An Azure service that provides a cloud content delivery network with threat protection.
Front Door managed cert for apex domain stuck in PendingRevalidation, TXT record is correct, expires 2026-10-06. Can revalidation be re-run without regenerating the token?
Problem description
The Front Door-managed certificate for our apex custom domain (Premium profile) is in PendingRevalidation. It probably entered that state around 2026-08-22, 45 days before expiry. The certificate expires on 2026-10-06 19:59 UTC.
Environment
- Azure Front Door Premium, managed certificate on an apex custom domain
- The apex uses an A record to Front Door, not a CNAME
- DNS is hosted by a third party, not Azure DNS
- Validation by
_dnsauthTXT record
What I've checked
- The
_dnsauthTXT record matches the currentvalidationTokenon the domain. It is served by all three authoritative nameservers and by public resolvers. - The portal diagnostic ("Azure Front Door Custom Domain not Validated") says the public TXT record "correctly matches the expected value".
- There are no CAA records.
- The domain's token shows an expiry date of 2026-04-13, which is in the past.
Why I can't regenerate the token
The docs say to click Regenerate and add the new TXT value. We can't do that in time. A new value needs a change by the third-party DNS owner, whose process will not finish before the certificate expires. Microsoft support (open case) also recommended not regenerating, because the published token is already correct.
What I need
- Can Front Door re-run revalidation and certificate rotation using the existing published token?
- Is there a supported way to re-run validation on the existing token? The docs mention an empty
PATCHto the custom domain API (for BYOC-validated domains) and aRefreshValidationaction in the FAQ. But the only CLI/PowerShell command I can find,az afd custom-domain regenerate-validation-token/Update-AzFrontDoorCdnCustomDomainValidationToken, issues a new token. Does either apply to a DNS-validated managed certificate? - If not, is there a supported way to clear the stuck state without a new token?
This domain carries production traffic and we have about three business days.