How to Check Which Certificate Authorities Can Issue Certificates for a Domain
Checking which certificate authorities are allowed to issue SSL or TLS certificates for your domain is a critical part of modern web security. A single compromised or rogue certificate authority could potentially issue a trusted certificate for your domain, leading to severe man-in-the-middle attacks. By publishing a Certificate Authority Authorization (CAA) DNS record, you explicitly restrict which organizations can generate cryptographic certificates for your hosts.
To quickly inspect your current DNS configuration, you can use the CAA Lookup tool on XiaTools, which instantly queries your domain name to display all active authorization policies and pin down misconfigurations. Mastering this process ensures complete control over your public-facing encryption assets and protects your domain from unauthorized issuance.
Understanding Certificate Authority Authorization (CAA)
Certificate Authority Authorization is a security mechanism defined in RFC 6844 that allows domain owners to declare which certificate authorities (CAs) are authorized to issue certificates for their domain names. Before a public CA issues any certificate, it is required by industry standards to check the domain's DNS zone for a CAA record. If a restrictive CAA record is found and the requesting CA is not listed, the authority must refuse to issue the certificate.
This protocol prevents unauthorized CAs from issuing certificates due to human error, social engineering, or compromise. Even if an attacker compromises the DNS records of a domain, implementing DNSSEC alongside CAA provides a hardened defense layer, ensuring that validation queries cannot be maliciously spoofed or altered in transit.
How to Check Allowed Certificate Authorities
There are several methods available to check allowed certificate authorities for any domain. You can use specialized web toolkits, command-line utilities, or direct DNS queries to inspect the active records.
Using Online Tools
Online network toolkits provide the fastest way to audit your zone file without memorizing complex command-line syntax. Tools like the XiaTools CAA Lookup utility query global DNS resolvers, parse the returned response bytes, and present human-readable authorization rules alongside formatting warnings.
Using Command-Line DNS Queries
If you prefer working inside a terminal, you can query standard DNS servers using tools such as dig or nslookup. Because CAA is a relatively modern record type, older DNS utilities might display the record as a generic type code (TYPE257) instead of the literal string CAA.
To query a domain's CAA records on Unix-like systems, run the following dig command:
dig example.com CAA +noall +answer
A properly configured domain will return a response similar to this sample output:
example.com. 3600 IN CAA 0 issue "letsencrypt.org"
example.com. 3600 IN CAA 0 issuewild ";";
example.com. 3600 IN CAA 0 iodef "mailto:security@example.com"
On Windows systems, you can use PowerShell to query custom DNS record types, though parsing raw type codes may require extra scripting. For quick lookups, web-based utilities remain the most efficient option.
Structure and Syntax of CAA Records
Writing correct CAA syntax is essential because CAs strictly parse these fields before issuing certificates. A standard CAA record consists of four distinct parts: a flag byte, a tag name, a value string, and standard DNS TTL properties.
| Component | Description | Example Value |
|---|---|---|
| Flags | An 8-bit integer. Usually set to 0 for non-critical, or 1 for critical. |
0 |
| Tag | Defines the rule type. Common tags are issue, issuewild, and iodef. |
issue |
| Value | The domain name of the authorized CA or an instruction modifier. | letsencrypt.org |
| TTL | Time-to-live defining how long resolvers cache the record. | 3600 |
Supported Tags Explained
issue: Authorizes a specific CA to issue single-domain and multi-domain (SAN) certificates for the specified hostname.issuewild: Authorizes a specific CA to issue wildcard certificates (e.g.,*.example.com). Ifissuewildis omitted, theissuetag governs wildcard issuance depending on the CA's interpretation, but explicitly settingissuewildis strongly recommended for security.iodef: Specifies a URL or email address usingmailto:format where CAs can report policy violation requests or suspected certificate issuance attempts.
Step-by-Step: Adding and Verifying CAA Records
Configuring CAA records requires access to your authoritative DNS provider's management console. While exact menu paths vary depending on your provider, the general workflow remains consistent.
- Log into your domain registrar or cloud DNS management dashboard.
- Navigate to the DNS zone management or DNS records section for your domain (names may differ slightly, such as DNS Manager, Zone Editor, or Name Server Management).
- Click Add New Record or the equivalent button.
- Select CAA from the record type dropdown list.
- Enter the target hostname (leave blank or use
@for the root zoneexample.com). - Set the flag to
0, choose the tag (issue), and input the domain of your chosen provider (e.g.,digicert.com). - Save the record changes and wait for propagation.
Once added, verify the record has propagated globally by running an inspection command:
dig @192.0.2.1 example.com CAA
Common Mistakes and How to Fix Them
Misconfigured CAA records can unintentionally block your own certificate renewals, causing unexpected website downtime when existing certificates expire.
1. Blocking All Issuance Accidentally
If you set an empty issue tag without allowing any vendor, such as 0 issue ";", you block all certificate authorities from generating certificates for your domain. Ensure you list every CA you actively use.
2. Typo in CA Domain Names
CAs strictly match the domain string provided in the issue tag against their own identifier. Writing lets-encrypt.org instead of letsencrypt.org will cause validation to fail silently at the CA level.
3. Forgetting Wildcard Rules
A common assumption is that an issue tag covers wildcard certificates. However, many CAs require an explicit issuewild tag if you plan to generate wildcard certificates for subdomains.
Quick Checklist for Domain CAA Security
- Identify all third-party vendors and internal services that require automated SSL certificate issuance for your domain.
- Draft clear CAA rules covering both standard single-domain and wildcard requirements.
- Publish the CAA records to your primary DNS zone file.
- Add an
iodefreporting email address to catch unauthorized issuance alerts. - Verify global propagation using an online lookup tool to ensure zero syntax errors.