A certificate request is a message your device sends to prove it owns a website, email address, or other online identity before getting an encrypted certificate

When you want to secure a website or set up encrypted email, you do not send your actual certificate to a certificate authority. Instead, your device creates a certificate request — a file that says "I control this domain" or "I own this email address" — and sends that request instead. The certificate authority checks the request, verifies you actually control what you claim, and then sends back a real certificate that your device can use.

Think of it like proving your identity to get a passport. You do not hand over your passport application and hope they believe you own the address on it. You prove you live there by showing a utility bill, then they issue the passport. A certificate request works the same way: it proves ownership, the authority verifies it, and then you get the certificate.

Key Takeaways

  • A certificate request contains your public key and the domain or email address you want to secure, but not your private key.
  • Your device creates the request automatically when you set up HTTPS for a website or request an encrypted email certificate.
  • The certificate authority uses the request to verify you control the domain or email before issuing a real certificate.
  • You send the request to the certificate authority, but you keep the private key that pairs with it completely private.

What goes inside a certificate request

A certificate request contains several pieces of information. The most important is your public key — a long string of characters that will eventually be part of your certificate. The request also includes details about what you want to secure: a domain name like example.com, an email address, your organization name, and your location.

The request does not contain your private key. That stays on your device, locked away. If your private key ever left your device or appeared in a certificate request, the whole system would break — anyone with that key could impersonate you. The certificate authority never asks for it and should never receive it.

When you look at a certificate request file on your computer, it usually has a name ending in .csr (Certificate Signing Request) or .pem. It looks like a block of random characters wrapped in lines that say "BEGIN CERTIFICATE REQUEST" and "END CERTIFICATE REQUEST". You cannot read the actual information inside without special tools, but the certificate authority's system can.

How certificate requests fit into getting a real certificate

The process usually works like this: your web server or email client generates a certificate request automatically. You copy that request and paste it into a form on the certificate authority's website, or upload the .csr file directly. The certificate authority reads the request and sees what domain or email you are trying to secure.

Then the authority has to verify you actually control that domain or email. For a website, they might send a verification code to an email address associated with the domain, or they might check a special DNS record you add to your domain settings. For email certificates, they usually send a confirmation link to the email address in the request. Once you prove ownership, the authority creates your real certificate and sends it back to you.

You then install that certificate on your web server or email client, and it pairs with the private key your device created at the start. The certificate and private key work together: the certificate proves to visitors that you are who you say you are, and the private key proves to your device that you own the certificate.

Why certificate authorities need to verify the request

A certificate request by itself is just a file. Anyone could create one claiming to own google.com or your-bank.com. The whole point of certificate authorities is that they do the verification work so visitors can trust the certificate.

When you visit a website with HTTPS, your browser checks the certificate and sees which certificate authority issued it. Your browser trusts that authority because it is in a list of trusted authorities built into your operating system. If the certificate authority had not verified ownership before issuing the certificate, that trust would mean nothing — a scammer could get a certificate for any domain they wanted.

That is why the verification step is not optional or automatic. The certificate authority has to confirm you control the domain or email address in the request before they will issue a certificate. Different authorities use different verification methods, but they all require some proof.

Certificate requests for different types of security

Website owners create certificate requests when they set up HTTPS. The request includes the domain name (or multiple domain names if the site covers several). The certificate authority verifies the owner controls that domain, then issues a certificate that browsers recognize.

People setting up encrypted email create certificate requests too. The request includes their email address, and the certificate authority sends a verification link to that address. Once confirmed, the person gets a certificate they can use to sign and encrypt email messages.

Developers and system administrators create certificate requests for internal tools, VPN connections, and code signing. The process is the same: create the request, prove ownership or authorization, receive the certificate.

What happens if you lose a certificate request

If you delete a certificate request file after the certificate authority has already issued your certificate, nothing breaks. You have the real certificate now, and that is what matters. The request was just a temporary step in the process.

If you lose the request before the certificate authority issues the certificate, you can create a new one. Your device can generate another certificate request using the same private key. The certificate authority will not care that you submitted a different request file — they only care that you prove ownership of the domain or email again.

The one thing you cannot replace is your private key. If you lose that, you lose the ability to use the certificate at all. You would have to create a new certificate request, go through verification again, and get a new certificate paired with a new private key.

Certificate requests and your security

A certificate request is safe to share. It contains only your public key and the domain or email you want to secure — nothing secret. You send it to the certificate authority, and they might store it in their records. That is fine.

What you must never share is your private key. If someone gets your private key, they can create certificates that impersonate you, decrypt your encrypted messages, or forge your digital signatures. Keep your private key on your device, protected by your operating system's security, and never paste it into a form or email it to anyone.

When you set up a certificate through a hosting provider or email service, they usually handle the certificate request and verification for you. You do not see the .csr file or the private key. The provider keeps the private key secure on their servers. This is fine as long as you trust the provider — they need the private key to use the certificate on your behalf.

Frequently Asked Questions

Can someone use my certificate request to impersonate me?

No. A certificate request by itself does not prove you own anything — it is just a claim. The certificate authority has to verify ownership before issuing a certificate. Even if someone sent a certificate request claiming to be you, the authority would ask for proof of ownership, and the imposter would not have it.

What if I submit a certificate request for the wrong domain by mistake?

The certificate authority will issue a certificate for the domain in the request, not the one you intended. You would need to create a new certificate request with the correct domain and go through verification again. This is why it is important to double-check the domain name before submitting the request.

Do I need to keep the certificate request file after I get my certificate?

No. Once the certificate authority has issued your certificate, you can delete the request file. You only need the certificate itself and your private key. Some people keep the request as a backup record, but it is not necessary for the certificate to work.

Why does my hosting provider ask me to generate a certificate request?

Your hosting provider needs the request to submit to a certificate authority on your behalf. They will handle the verification and installation. You generate the request on your device, send it to them, and they take it from there. This saves you from dealing with the certificate authority directly.

Can I use the same certificate request twice?

Technically yes, but it is not a good idea. Once a certificate authority has issued a certificate for a request, submitting the same request again will just get you another certificate for the same domain. If you need a new certificate later, create a new request instead — it is a simple process and keeps your records clear.