CAA Record Generator

Choose which certificate authorities may issue SSL certificates for your domain. We check your live certificate so the record can't lock out the CA that renews it.

Build your records

Certificate authorities allowed to issue
Wildcard certificates (*.domain)

A CAA record lists the certificate authorities that are allowed to issue SSL/TLS certificates for your domain. Every public CA must check it before issuing. If a CA is not on the list, it has to refuse, even if someone passes its domain validation.

That makes CAA a cheap way to shrink the number of organisations that could ever issue a certificate for your site. It also makes it easy to break your own renewals, which is why this generator reads your live certificate first and refuses to let you leave out the CA that issued it.

What CAA protects against

There are dozens of trusted certificate authorities, and by default any of them can issue a certificate for any domain once the requester proves control of it. CAA (RFC 8659) narrows that to the CAs you name. CAs have been required to check CAA before issuing since September 2017.

It does not stop an attacker who already controls your DNS or your website, because they could change the record or pass validation with your chosen CA. What it does stop is mis-issuance by a CA you never use, whether through a validation mistake there or an attacker exploiting a weaker process at that CA.

The mistake that breaks renewals

The classic CAA outage goes like this: someone adds a record listing the CA they think they use, the certificate keeps working for weeks, and then the automatic renewal fails because the certificate actually comes from somebody else. Hosting platforms, CDNs and website builders often obtain certificates for you from a CA you never chose.

Enter your domain above and the generator connects to it, reads the certificate being served right now, and identifies the issuer. If that CA is missing from your selection it shows an error rather than a record. If you use more than one platform (a CDN for the website and a different service for a subdomain, for example), check each hostname.

How CAA is inherited

CAs look for CAA records on the exact name being certified first, then climb towards the root of the domain. A certificate for shop.example.com is governed by a CAA record on shop.example.com if one exists, otherwise by the one on example.com. So one record at the top of your domain usually covers everything, and a subdomain served by a different provider can be given its own record.

If no CAA record exists anywhere up the tree, any CA may issue. That is the default state for most domains, and it is not dangerous in itself; CAA is an extra layer, not a fix for something broken.

issue, issuewild and iodef

An issue record names a CA allowed to issue normal certificates, one record per CA. An issuewild record controls wildcard certificates (*.example.com) separately; if there is none, wildcards follow the issue records. issuewild ";" forbids wildcards from every CA.

iodef gives CAs an address to report refused requests to. Support for actually sending those reports varies between CAs, so treat it as a nice-to-have rather than a monitoring system.

An issue ";" record with no CA forbids all issuance, which is right only for a domain that should never have a certificate.

If you use Cloudflare or another CDN

Platforms that issue certificates for you often use several CAs and switch between them. Cloudflare, for example, automatically adds the CAA records its own certificates need when you publish any CAA record on a domain it serves. Check your provider's documentation before publishing, and recheck with this tool after your next renewal.

Frequently asked questions