Skip to content
ipaddress.si
CAA

What is a CAA record?

CAA records specify which certificate authorities may issue TLS certificates for a domain. Learn the issue, issuewild and iodef tags.

example.com.   3600   IN   CAA   0 issue "letsencrypt.org"

A CAA record (Certification Authority Authorization, RFC 8659) lists the certificate authorities allowed to issue TLS certificates for a domain. Every public CA must check CAA before issuing; if the records exist and the CA isn’t listed, it must refuse.

Tags

  • issue — CAs allowed to issue certificates for the name.
  • issuewild — CAs allowed to issue wildcard certificates.
  • iodef — where CAs should report rejected requests (mailto: or https:).

CAA is inherited: a record on example.com also covers www.example.com unless the subdomain has its own CAA records. No CAA records at all means any CA may issue.

Frequently asked questions

Do I need a CAA record?
It's optional but recommended: it reduces the risk of a certificate being mis-issued by a CA you don't use.
Why did my certificate renewal fail after adding CAA?
The CA you use isn't listed. Add an issue tag with its identifier, e.g. letsencrypt.org.

DNS record guides