---
name: azion-add-the-let-s-encrypt-txt-record
description: >-
  Add the _acme-challenge TXT record to a zone in Edge DNS so Let's Encrypt can validate a certificate that Certbot or another ACME client requests.
---

# Add the Let's Encrypt TXT record

You can add the TXT record of a Let's Encrypt DNS-01 challenge to a zone in [Edge DNS](/en/documentation/platform/edge-dns/) from Azion Console. Add it when an ACME client outside Azion, such as Certbot, requests the certificate for a hostname of that zone.

A certificate that Azion requests for a workload needs no TXT record from you. When the zone is in Edge DNS, Azion writes the challenge record itself. At another DNS provider, you create a CNAME record instead. To create that record, refer to [Issuance and renewal](/en/documentation/platform/workloads/certificate-manager/issuance-and-renewal/#domain-validation). To have Azion request the certificate, refer to [Request a Let's Encrypt certificate](/en/documentation/guides/application-security/tls-and-certificates/how-to-generate-a-lets-encrypt-certificate/).

Devices that depend on the expired Let's Encrypt chain cross-signed by IdenTrust reject certificates that use it. For more information, refer to [Certificate chain](/en/documentation/platform/workloads/certificate-manager/certificates/#certificate-chain).

---

## Prerequisites

- A zone in Edge DNS that holds the domain of the hostname. To create a zone, refer to [Edge DNS guides and tutorials](/en/documentation/platform/edge-dns/guides/).
- The challenge value that the ACME client provides for the TXT record.
- Access to Azion Console. For more information, refer to [How to access Azion Console](/en/documentation/guides/platform/account-and-billing/how-to-access-azion-console/).

---

## Add the TXT record to the zone

With the DNS-01 challenge, Let's Encrypt confirms control of the domain through a TXT record in its DNS zone. The record carries the name and the value that the ACME client gives you.

To add the record in Azion Console:

1. **Open the Edge DNS page**

   Access [Azion Console](https://console.azion.com/) > **Edge DNS**.

2. **Open the zone**

   Select the zone that holds the domain of the hostname.

3. **Open the Records tab**

4. **Select + Record**

5. **Enter the record name**

   In **Name**, enter `_acme-challenge`. For a hostname below the domain, enter `_acme-challenge.<subdomain>`, such as `_acme-challenge.www`.

   The name is relative to the zone, so the Console adds the domain for you. When the ACME client gives the full name, enter only the part before the domain. A name typed with the domain carries the domain twice, and Let's Encrypt never finds the record. For the length and characters a name accepts, refer to [Zones and records](/en/documentation/platform/edge-dns/zones-and-records/#record-fields).

6. **Select the record type**

   In **Record Type**, select *TXT*.

7. **Enter the challenge value**

   In **Value**, enter the challenge value that the ACME client provides.

8. **Set the TTL**

   In **TTL (seconds)**, enter how long a resolver can cache the response, in seconds. The field accepts `0` to `604800`.

9. **Save the record**

   Select **Save**.

A name that nobody queried before it existed answers within seconds. A name queried before the record exists is answered `NXDOMAIN` for up to one hour, so save the record before the ACME client validates. For more information, refer to [How it works](/en/documentation/platform/edge-dns/how-it-works/#caching-and-propagation). Let's Encrypt reads the record when it validates the certificate request.

---

## Next steps

- [Upload a digital certificate](/en/documentation/guides/application-security/tls-and-certificates/digital-certificates.md): Upload the certificate that the ACME client receives, and bind it to a workload.
- [Issuance and renewal](/en/documentation/platform/workloads/certificate-manager/issuance-and-renewal.md): Find how Azion validates the domains of a certificate it requests, and the statuses of a request.
- [Request a Let's Encrypt certificate](/en/documentation/guides/application-security/tls-and-certificates/how-to-generate-a-lets-encrypt-certificate.md): Have Azion request the certificate for a workload instead of an ACME client.
- [Edge DNS guides and tutorials](/en/documentation/platform/edge-dns/guides.md): Create a zone and manage its records in Edge DNS.
