CAA Record Checker
See which certificate authorities are allowed to issue SSL/TLS certificates for a domain, and whether the CAA records are valid.
How it works
A CAA (Certification Authority Authorization) record lets a domain owner name the companies allowed to issue SSL/TLS certificates for it. Before issuing, every public certificate authority must look up CAA and refuse if it is not on the list. It is a cheap safeguard against a certificate being issued by mistake or by an attacker who tricked a CA.
The lookup climbs the DNS tree: if www.example.com has no CAA records, the check continues with example.com. This tool does the same, then validates every record and names the CAs it recognises.
| Tag | Meaning |
|---|---|
issue | A CA allowed to issue normal certificates. ";" alone forbids all. |
issuewild | A CA allowed to issue wildcard (*.) certificates. |
iodef | Where a CA can report a refused request (mailto: or https:). |
flags 128 | Critical: a CA that does not understand the tag must refuse. |
After changing CAA, check your certificate details with the SSL Certificate Checker, and the raw records with the DNS Lookup Tool.
Frequently asked
Do I need a CAA record?
No. Without one, any public CA may issue for your domain. Adding one is optional hardening, and it is most useful if you want to be sure only your chosen CA can issue.
Can a CAA record break my HTTPS?
Yes, if it lists the wrong CA. Certificate renewals from a CA that is not listed will fail. Before publishing, make sure your current CA (and any CDN or host that issues certificates for you, such as a managed hosting provider) is included.
Does CAA affect certificates that already exist?
No. It is only checked at the moment a CA issues or renews a certificate. Existing certificates keep working until they expire.
What is the difference between issue and issuewild?
issue controls normal certificates and, if there is no issuewild record, wildcard ones too. Add issuewild when you want a different rule for wildcards, or ";" to forbid them.
Why does it show records from a parent domain?
CAA is inherited. If a subdomain has none, CAs use the nearest parent domain that does. Publish CAA on a subdomain only when it needs different rules.