Blog

Web Security articles

DV, OV and EV SSL Certificates: What's the Difference?

SSL certificate types explained: how DV, OV and EV differ in validation, what visitors actually see, and which one your business really needs.

4 min read Web Security

Shop for an SSL certificate and you will quickly meet three acronyms: DV, OV and EV. Prices range from free to several hundred dollars a year, and the marketing can make the expensive options sound essential. In reality, the encryption is identical across all three. The SSL certificate types differ in one thing only: how thoroughly the certificate authority checks who you are before issuing.

What every certificate does, regardless of type

All publicly trusted certificates do the same technical job. They let a browser confirm it is talking to the server that controls the domain, and they enable TLS encryption so nobody in between can read or alter the traffic. A free DV certificate and a premium EV certificate use the same algorithms and key sizes and produce the same padlock-level security for data in transit.

What changes is the identity information baked into the certificate, and the paperwork the certificate authority (CA) does to confirm it.

Domain Validated (DV)

A DV certificate proves only that the applicant controls the domain. The CA checks this automatically, usually in one of three ways:

  • Placing a specific file at a URL on the website (HTTP validation).
  • Adding a specific TXT record to the domain's DNS (DNS validation).
  • Clicking a link sent to an address such as admin@ or webmaster@ the domain (email validation).

Issuance takes seconds to minutes, can be fully automated with the ACME protocol, and is often free. The certificate's subject contains only the domain name; there is no company name in it.

Good for: blogs, brochure sites, internal tools, APIs, and the large majority of business websites.

Organization Validated (OV)

An OV certificate adds a check on the organization behind the domain. As well as domain control, the CA verifies that the business legally exists, typically by consulting government business registers or official records, and confirms the organization's name, locality and country. Those details are written into the certificate's subject fields, where anyone inspecting the certificate can read them.

Issuance usually takes from one to a few business days, depending on how easily the CA can verify your records. It cannot be fully automated the first time, though renewals for an already-verified organization are faster.

Good for: organizations whose customers or partners inspect certificate details, or whose procurement or compliance policies require organization identity in the certificate.

Extended Validation (EV)

EV follows a stricter, standardized vetting process defined by the CA/Browser Forum's EV Guidelines. The CA verifies the organization's legal existence, physical address, operational existence, and that the person requesting the certificate is authorized to do so. This can take several days and requires more documentation.

Years ago, browsers rewarded EV with a green address bar showing the company name. Major browsers removed that display around 2019, after research suggested users did not notice its absence and it could be imitated. Today the company name is visible only if a visitor clicks the padlock and opens the certificate details.

Good for: organizations with a specific regulatory or contractual requirement for EV. For most others, it no longer offers a visible benefit.

SSL certificate types compared

DVOVEV
What is checkedDomain controlDomain + organization existsDomain + detailed legal, physical and operational checks
Typical issuance timeMinutesOne to a few daysSeveral days
Company name in certificateNoYesYes
Shown in address barPadlock onlyPadlock onlyPadlock only
AutomationFully (ACME)PartialPartial
Encryption strengthSameSameSame
CostFree to lowModerateHighest

Validation level is not the same as coverage

A common source of confusion is mixing up validation level with what names the certificate covers. These are separate choices:

  • Single-domain: one name, such as www.example.com (often with the bare example.com included).
  • Wildcard: every first-level subdomain, such as *.example.com.
  • Multi-domain (SAN): a list of specific names, possibly across different domains.

DV and OV certificates are available in all three forms. EV certificates cannot be wildcards under the industry rules, though multi-domain EV is available.

How to see which type a site uses

Click the padlock, open the certificate viewer and look at the Subject. If it shows only CN=example.com, it is DV. If it includes O= (organization), L= (locality) and C= (country), it is OV or EV. EV certificates also include fields such as the business category and registration number. An online tool like our SSL checker shows the issuer and subject details without digging through browser menus.

Which one should you choose?

A simple decision path:

  1. Start with DV. It is free or cheap, renews automatically, and gives visitors exactly the same padlock and encryption.
  2. Choose OV if a client contract, tender or internal policy explicitly asks for organization-validated certificates, or if you want your legal entity name verifiable in the certificate.
  3. Choose EV only if a regulator, payment partner or contract specifically requires it.

Whatever you pick, the bigger security wins are elsewhere: keeping the certificate renewed, serving the full intermediate chain, disabling outdated TLS versions, and adding HTTP security headers (which you can review with an HTTP header checker). A well-configured DV certificate is far more valuable than a neglected EV one.

Key takeaways

  • DV, OV and EV provide identical encryption; they differ only in identity checks.
  • Browsers no longer display EV company names in the address bar.
  • Validation level (DV/OV/EV) and coverage (single, wildcard, SAN) are separate decisions.
  • DV suits most websites; buy OV or EV when a policy or contract requires it.

Need help with this?

Netifi helps businesses around the world with Web Security. Tell us what you are working on.