XiaTools

How to Check Which Certificate Authorities Can Issue Certificates for a Domain

Updated 10 Oct 2026

Checking which certificate authorities are allowed to issue SSL or TLS certificates for your domain is a critical part of modern web security. A single compromised or rogue certificate authority could potentially issue a trusted certificate for your domain, leading to severe man-in-the-middle attacks. By publishing a Certificate Authority Authorization (CAA) DNS record, you explicitly restrict which organizations can generate cryptographic certificates for your hosts.

To quickly inspect your current DNS configuration, you can use the CAA Lookup tool on XiaTools, which instantly queries your domain name to display all active authorization policies and pin down misconfigurations. Mastering this process ensures complete control over your public-facing encryption assets and protects your domain from unauthorized issuance.

Understanding Certificate Authority Authorization (CAA)

Certificate Authority Authorization is a security mechanism defined in RFC 6844 that allows domain owners to declare which certificate authorities (CAs) are authorized to issue certificates for their domain names. Before a public CA issues any certificate, it is required by industry standards to check the domain's DNS zone for a CAA record. If a restrictive CAA record is found and the requesting CA is not listed, the authority must refuse to issue the certificate.

This protocol prevents unauthorized CAs from issuing certificates due to human error, social engineering, or compromise. Even if an attacker compromises the DNS records of a domain, implementing DNSSEC alongside CAA provides a hardened defense layer, ensuring that validation queries cannot be maliciously spoofed or altered in transit.

How to Check Allowed Certificate Authorities

There are several methods available to check allowed certificate authorities for any domain. You can use specialized web toolkits, command-line utilities, or direct DNS queries to inspect the active records.

Using Online Tools

Online network toolkits provide the fastest way to audit your zone file without memorizing complex command-line syntax. Tools like the XiaTools CAA Lookup utility query global DNS resolvers, parse the returned response bytes, and present human-readable authorization rules alongside formatting warnings.

Using Command-Line DNS Queries

If you prefer working inside a terminal, you can query standard DNS servers using tools such as dig or nslookup. Because CAA is a relatively modern record type, older DNS utilities might display the record as a generic type code (TYPE257) instead of the literal string CAA.

To query a domain's CAA records on Unix-like systems, run the following dig command:

dig example.com CAA +noall +answer

A properly configured domain will return a response similar to this sample output:

example.com.		3600	IN	CAA	0 issue "letsencrypt.org"
example.com.		3600	IN	CAA	0 issuewild ";";
example.com.		3600	IN	CAA	0 iodef "mailto:security@example.com"

On Windows systems, you can use PowerShell to query custom DNS record types, though parsing raw type codes may require extra scripting. For quick lookups, web-based utilities remain the most efficient option.

Structure and Syntax of CAA Records

Writing correct CAA syntax is essential because CAs strictly parse these fields before issuing certificates. A standard CAA record consists of four distinct parts: a flag byte, a tag name, a value string, and standard DNS TTL properties.

Component Description Example Value
Flags An 8-bit integer. Usually set to 0 for non-critical, or 1 for critical. 0
Tag Defines the rule type. Common tags are issue, issuewild, and iodef. issue
Value The domain name of the authorized CA or an instruction modifier. letsencrypt.org
TTL Time-to-live defining how long resolvers cache the record. 3600

Supported Tags Explained

  • issue: Authorizes a specific CA to issue single-domain and multi-domain (SAN) certificates for the specified hostname.
  • issuewild: Authorizes a specific CA to issue wildcard certificates (e.g., *.example.com). If issuewild is omitted, the issue tag governs wildcard issuance depending on the CA's interpretation, but explicitly setting issuewild is strongly recommended for security.
  • iodef: Specifies a URL or email address using mailto: format where CAs can report policy violation requests or suspected certificate issuance attempts.

Step-by-Step: Adding and Verifying CAA Records

Configuring CAA records requires access to your authoritative DNS provider's management console. While exact menu paths vary depending on your provider, the general workflow remains consistent.

  1. Log into your domain registrar or cloud DNS management dashboard.
  2. Navigate to the DNS zone management or DNS records section for your domain (names may differ slightly, such as DNS Manager, Zone Editor, or Name Server Management).
  3. Click Add New Record or the equivalent button.
  4. Select CAA from the record type dropdown list.
  5. Enter the target hostname (leave blank or use @ for the root zone example.com).
  6. Set the flag to 0, choose the tag (issue), and input the domain of your chosen provider (e.g., digicert.com).
  7. Save the record changes and wait for propagation.

Once added, verify the record has propagated globally by running an inspection command:

dig @192.0.2.1 example.com CAA

Common Mistakes and How to Fix Them

Misconfigured CAA records can unintentionally block your own certificate renewals, causing unexpected website downtime when existing certificates expire.

1. Blocking All Issuance Accidentally

If you set an empty issue tag without allowing any vendor, such as 0 issue ";", you block all certificate authorities from generating certificates for your domain. Ensure you list every CA you actively use.

2. Typo in CA Domain Names

CAs strictly match the domain string provided in the issue tag against their own identifier. Writing lets-encrypt.org instead of letsencrypt.org will cause validation to fail silently at the CA level.

3. Forgetting Wildcard Rules

A common assumption is that an issue tag covers wildcard certificates. However, many CAs require an explicit issuewild tag if you plan to generate wildcard certificates for subdomains.

Quick Checklist for Domain CAA Security

  • Identify all third-party vendors and internal services that require automated SSL certificate issuance for your domain.
  • Draft clear CAA rules covering both standard single-domain and wildcard requirements.
  • Publish the CAA records to your primary DNS zone file.
  • Add an iodef reporting email address to catch unauthorized issuance alerts.
  • Verify global propagation using an online lookup tool to ensure zero syntax errors.

Frequently asked questions

What happens if a domain has no CAA records?

If a domain contains no CAA records, any public certificate authority is legally and technically permitted to issue an SSL or TLS certificate for that domain. While convenient, this leaves the domain unprotected against unauthorized or accidental certificate generation by rogue CAs.

Can I authorize multiple certificate authorities for a single domain?

Yes, you can publish multiple CAA records for the same domain name. Simply create a separate CAA record for each authorized certificate authority, and every listed vendor will be permitted to issue certificates for your hosts.

How do I block all certificate authorities from issuing certificates?

You can completely lock down your domain by publishing a restrictive CAA record with a semicolon value, such as `0 issue ";"`. This explicitly tells all certificate authorities that no entity is authorized to generate certificates for the domain.

Do subdomains inherit CAA records from their parent domain?

Yes, CAs follow a climbing algorithm when evaluating CAA records. If a specific subdomain like `blog.example.com` lacks its own CAA records, the validating CA will check the parent domain `example.com` and use those rules.

How long does it take for DNS CAA changes to take effect?

The propagation time depends entirely on the Time-To-Live (TTL) value configured on your DNS records and how aggressively certificate authorities cache DNS queries. Typically, changes take effect anywhere from a few minutes up to a few hours.

Related articles

Free tools