See which certificate authorities are allowed to issue SSL certificates for a domain.
Enter a domain to look up its CAA records.
A CAA (Certification Authority Authorization) record lists which certificate authorities are permitted to issue SSL/TLS certificates for your domain. CAs are required to check it before issuing.
CAA records are a strong defence against mis-issuance: if an attacker tries to obtain a certificate from a CA you have not authorised, the CAA record blocks it. This tool shows your domain's CAA policy.
It is optional but recommended. Without one, any public CA may issue certificates for your domain. A CAA record restricts issuance to CAs you trust, reducing the risk of fraudulent certificates.
The issue tag authorises a CA to issue standard certificates, issuewild covers wildcard certificates, and iodef gives a contact address for CAs to report policy violations.
No. CAA is only checked at issuance time. Existing certificates continue to work. Just make sure your record authorises the CA you plan to renew with.
Every one runs a real check, live, with nothing to install.
A one-off check is useful, but PulseStack repeats it every minute and alerts you the moment something changes. Start free with 5 monitors, no card required.