XiaTools

How to Set Up CAA Records in Gandi Domain Management Interface

Updated 10 Oct 2026

Setting up Certificate Authority Authorization (CAA) records in your domain's DNS configuration is a crucial step to prevent unauthorized SSL/TLS certificate issuance for your domain. If you use Gandi for domain registration and DNS management, adding these security records takes only a few minutes through their web interface. Before making any modifications, you can use the CAA Lookup tool on XiaTools to inspect your current DNS state and instantly verify whether your existing CAA configuration is active and correctly parsed.

Understanding CAA Records and DNS Security

A CAA record is a type of Resource Record (RR) in the Domain Name System that allows domain owners to declare which Certificate Authorities (CAs) are authorized to issue digital certificates for their domain names. Since the introduction of baseline requirements by the CA/Browser Forum, all public Certificate Authorities are mandated to check for CAA records before issuing an SSL or TLS certificate. If a CA receives a request to issue a certificate for example.com, but your CAA records explicitly authorize only specific providers—such as Let's Encrypt or DigiCert—any other CA must refuse the request.

Failing to configure CAA records leaves your domain vulnerable to compromised or misbehaving CAs issuing fraudulent certificates without your knowledge. By implementing them, you add an extra layer of defense-in-depth on top of standard public key infrastructure controls.

Structure of a Gandi DNS CAA Record

A standard DNS CAA record consists of three core components: Flags, Tag, and Value.

  • Flags: An unsigned integer between 0 and 255. The most common flag is 0, which means non-critical (the CA can ignore unknown tags, though standard tags must be respected). A flag of 1 indicates a critical record; if a CA does not understand the flag or tag, it must abort certificate issuance.
  • Tag: The property you wish to control. There are three primary tags defined in the standard:
    • issue: Authorizes a specific CA to issue any type of certificate (wildcard and non-wildcard).
    • issuewild: Authorizes a specific CA to issue wildcards only. If an issuewild tag is present, it overrides the issue tag for wildcard certificates.
    • iodef: Specifies a URL or email address where CAs can report policy violation incidents.
  • Value: The domain name of the authorized Certificate Authority, or a contact URI for the iodef tag.

Common Record Examples

  • Allow only Let's Encrypt for all certificates:
    • Flags: 0
    • Tag: issue
    • Value: letsencrypt.org
  • Explicitly disallow all certificate issuance:
    • Flags: 0
    • Tag: issue
    • Value: ; (a single semicolon denotes a null value, meaning no CA is allowed)

Step-by-Step Instructions to Add CAA Records in Gandi

Gandi provides a clean domain management dashboard where you can manage DNS zones directly. While interface labels may differ slightly depending on whether you use their legacy portal or the newer Domain interface, the core steps remain identical.

  1. Log into your Gandi account and navigate to the Domain or Domain Management section.
  2. Click on the domain name (for example, example.com) for which you want to configure CAA records.
  3. Locate and click on the DNS or DNS Records tab.
  4. Click on the button to Add a new record or edit the zone file.
  5. Select CAA from the available record type dropdown menu.
  6. Fill in the required fields:
    • Name / Host: Leave blank or enter @ to apply the record to your root domain (example.com), or enter a subdomain prefix like www or mail if needed.
    • TTL: Leave as default (e.g., 10800 or 3600 seconds) or set a custom time-to-live.
    • Flags: Enter 0 for standard non-critical enforcement.
    • Tag: Select or type issue (or issuewild).
    • Value: Enter the authorized CA domain, such as letsencrypt.org or comodoca.com.
  7. Click Save or Add to confirm the record creation.
  8. Repeat the process if you need to authorize multiple distinct Certificate Authorities or add issuewild and iodef tags.

Verification and Testing

Once you have successfully added your CAA records to Gandi, you need to verify that they propagate globally and return the expected values. DNS propagation can take anywhere from a few minutes up to a couple of hours depending on TTL values and local caching.

Using Command Line Tools

You can query your domain's CAA records using standard command-line DNS utilities.

Using dig on Linux or macOS:

dig example.com CAA

Sample output:

;; QUESTION SECTION:
;example.com.			IN	CAA

;; ANSWER SECTION:
example.com.		10800	IN	CAA	0 issue "letsencrypt.org"
example.com.		10800	IN	CAA	0 issuewild ";"

Using PowerShell on Windows:

Resolve-DnsName -Name example.com -Type CAA

Comparison of DNS Interface Options

Feature Gandi Web Interface Gandi Zone File Import External DNS Provider
Ease of Use High, visual dropdowns Medium, requires text editing Varies by provider
Error Risk Low, input validation Moderate, syntax-sensitive Low to Moderate
Speed Fast for single records Fast for bulk additions Varies
Flexibility Good for standard setups Excellent for automation High

Common Mistakes and How to Fix Them

Even experienced engineers occasionally misconfigure DNS records. Keep these common pitfalls in mind when setting up Gandi DNS CAA records:

  • Forgetting Wildcard Rules: If you add an issue tag for letsencrypt.org, it allows wildcards unless you have an explicit issuewild tag pointing elsewhere or blocking them. Always verify how your chosen CA handles wildcard requests.
  • Incorrect Value Formatting: Gandi's interface generally handles quotes automatically, but if you are editing raw zone files, ensure that CA domain strings inside the value field are enclosed in double quotes, such as "letsencrypt.org".
  • Using Empty Values Incorrectly: To completely block all certificate issuance, the value must be a single semicolon (;). Entering nothing or the word none will cause DNS parsing errors or be ignored by CAs.
  • Overlooking Subdomains: CAA records do not automatically inherit down to subdomains unless specified, or unless the CA checks parent domains according to RFC 8659 rules. If you issue certificates for app.example.com, consider setting a specific CAA record for that subdomain or at the apex domain level.

Quick Checklist for Gandi CAA Setup

  • Identify which CAs currently issue certificates for your services (web, mail, CDN).
  • Determine if you need distinct rules for standard certificates versus wildcard certificates.
  • Access the Gandi domain management interface and navigate to DNS settings.
  • Create individual CAA records for issue and issuewild as required.
  • Validate propagation using command-line tools or online lookup utilities.
  • Request a test certificate from your authorized CA to ensure issuance succeeds.

Frequently asked questions

What happens if I don't set up CAA records on Gandi?

If no CAA records are present, any public Certificate Authority is permitted to issue an SSL or TLS certificate for your domain upon request. While this is the default state for most domains, adding CAA records locks down authorization to only your trusted vendors.

Can I authorize multiple Certificate Authorities in Gandi?

Yes. You can create multiple separate CAA records within your Gandi DNS zone file. For example, you can create one record for Let's Encrypt and a second record for DigiCert, and CAs will respect both authorizations.

What is the difference between issue and issuewild tags?

The issue tag controls whether a CA can issue standard certificates as well as wildcard certificates, unless overridden. The issuewild tag specifically controls wildcard certificate issuance, allowing you to restrict wildcard creation to a different CA than your standard certificates.

How long does it take for Gandi CAA changes to take effect?

DNS changes on Gandi typically propagate within a few minutes, but global propagation can take up to the TTL (Time to Live) duration configured on your zone, which is often set between 1 and 3 hours.

How do I completely block all certificate issuance for my domain?

To prevent any Certificate Authority from issuing a certificate for your domain, create a CAA record with the flag set to 0, the tag set to issue, and the value set to a single semicolon (;).

Related articles

Free tools