120 seconds when the provider confirms the record but ACME intermittently reports that the TXT value is missing.

Use 180–300 seconds only when authoritative DNS for the zone is consistently slow.

Do not increase propagation delay for invalid credentials, disabled integrations, rejected record changes, or provider API errors. Resolve the reported provider error instead.

A longer delay makes every affected certificate order slower. Increase it for the specific DNS authorization that needs more time instead of changing unrelated providers or zones.
An unhandled error has occurred. Reload 🗙
An unhandled error has occurred. Reload 🗙