How to Set Up CAA Records in Ionos by 1&1 Control Panel
Configuring a Certification Authority Authorization (CAA) record in your Ionos control panel is a vital step in securing your domain against unauthorized SSL/TLS certificate issuance. A CAA record tells Certificate Authorities (CAs) which organizations are permitted to issue digital certificates for your domain name, acting as a strict whitelist for website security.
Before you make any changes to your zone file, it is always a best practice to check your current setup using the CAA Lookup tool on XiaTools to see if any policies or default entries already exist.
Understanding CAA Records and DNS Syntax
A CAA record consists of three main components: flags, tags, and values. Understanding how these pieces fit together ensures your domain remains accessible while blocking rogue certificate requests from unwanted CAs.
Core Components of a CAA Record
- Flags: An unsigned integer between 0 and 255. Typically, this is set to
0for standard issuance policies. A flag of1(often called critical) means that any CA that does not understand the specified tag must refuse to issue a certificate. - Tags: The property you want to control. The standard tags are:
issue: Authorizes a specific CA to issue any type of certificate (wildcard or standard) for your domain.issuewild: Authorizes a specific CA to issue wildcard certificates only. If omitted, the2tag rules apply.iodef: Specifies a URL or email address where CAs can report policy violation incidents.
- Values: The domain name of the authorized Certificate Authority (such as
letsencrypt.org,digicert.com, orcomodo.com), or a reporting URI for theiodeftag.
Exact Record Syntax for Zone Files
If you were exporting or importing a standard zone file, a typical CAA record targeting example.com looks like this:
example.com. IN CAA 0 issue "letsencrypt.org"
example.com. IN CAA 0 issuewild ";"
example.com. IN CAA 0 iodef "mailto:security@example.com"
Setting issuewild to ";" is a common hardening technique that explicitly forbids any CA from issuing wildcard certificates for your domain, even if standard certificates are allowed.
Step-by-Step Ionos CAA Record Configuration
Adding a CAA record in the Ionos control panel is straightforward, provided you know where to navigate within their modernized interface. Keep in mind that hosting provider menu paths can occasionally change and label names may differ slightly depending on your account region.
Step 1: Access Your Ionos Account
- Open your web browser and navigate to the official Ionos login page.
- Log in using your credentials, Customer ID, or email address.
- Once authenticated, locate and open the Domains & SSL section from the primary dashboard or product list.
Step 2: Open the DNS Settings
- Find the specific domain name (e.g.,
example.com) for which you want to configure CAA records. - Click on the gear icon or the Actions menu next to the domain.
- Select DNS or Manage DNS from the drop-down options to open the comprehensive DNS record management table.
Step 3: Add a New Record
- Look for a button labeled Add Record or Create Record usually positioned at the top of the DNS table.
- From the list of available record types (such as A, AAAA, CNAME, TXT), select CAA.
Step 4: Fill in the Record Parameters
Complete the configuration fields using your specific provider details. For example, if you are authorizing Let's Encrypt for example.com and 2001:db8::/32 hosted resources, enter the following:
- Host / Name: Leave blank or enter
@to apply the record to the root domain (example.com). You can also input a subdomain likewwwif needed. - Flag: Enter
0for standard non-critical authorization. - Tag: Select
issuefrom the drop-down menu. - Value / CA Domain: Enter
letsencrypt.org. - TTL (Time to Live): Choose a standard duration such as
1 hourorDefault.
Click Save or Submit to commit the changes to your DNS zone.
Verifying Your Ionos CAA Record Configuration
DNS changes require time to propagate globally across name servers. You can use standard command-line diagnostic utilities or online tools to verify that your new records are correctly published.
Using Dig on Linux and macOS
Open your terminal and run the dig command to query the CAA records for your domain:
dig example.com CAA
A successful response returns an output similar to this:
; <<>> DiG 9.16.1-Ubuntu <<>> example.com CAA
;; global options: +cmd
;; Got ANSWER SECTION:
example.com. 3600 IN CAA 0 issue "letsencrypt.org"
Using PowerShell on Windows
Open PowerShell and run the following cmdlet to check the DNS response:
Resolve-DnsName -Name example.com -Type CAA
Sample output:
Name Type TTL Section NameTag Value
---- ---- ----- ------- ------- -----
example.com CAA 3600 Answer letsencrypt.org
| Verification Method | Speed | Best For | Command / Tool |
|---|---|---|---|
| Command Line (Dig) | Instant (Direct) | Developers, Sysadmins | dig domain.com CAA |
| PowerShell | Instant (Direct) | Windows Administrators | Resolve-DnsName |
| Online Tool | Instant (Cached) | Quick Checks & Audits | CAA Lookup |
Common Mistakes and How to Fix Them
Even experienced engineers can trip up on minor syntax details when writing security records. Avoid these common pitfalls:
- Forgetting Quotation Marks: Many control panels require the CA domain value to be enclosed in double quotes. Omitting quotes can cause the DNS server to reject the record or parse it incorrectly.
- Restricting Too Broadly Too Soon: If you add a CAA record for
letsencrypt.orgbut your CDN provider attempts to automatically provision a certificate via DigiCert, your site's HTTPS will break. Always check every service that requires certificate issuance before applying a strict whitelist. - Typoes in CA Domain Names: Typing
letencrypt.org(missing the 's') invalidates the authorization, and the CA will refuse to issue your certificate. - Incorrect Flag Values: Unless you explicitly intend to block all non-compliant CAs using a critical failure rule, always use
0as your flag value.
Summary Checklist for Ionos Setup
- Audit all services that request SSL certificates for your domain.
- Log into the Ionos control panel and navigate to Domains & SSL.
- Open the DNS Management view for your target domain.
- Create a
CAArecord with flag0, tagissue, and your trusted CA domain value. - Add an
issuewildrecord if you want to restrict wildcard certificate generation. - Save changes and verify propagation using
digor an online tool.