How to Set Up CAA Records in Gandi Domain Management Interface
Setting up Certificate Authority Authorization (CAA) records in your domain's DNS configuration is a crucial step to prevent unauthorized SSL/TLS certificate issuance for your domain. If you use Gandi for domain registration and DNS management, adding these security records takes only a few minutes through their web interface. Before making any modifications, you can use the CAA Lookup tool on XiaTools to inspect your current DNS state and instantly verify whether your existing CAA configuration is active and correctly parsed.
Understanding CAA Records and DNS Security
A CAA record is a type of Resource Record (RR) in the Domain Name System that allows domain owners to declare which Certificate Authorities (CAs) are authorized to issue digital certificates for their domain names. Since the introduction of baseline requirements by the CA/Browser Forum, all public Certificate Authorities are mandated to check for CAA records before issuing an SSL or TLS certificate. If a CA receives a request to issue a certificate for example.com, but your CAA records explicitly authorize only specific providers—such as Let's Encrypt or DigiCert—any other CA must refuse the request.
Failing to configure CAA records leaves your domain vulnerable to compromised or misbehaving CAs issuing fraudulent certificates without your knowledge. By implementing them, you add an extra layer of defense-in-depth on top of standard public key infrastructure controls.
Structure of a Gandi DNS CAA Record
A standard DNS CAA record consists of three core components: Flags, Tag, and Value.
- Flags: An unsigned integer between 0 and 255. The most common flag is
0, which means non-critical (the CA can ignore unknown tags, though standard tags must be respected). A flag of1indicates a critical record; if a CA does not understand the flag or tag, it must abort certificate issuance. - Tag: The property you wish to control. There are three primary tags defined in the standard:
issue: Authorizes a specific CA to issue any type of certificate (wildcard and non-wildcard).issuewild: Authorizes a specific CA to issue wildcards only. If anissuewildtag is present, it overrides theissuetag for wildcard certificates.iodef: Specifies a URL or email address where CAs can report policy violation incidents.
- Value: The domain name of the authorized Certificate Authority, or a contact URI for the
iodeftag.
Common Record Examples
- Allow only Let's Encrypt for all certificates:
- Flags:
0 - Tag:
issue - Value:
letsencrypt.org
- Flags:
- Explicitly disallow all certificate issuance:
- Flags:
0 - Tag:
issue - Value:
;(a single semicolon denotes a null value, meaning no CA is allowed)
- Flags:
Step-by-Step Instructions to Add CAA Records in Gandi
Gandi provides a clean domain management dashboard where you can manage DNS zones directly. While interface labels may differ slightly depending on whether you use their legacy portal or the newer Domain interface, the core steps remain identical.
- Log into your Gandi account and navigate to the Domain or Domain Management section.
- Click on the domain name (for example,
example.com) for which you want to configure CAA records. - Locate and click on the DNS or DNS Records tab.
- Click on the button to Add a new record or edit the zone file.
- Select CAA from the available record type dropdown menu.
- Fill in the required fields:
- Name / Host: Leave blank or enter
@to apply the record to your root domain (example.com), or enter a subdomain prefix likewwwormailif needed. - TTL: Leave as default (e.g., 10800 or 3600 seconds) or set a custom time-to-live.
- Flags: Enter
0for standard non-critical enforcement. - Tag: Select or type
issue(orissuewild). - Value: Enter the authorized CA domain, such as
letsencrypt.orgorcomodoca.com.
- Name / Host: Leave blank or enter
- Click Save or Add to confirm the record creation.
- Repeat the process if you need to authorize multiple distinct Certificate Authorities or add
issuewildandiodeftags.
Verification and Testing
Once you have successfully added your CAA records to Gandi, you need to verify that they propagate globally and return the expected values. DNS propagation can take anywhere from a few minutes up to a couple of hours depending on TTL values and local caching.
Using Command Line Tools
You can query your domain's CAA records using standard command-line DNS utilities.
Using dig on Linux or macOS:
dig example.com CAA
Sample output:
;; QUESTION SECTION:
;example.com. IN CAA
;; ANSWER SECTION:
example.com. 10800 IN CAA 0 issue "letsencrypt.org"
example.com. 10800 IN CAA 0 issuewild ";"
Using PowerShell on Windows:
Resolve-DnsName -Name example.com -Type CAA
Comparison of DNS Interface Options
| Feature | Gandi Web Interface | Gandi Zone File Import | External DNS Provider |
|---|---|---|---|
| Ease of Use | High, visual dropdowns | Medium, requires text editing | Varies by provider |
| Error Risk | Low, input validation | Moderate, syntax-sensitive | Low to Moderate |
| Speed | Fast for single records | Fast for bulk additions | Varies |
| Flexibility | Good for standard setups | Excellent for automation | High |
Common Mistakes and How to Fix Them
Even experienced engineers occasionally misconfigure DNS records. Keep these common pitfalls in mind when setting up Gandi DNS CAA records:
- Forgetting Wildcard Rules: If you add an
issuetag forletsencrypt.org, it allows wildcards unless you have an explicitissuewildtag pointing elsewhere or blocking them. Always verify how your chosen CA handles wildcard requests. - Incorrect Value Formatting: Gandi's interface generally handles quotes automatically, but if you are editing raw zone files, ensure that CA domain strings inside the value field are enclosed in double quotes, such as
"letsencrypt.org". - Using Empty Values Incorrectly: To completely block all certificate issuance, the value must be a single semicolon (
;). Entering nothing or the wordnonewill cause DNS parsing errors or be ignored by CAs. - Overlooking Subdomains: CAA records do not automatically inherit down to subdomains unless specified, or unless the CA checks parent domains according to RFC 8659 rules. If you issue certificates for
app.example.com, consider setting a specific CAA record for that subdomain or at the apex domain level.
Quick Checklist for Gandi CAA Setup
- Identify which CAs currently issue certificates for your services (web, mail, CDN).
- Determine if you need distinct rules for standard certificates versus wildcard certificates.
- Access the Gandi domain management interface and navigate to DNS settings.
- Create individual CAA records for
issueandissuewildas required. - Validate propagation using command-line tools or online lookup utilities.
- Request a test certificate from your authorized CA to ensure issuance succeeds.