Choose which certificate authorities may issue SSL certificates for your domain. We check your live certificate so the record can't lock out the CA that renews it.
A CAA record lists the certificate authorities that are allowed to issue SSL/TLS certificates for your domain. Every public CA must check it before issuing. If a CA is not on the list, it has to refuse, even if someone passes its domain validation.
That makes CAA a cheap way to shrink the number of organisations that could ever issue a certificate for your site. It also makes it easy to break your own renewals, which is why this generator reads your live certificate first and refuses to let you leave out the CA that issued it.
There are dozens of trusted certificate authorities, and by default any of them can issue a certificate for any domain once the requester proves control of it. CAA (RFC 8659) narrows that to the CAs you name. CAs have been required to check CAA before issuing since September 2017.
It does not stop an attacker who already controls your DNS or your website, because they could change the record or pass validation with your chosen CA. What it does stop is mis-issuance by a CA you never use, whether through a validation mistake there or an attacker exploiting a weaker process at that CA.
The classic CAA outage goes like this: someone adds a record listing the CA they think they use, the certificate keeps working for weeks, and then the automatic renewal fails because the certificate actually comes from somebody else. Hosting platforms, CDNs and website builders often obtain certificates for you from a CA you never chose.
Enter your domain above and the generator connects to it, reads the certificate being served right now, and identifies the issuer. If that CA is missing from your selection it shows an error rather than a record. If you use more than one platform (a CDN for the website and a different service for a subdomain, for example), check each hostname.
CAs look for CAA records on the exact name being certified first, then climb towards the root of the domain. A certificate for shop.example.com is governed by a CAA record on shop.example.com if one exists, otherwise by the one on example.com. So one record at the top of your domain usually covers everything, and a subdomain served by a different provider can be given its own record.
If no CAA record exists anywhere up the tree, any CA may issue. That is the default state for most domains, and it is not dangerous in itself; CAA is an extra layer, not a fix for something broken.
An issue record names a CA allowed to issue normal certificates, one record per CA. An issuewild record controls wildcard certificates (*.example.com) separately; if there is none, wildcards follow the issue records. issuewild ";" forbids wildcards from every CA.
iodef gives CAs an address to report refused requests to. Support for actually sending those reports varies between CAs, so treat it as a nice-to-have rather than a monitoring system.
An issue ";" record with no CA forbids all issuance, which is right only for a domain that should never have a certificate.
Platforms that issue certificates for you often use several CAs and switch between them. Cloudflare, for example, automatically adds the CAA records its own certificates need when you publish any CAA record on a domain it serves. Check your provider's documentation before publishing, and recheck with this tool after your next renewal.
No, it is optional. Without one, any public CA may issue for your domain, which is how most of the web works. A CAA record is a worthwhile extra layer once you know exactly which CAs your certificates come from.
Not directly, because existing certificates keep working. It can break your next renewal if the CA that issues your certificate is not listed, which is why this tool checks your live certificate before giving you a record.
letsencrypt.org. Google Trust Services uses pki.goog, DigiCert uses digicert.com, Sectigo (including ZeroSSL) uses sectigo.com, and Amazon's certificate manager accepts amazon.com.
Yes. CAs look for a record on the exact name first and then walk up the domain, so a record on example.com covers www.example.com and every other subdomain that does not have its own.
It is the flags field. 0 is normal. 128 marks a tag as critical, meaning a CA that does not understand the tag must refuse to issue. You only need it for advanced tags, so leave it at 0.