We climb the DNS tree the way a certificate authority does, and show you which name the governing records came from.
CAA is the one record here where a typo makes things stricter rather than looser. A value
that does not parse is treated as naming nobody, and a record naming nobody forbids every
CA from issuing — so a stray https:// stops your renewals rather than
being ignored.
The records that govern a name are also, very often, not published at that name. We climb the tree all the way to the root and show you which name the governing records actually came from.
Enter a domain above to see who can currently get a certificate for it, or read about Certificate Transparency monitoring, which is how you find out when one is issued anyway.
Pick the certificate authorities you actually use. Everything else has a safe default.
example.com. CAA 0 issue "letsencrypt.org" example.com. CAA 0 issue "digicert.com" example.com. CAA 0 iodef "mailto:security@example.com"
CAs are required to check your CAA records and respect them before issuing a certificate, but mistakes happen. Report URI watches the Certificate Transparency logs and alerts you whenever a certificate is issued for your domain, so you can spot one you weren't expecting.