CAA Record Checker

Requires server processing Network

Enter a domain to see its CAA records, which certificate authorities they allow, whether wildcard certificates are restricted, and where violation reports go.

Subdomains inherit CAA records from their parent domain, so you can check either.

Overview

Certification Authority Authorization (CAA) records are DNS records that name the certificate authorities allowed to issue certificates for your domain. Every public CA must check them before issuing, so a correct CAA record stops an attacker from getting a certificate for your site from a CA you don’t use.

CAA records are inherited: if www.example.com has none, the records on example.com apply. This checker walks up the domain the same way a CA does and shows which set applies and where it came from. It lists the CAs allowed to issue normal and wildcard certificates, flags records that forbid issuance entirely, and shows whether an iodef address is set for violation reports.

Before adding or changing CAA records, make sure every CA you rely on is listed, including the ones your hosting or CDN provider uses on your behalf. Otherwise certificate renewals will start failing.

Examples & Sample Data

Single CA

Input
google.com
Output
Pass: CAs allowed to issue certificates: Google Trust Services (pki.goog)

No records

Input
example.com
Output
Warning: No CAA records. Any certificate authority can issue certificates for example.com.

How It Works

  1. Enter a domain or subdomain.
  2. The checker queries CAA records for the name, then for each parent domain until it finds a set, exactly as certificate authorities do.
  3. It groups the issue, issuewild, and iodef records and recognizes common CA identifiers such as letsencrypt.org and pki.goog.
  4. Each finding is marked as a pass, warning, or problem, with the raw records listed below.

Common Use Cases

Locking down certificate issuance

Confirm that only your chosen CAs can issue certificates after adding CAA records.

Debugging failed certificate renewals

Find out whether a CAA record is blocking a CA such as Let’s Encrypt from renewing a certificate.

Security audits

Check CAA coverage across your domains and subdomains as part of a DNS security review.

Tips & Best Practices

  • Cloudflare, AWS, and other providers issue certificates through specific CAs. Add every one they use, or renewals can fail.
  • Add an issuewild record to control wildcard certificates separately, for example allowing them from only one CA.
  • Set an iodef record, such as mailto:[email protected], so CAs can tell you about refused requests.

Frequently Asked Questions

Any publicly trusted certificate authority may issue certificates for it. CAA records are optional, but adding them limits issuance to the CAs you actually use.

No. A subdomain without CAA records inherits the records of the nearest parent domain that has them. Add records to a subdomain only when it needs different rules.

An issue record with an empty value, written as a semicolon, forbids every CA from issuing certificates for that name. It’s used for domains that should never have certificates.

No. CAs check CAA only when issuing or renewing, so existing certificates keep working until they expire.

Related Tools

Explore more high-performance utilities.