Skip to content

DNS security

CAA checker

Look up a domain's CAA records, which tell certificate authorities whether they may issue certificates for it. The check looks where an authority would, at the name and then its parents, and shows which authorities are allowed, for wildcards too, and where they may report refused requests.

Checked from Ironfang Security's scanner address with the same low-impact limits as a scan. Nothing you enter is kept.

What this checks

What the result means

Before a publicly trusted certificate authority issues a certificate, it must check the domain's CAA records. If records exist and do not name it, it must refuse. With no CAA records at all, any public authority may issue, subject to its usual checks that the requester controls the domain.

A pass means CAA records were found at the name or a parent, and the table shows what they allow. A finding means there are none. It is a low-severity hardening recommendation: many domains have no CAA records, and adding them narrows who can issue rather than fixing a fault.

Before you add or change CAA, find out which authorities issue your current certificates, including any your CDN or hosting provider requests for you. Leave one out and its renewals will fail.

How to fix common issues

No CAA records

Add a CAA record naming the certificate authorities you use, for example example.com. CAA 0 issue "letsencrypt.org". Check which authorities issue your current certificates first, so renewals keep working.

More in the CAA records check reference

Cyber Essentials and ISO 27001

Neither Cyber Essentials nor ISO 27001 names CAA. A CAA record is technical evidence for broader ISO/IEC 27001:2022 Annex A controls: 8.24 Use of cryptography, since certificates are part of how an organisation uses cryptography, and 8.9 Configuration management.

The organisation still has to decide which certificate authorities it uses, who may request certificates, and how the record is updated when a provider changes. The record shows the result of that decision, not the process behind it.

Scope and limitations

Related guides

Questions

What happens if a domain has no CAA records?
Any publicly trusted certificate authority may issue certificates for it, provided the requester passes that authority's checks that they control the domain. CAA narrows that to the authorities you name.
Will adding CAA records affect certificates I already have?
No. Authorities check CAA when they issue, so existing certificates stay valid until they expire. Renewals are checked, so name every authority that issues for you, including any your CDN or hosting provider uses, before you publish the record.
Does a CAA record on my domain cover its subdomains?
Yes, unless a subdomain has CAA records of its own. An authority looks at the name in the certificate first, then at each parent in turn, and uses the first set it finds.
What is the difference between issue and issuewild?
issue names the authorities that may issue certificates for the domain. issuewild, where present, applies to wildcard certificates instead, so you can allow wildcards from fewer authorities, or from none at all.

Related security tools