A CAA record is a type of DNS record that tells certificate authorities which organizations are allowed to issue SSL certificates for your domain. It acts as an additional security layer by reducing the risk of unauthorized certificates being created.
Most websites do not require manual CAA configuration. However, incorrect CAA records can prevent new SSL certificates from being issued or renewed, which may cause browsers to display security warnings.
Table of Contents
What does a CAA record do?
CAA stands for Certification Authority Authorization.
When a certificate authority attempts to issue an SSL certificate for your domain, it first checks your DNS records for any CAA restrictions. If a CAA record exists, the certificate authority must follow the rules defined there.
For example, a CAA record can specify:
- Which certificate authorities are allowed to issue certificates.
- Which certificate authorities are explicitly blocked.
- Which email address should receive notifications about certificate-related issues.
If no CAA record exists, any trusted certificate authority may issue a certificate for the domain.
How does a CAA record look?
A CAA record contains three main elements:
- A flag value.
- A property.
- A value.
For example:
example.com. CAA 0 issue "letsencrypt.org"
This record allows Let’s Encrypt to issue SSL certificates for the domain.
Another example:
example.com. CAA 0 issue "digicert.com"
This record allows DigiCert to issue certificates.
Domains can have multiple CAA records if they use more than one certificate authority.
Common CAA properties
The most common properties are:
| Property | Purpose |
|---|---|
issue | Allows a certificate authority to issue standard SSL certificates. |
issuewild | Allows a certificate authority to issue wildcard certificates. |
iodef | Defines where certificate-related notifications should be sent. |
For example:
example.com. CAA 0 iodef "mailto:[email protected]"
This record tells certificate authorities where to send reports about policy violations or certificate requests.
How can CAA records affect SSL certificates?
Incorrect CAA records can prevent SSL certificates from being issued or renewed.
This may happen if:
- The record authorizes the wrong certificate authority.
- A certificate authority has been removed accidentally.
- A wildcard certificate is requested, but
issuewildis missing. - DNS changes have not yet propagated.
When this happens, automatic SSL renewal may fail even though the website itself continues to work normally.
Common situations where CAA records cause problems
CAA records are often reviewed after:
- Migrating a website to another hosting provider.
- Changing DNS providers.
- Switching to a different SSL certificate issuer.
- Manually editing DNS records.
For example, if your DNS zone only authorizes one certificate authority and your hosting provider uses another, SSL issuance may fail until the CAA records are updated.
How to check whether your domain has CAA records
You can inspect your domain’s DNS configuration using tools such as:
- MXToolbox CAA Lookup
- Google Admin Toolbox Dig
- Command-line tools such as
digornslookup.
If you are unsure which certificate authority your hosting provider uses, contact support before modifying your DNS records.
What to expect
Most websites can use SSL certificates without any manual CAA configuration. However, if your domain has custom CAA records, they must allow the certificate authority used by your hosting provider.
When troubleshooting SSL issues, checking the domain’s CAA records can help determine why a certificate cannot be issued or renewed.