DNS security
CAA checker
Look up a domain's CAA records, which tell certificate authorities whether they may issue certificates for it. The check looks where an authority would, at the name and then its parents, and shows which authorities are allowed, for wildcards too, and where they may report refused requests.
What this checks
- CAA records at the name you enter, then at each parent name up to the zone apex, stopping at the first that has any (RFC 8659).
- The
issuerecords: the authorities allowed to issue certificates, or;for none. - The
issuewildrecords: the authorities allowed to issue wildcard certificates. - The
iodefrecords: where authorities may report requests that break the policy.
What the result means
Before a publicly trusted certificate authority issues a certificate, it must check the domain's CAA records. If records exist and do not name it, it must refuse. With no CAA records at all, any public authority may issue, subject to its usual checks that the requester controls the domain.
A pass means CAA records were found at the name or a parent, and the table shows what they allow. A finding means there are none. It is a low-severity hardening recommendation: many domains have no CAA records, and adding them narrows who can issue rather than fixing a fault.
Before you add or change CAA, find out which authorities issue your current certificates, including any your CDN or hosting provider requests for you. Leave one out and its renewals will fail.
How to fix common issues
No CAA records
Add a CAA record naming the certificate authorities you use, for example example.com. CAA 0 issue "letsencrypt.org". Check which authorities issue your current certificates first, so renewals keep working.
Cyber Essentials and ISO 27001
Neither Cyber Essentials nor ISO 27001 names CAA. A CAA record is technical evidence for broader ISO/IEC 27001:2022 Annex A controls: 8.24 Use of cryptography, since certificates are part of how an organisation uses cryptography, and 8.9 Configuration management.
The organisation still has to decide which certificate authorities it uses, who may request certificates, and how the record is updated when a provider changes. The record shows the result of that decision, not the process behind it.
Scope and limitations
- It does not compare the records with the authority that issued your current certificate; the certificate checker shows the issuer.
- An authority checks CAA when it issues. CAA does not affect certificates already issued, and it cannot stop an authority that ignores it.
- Names below the one you enter can have CAA records of their own, which apply to them instead; enter a subdomain to check its set.
- Tags other than
issue,issuewildandiodef, and parameters after an authority name, are shown but not judged.
Related guides
Questions
- What happens if a domain has no CAA records?
- Any publicly trusted certificate authority may issue certificates for it, provided the requester passes that authority's checks that they control the domain. CAA narrows that to the authorities you name.
- Will adding CAA records affect certificates I already have?
- No. Authorities check CAA when they issue, so existing certificates stay valid until they expire. Renewals are checked, so name every authority that issues for you, including any your CDN or hosting provider uses, before you publish the record.
- Does a CAA record on my domain cover its subdomains?
- Yes, unless a subdomain has CAA records of its own. An authority looks at the name in the certificate first, then at each parent in turn, and uses the first set it finds.
- What is the difference between issue and issuewild?
- issue names the authorities that may issue certificates for the domain. issuewild, where present, applies to wildcard certificates instead, so you can allow wildcards from fewer authorities, or from none at all.
Related security tools
- Certificate checker - Read a site's TLS certificate: the names it covers, its issuer, validity and trust.
- Subdomain finder - Find a domain's subdomains in public certificate transparency logs.
- SSL/TLS checker - Check a site's HTTPS, certificate, expiry, TLS versions and weak cipher suites.
- DNS security checker - Check a domain's address records, nameserver redundancy, CAA, DNSSEC and dangling CNAMEs.

