Free Tools

CAA Record Checker

Check a domain

We climb the DNS tree the way a certificate authority does, and show you which name the governing records came from.

What this checks

CAA is the one record here where a typo makes things stricter rather than looser. A value that does not parse is treated as naming nobody, and a record naming nobody forbids every CA from issuing — so a stray https:// stops your renewals rather than being ignored.

The records that govern a name are also, very often, not published at that name. We climb the tree all the way to the root and show you which name the governing records actually came from.

Enter a domain above to see who can currently get a certificate for it, or read about Certificate Transparency monitoring, which is how you find out when one is issued anyway.

Build a record

Pick the certificate authorities you actually use. Everything else has a safe default.

The list above is the CAs people ask for most. Any identifier is accepted — one we do not recognise is reported as such rather than refused.

Publishes issue ";". Wildcards follow it too, because issue governs them when no issuewild record says otherwise.

Leaving this alone is almost always right: no issuewild record is needed, because issue already covers wildcards.

A CA that refuses a request should tell you here. mailto: or https: only — http: is legal and is not expected to work.

issue does not cover either of these. Ticking them publishes issuemail ";" and issuevmc ";".

Pin issuance to one ACME account (RFC 8657)

Narrows issuance from "anyone with an account at this CA" to "this account, by this method". CAs should honour these today and must from 15 March 2027, so check your CA documents support before relying on it. Validation methods apply to every certificate authority selected. The account URI applies only when exactly one is selected: spread across several it would block all but one of them.

example.com.  CAA  0 issue "letsencrypt.org"
example.com.  CAA  0 issue "digicert.com"
example.com.  CAA  0 iodef "mailto:security@example.com"

Narrowed down who can issue? Find out if anyone does it anyway.

CAs are required to check your CAA records and respect them before issuing a certificate, but mistakes happen. Report URI watches the Certificate Transparency logs and alerts you whenever a certificate is issued for your domain, so you can spot one you weren't expecting.