{"id":12083,"date":"2026-07-13T08:45:49","date_gmt":"2026-07-13T06:45:49","guid":{"rendered":"https:\/\/mybox.com\/help\/?post_type=manual_kb&#038;p=12083"},"modified":"2026-07-13T08:45:55","modified_gmt":"2026-07-13T06:45:55","slug":"ce-este-o-inregistrare-caa-si-cum-afecteaza-aceasta-certificatele-ssl","status":"publish","type":"manual_kb","link":"https:\/\/mybox.com\/help\/ro\/knowledgebase\/what-is-a-caa-record-and-how-does-it-affect-ssl-certificates\/","title":{"rendered":"Ce este o \u00eenregistrare CAA \u0219i cum afecteaz\u0103 aceasta certificatele SSL?"},"content":{"rendered":"<div class=\"translation-block translation-block-merged\">\n<p class=\"wp-block-paragraph\">A CAA record is a type of DNS record that tells certificate authorities which organizations are allowed to issue SSL certificates for your domain. It acts as an additional security layer by reducing the risk of unauthorized certificates being created.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Most websites do not require manual CAA configuration. However, incorrect CAA records can prevent new SSL certificates from being issued or renewed, which may cause browsers to display security warnings.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<div id=\"ez-toc-container\" class=\"ez-toc-v2_0_86 ez-toc-wrap-left counter-hierarchy ez-toc-counter ez-toc-custom ez-toc-container-direction\">\n<div class=\"ez-toc-title-container\">\n<p class=\"ez-toc-title\" style=\"cursor:inherit\">Table of Contents<\/p>\n<span class=\"ez-toc-title-toggle\"><\/span><\/div>\n<nav><ul class='ez-toc-list ez-toc-list-level-1' ><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-1\" href=\"https:\/\/mybox.com\/help\/ro\/knowledgebase\/what-is-a-caa-record-and-how-does-it-affect-ssl-certificates\/#What_does_a_CAA_record_do\" >What does a CAA record do?<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-2\" href=\"https:\/\/mybox.com\/help\/ro\/knowledgebase\/what-is-a-caa-record-and-how-does-it-affect-ssl-certificates\/#How_does_a_CAA_record_look\" >How does a CAA record look?<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-3\" href=\"https:\/\/mybox.com\/help\/ro\/knowledgebase\/what-is-a-caa-record-and-how-does-it-affect-ssl-certificates\/#Common_CAA_properties\" >Common CAA properties<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-4\" href=\"https:\/\/mybox.com\/help\/ro\/knowledgebase\/what-is-a-caa-record-and-how-does-it-affect-ssl-certificates\/#How_can_CAA_records_affect_SSL_certificates\" >How can CAA records affect SSL certificates?<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-5\" href=\"https:\/\/mybox.com\/help\/ro\/knowledgebase\/what-is-a-caa-record-and-how-does-it-affect-ssl-certificates\/#Common_situations_where_CAA_records_cause_problems\" >Common situations where CAA records cause problems<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-6\" href=\"https:\/\/mybox.com\/help\/ro\/knowledgebase\/what-is-a-caa-record-and-how-does-it-affect-ssl-certificates\/#How_to_check_whether_your_domain_has_CAA_records\" >How to check whether your domain has CAA records<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-7\" href=\"https:\/\/mybox.com\/help\/ro\/knowledgebase\/what-is-a-caa-record-and-how-does-it-affect-ssl-certificates\/#What_to_expect\" >What to expect<\/a><\/li><\/ul><\/nav><\/div>\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"What_does_a_CAA_record_do\"><\/span>What does a CAA record do?<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<\/div>\n\n<div id=\"mybox-3893917811\" class=\"mybox-content mybox-entity-placement\"><div class=\"early-access-banner-inpost\">\r\n  <div class=\"banner-left-inpost\">\r\n    <div class=\"icon-box-inpost\">\r\n      <img decoding=\"async\" src=\"https:\/\/mybox.com\/help\/wp-content\/uploads\/2026\/02\/square-info-icon.svg\" alt=\"Info\">\r\n    <\/div>\r\n    <div class=\"text-box-inpost\">\r\n      <span class=\"label-inpost\"><span class=\"translation-block translation-block-banner-text\">Acces timpuriu<\/span><\/span>\r\n      <h4><span class=\"translation-block translation-block-banner-text\">Mai ave\u021bi nevoie de ajutor?<\/span><\/h4>\r\n      <p><span class=\"translation-block translation-block-banner-text\">Contacta\u021bi echipa noastr\u0103 de servicii pentru clien\u021bi.<\/span><\/p>\r\n    <\/div>\r\n  <\/div>\r\n\r\n  <div class=\"banner-right-inpost\">\r\n    <a href=\"https:\/\/panel.mybox.com\/helpdesk2\/v\/list\/\" class=\"banner-button-inpost\"><span class=\"translation-block translation-block-banner-text\">Trimite mesaj<\/span><\/a>\r\n  <\/div>\r\n<\/div><\/div>\n\n<div class=\"translation-block translation-block-merged\"><p class=\"wp-block-paragraph\">CAA stands for <strong>Certification Authority Authorization<\/strong>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">When a certificate authority attempts to issue an SSL certificate for your domain, it first checks your DNS records for any CAA restrictions. If a CAA record exists, the certificate authority must follow the rules defined there.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For example, a CAA record can specify:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Which certificate authorities are allowed to issue certificates.<\/li>\n\n\n\n<li>Which certificate authorities are explicitly blocked.<\/li>\n\n\n\n<li>Which email address should receive notifications about certificate-related issues.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">If no CAA record exists, any trusted certificate authority may issue a certificate for the domain.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"How_does_a_CAA_record_look\"><\/span>How does a CAA record look?<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">A CAA record contains three main elements:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>A flag value.<\/li>\n\n\n\n<li>A property.<\/li>\n\n\n\n<li>A value.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">For example:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>example.com.    CAA    0 issue \"letsencrypt.org\"\n<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">This record allows Let&#8217;s Encrypt to issue SSL certificates for the domain.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Another example:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>example.com.    CAA    0 issue \"digicert.com\"\n<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">This record allows DigiCert to issue certificates.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Domains can have multiple CAA records if they use more than one certificate authority.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Common_CAA_properties\"><\/span>Common CAA properties<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The most common properties are:<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th>Property<\/th><th>Purpose<\/th><\/tr><\/thead><tbody><tr><td><code>issue<\/code><\/td><td>Allows a certificate authority to issue standard SSL certificates.<\/td><\/tr><tr><td><code>issuewild<\/code><\/td><td>Allows a certificate authority to issue wildcard certificates.<\/td><\/tr><tr><td><code>iodef<\/code><\/td><td>Defines where certificate-related notifications should be sent.<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">For example:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>example.com.    CAA    0 iodef \"mailto:admin@example.com\"\n<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">This record tells certificate authorities where to send reports about policy violations or certificate requests.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"How_can_CAA_records_affect_SSL_certificates\"><\/span>How can CAA records affect SSL certificates?<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Incorrect CAA records can prevent SSL certificates from being issued or renewed.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This may happen if:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>The record authorizes the wrong certificate authority.<\/li>\n\n\n\n<li>A certificate authority has been removed accidentally.<\/li>\n\n\n\n<li>A wildcard certificate is requested, but <code>issuewild<\/code> is missing.<\/li>\n\n\n\n<li>DNS changes have not yet propagated.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">When this happens, automatic SSL renewal may fail even though the website itself continues to work normally.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Common_situations_where_CAA_records_cause_problems\"><\/span>Common situations where CAA records cause problems<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">CAA records are often reviewed after:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Migrating a website to another hosting provider.<\/li>\n\n\n\n<li>Changing DNS providers.<\/li>\n\n\n\n<li>Switching to a different SSL certificate issuer.<\/li>\n\n\n\n<li>Manually editing DNS records.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">For example, if your DNS zone only authorizes one certificate authority and your hosting provider uses another, SSL issuance may fail until the CAA records are updated.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"How_to_check_whether_your_domain_has_CAA_records\"><\/span>How to check whether your domain has CAA records<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">You can inspect your domain&#8217;s DNS configuration using tools such as:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/mxtoolbox.com\/caa.aspx?utm_source=chatgpt.com\" target=\"_blank\" rel=\"noopener\">MXToolbox CAA Lookup<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/toolbox.googleapps.com\/apps\/dig\/?utm_source=chatgpt.com\" target=\"_blank\" rel=\"noopener\">Google Admin Toolbox Dig<\/a><\/li>\n\n\n\n<li>Command-line tools such as <code>dig<\/code> or <code>nslookup<\/code>.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">If you are unsure which certificate authority your hosting provider uses, contact support before modifying your DNS records.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"What_to_expect\"><\/span>What to expect<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Most websites can use SSL certificates without any manual CAA configuration. However, if your domain has custom CAA records, they must allow the certificate authority used by your hosting provider.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">When troubleshooting SSL issues, checking the domain&#8217;s CAA records can help determine why a certificate cannot be issued or renewed.<\/p>\n<\/div>","protected":false},"author":1,"featured_media":0,"parent":0,"menu_order":0,"template":"","format":"standard","manualknowledgebasecat":[11,28],"manual_kb_tag":[],"class_list":["post-12083","manual_kb","type-manual_kb","status-publish","format-standard","hentry","manualknowledgebasecat-ssl-certificates","manualknowledgebasecat-others"],"_links":{"self":[{"href":"https:\/\/mybox.com\/help\/ro\/wp-json\/wp\/v2\/manual_kb\/12083","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/mybox.com\/help\/ro\/wp-json\/wp\/v2\/manual_kb"}],"about":[{"href":"https:\/\/mybox.com\/help\/ro\/wp-json\/wp\/v2\/types\/manual_kb"}],"author":[{"embeddable":true,"href":"https:\/\/mybox.com\/help\/ro\/wp-json\/wp\/v2\/users\/1"}],"version-history":[{"count":1,"href":"https:\/\/mybox.com\/help\/ro\/wp-json\/wp\/v2\/manual_kb\/12083\/revisions"}],"predecessor-version":[{"id":12084,"href":"https:\/\/mybox.com\/help\/ro\/wp-json\/wp\/v2\/manual_kb\/12083\/revisions\/12084"}],"wp:attachment":[{"href":"https:\/\/mybox.com\/help\/ro\/wp-json\/wp\/v2\/media?parent=12083"}],"wp:term":[{"taxonomy":"manualknowledgebasecat","embeddable":true,"href":"https:\/\/mybox.com\/help\/ro\/wp-json\/wp\/v2\/manualknowledgebasecat?post=12083"},{"taxonomy":"manual_kb_tag","embeddable":true,"href":"https:\/\/mybox.com\/help\/ro\/wp-json\/wp\/v2\/manual_kb_tag?post=12083"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}