XiaTools

How to Set Up CAA Records in Ionos by 1&1 Control Panel

Updated 11 Oct 2026

Configuring a Certification Authority Authorization (CAA) record in your Ionos control panel is a vital step in securing your domain against unauthorized SSL/TLS certificate issuance. A CAA record tells Certificate Authorities (CAs) which organizations are permitted to issue digital certificates for your domain name, acting as a strict whitelist for website security.

Before you make any changes to your zone file, it is always a best practice to check your current setup using the CAA Lookup tool on XiaTools to see if any policies or default entries already exist.

Understanding CAA Records and DNS Syntax

A CAA record consists of three main components: flags, tags, and values. Understanding how these pieces fit together ensures your domain remains accessible while blocking rogue certificate requests from unwanted CAs.

Core Components of a CAA Record

  • Flags: An unsigned integer between 0 and 255. Typically, this is set to 0 for standard issuance policies. A flag of 1 (often called critical) means that any CA that does not understand the specified tag must refuse to issue a certificate.
  • Tags: The property you want to control. The standard tags are:
    • issue: Authorizes a specific CA to issue any type of certificate (wildcard or standard) for your domain.
    • issuewild: Authorizes a specific CA to issue wildcard certificates only. If omitted, the 2 tag rules apply.
    • iodef: Specifies a URL or email address where CAs can report policy violation incidents.
  • Values: The domain name of the authorized Certificate Authority (such as letsencrypt.org, digicert.com, or comodo.com), or a reporting URI for the iodef tag.

Exact Record Syntax for Zone Files

If you were exporting or importing a standard zone file, a typical CAA record targeting example.com looks like this:

example.com. IN CAA 0 issue "letsencrypt.org"
example.com. IN CAA 0 issuewild ";"
example.com. IN CAA 0 iodef "mailto:security@example.com"

Setting issuewild to ";" is a common hardening technique that explicitly forbids any CA from issuing wildcard certificates for your domain, even if standard certificates are allowed.

Step-by-Step Ionos CAA Record Configuration

Adding a CAA record in the Ionos control panel is straightforward, provided you know where to navigate within their modernized interface. Keep in mind that hosting provider menu paths can occasionally change and label names may differ slightly depending on your account region.

Step 1: Access Your Ionos Account

  1. Open your web browser and navigate to the official Ionos login page.
  2. Log in using your credentials, Customer ID, or email address.
  3. Once authenticated, locate and open the Domains & SSL section from the primary dashboard or product list.

Step 2: Open the DNS Settings

  1. Find the specific domain name (e.g., example.com) for which you want to configure CAA records.
  2. Click on the gear icon or the Actions menu next to the domain.
  3. Select DNS or Manage DNS from the drop-down options to open the comprehensive DNS record management table.

Step 3: Add a New Record

  1. Look for a button labeled Add Record or Create Record usually positioned at the top of the DNS table.
  2. From the list of available record types (such as A, AAAA, CNAME, TXT), select CAA.

Step 4: Fill in the Record Parameters

Complete the configuration fields using your specific provider details. For example, if you are authorizing Let's Encrypt for example.com and 2001:db8::/32 hosted resources, enter the following:

  • Host / Name: Leave blank or enter @ to apply the record to the root domain (example.com). You can also input a subdomain like www if needed.
  • Flag: Enter 0 for standard non-critical authorization.
  • Tag: Select issue from the drop-down menu.
  • Value / CA Domain: Enter letsencrypt.org.
  • TTL (Time to Live): Choose a standard duration such as 1 hour or Default.

Click Save or Submit to commit the changes to your DNS zone.

Verifying Your Ionos CAA Record Configuration

DNS changes require time to propagate globally across name servers. You can use standard command-line diagnostic utilities or online tools to verify that your new records are correctly published.

Using Dig on Linux and macOS

Open your terminal and run the dig command to query the CAA records for your domain:

dig example.com CAA

A successful response returns an output similar to this:

; <<>> DiG 9.16.1-Ubuntu <<>> example.com CAA
;; global options: +cmd
;; Got ANSWER SECTION:
example.com.		3600	IN	CAA	0 issue "letsencrypt.org"

Using PowerShell on Windows

Open PowerShell and run the following cmdlet to check the DNS response:

Resolve-DnsName -Name example.com -Type CAA

Sample output:

Name             Type   TTL   Section   NameTag          Value
----             ----   ----- -------   -------          -----
example.com      CAA    3600  Answer                     letsencrypt.org
Verification Method Speed Best For Command / Tool
Command Line (Dig) Instant (Direct) Developers, Sysadmins dig domain.com CAA
PowerShell Instant (Direct) Windows Administrators Resolve-DnsName
Online Tool Instant (Cached) Quick Checks & Audits CAA Lookup

Common Mistakes and How to Fix Them

Even experienced engineers can trip up on minor syntax details when writing security records. Avoid these common pitfalls:

  • Forgetting Quotation Marks: Many control panels require the CA domain value to be enclosed in double quotes. Omitting quotes can cause the DNS server to reject the record or parse it incorrectly.
  • Restricting Too Broadly Too Soon: If you add a CAA record for letsencrypt.org but your CDN provider attempts to automatically provision a certificate via DigiCert, your site's HTTPS will break. Always check every service that requires certificate issuance before applying a strict whitelist.
  • Typoes in CA Domain Names: Typing letencrypt.org (missing the 's') invalidates the authorization, and the CA will refuse to issue your certificate.
  • Incorrect Flag Values: Unless you explicitly intend to block all non-compliant CAs using a critical failure rule, always use 0 as your flag value.

Summary Checklist for Ionos Setup

  • Audit all services that request SSL certificates for your domain.
  • Log into the Ionos control panel and navigate to Domains & SSL.
  • Open the DNS Management view for your target domain.
  • Create a CAA record with flag 0, tag issue, and your trusted CA domain value.
  • Add an issuewild record if you want to restrict wildcard certificate generation.
  • Save changes and verify propagation using dig or an online tool.

Frequently asked questions

What happens if I do not set up CAA records in Ionos?

If no CAA records exist on your domain, any publicly trusted Certificate Authority is legally permitted to issue an SSL/TLS certificate for your domain name. While this allows flexibility, it leaves your domain vulnerable to accidental or malicious certificate issuance by compromised or untrusted CAs.

Can I authorize multiple Certificate Authorities in Ionos?

Yes. You can create multiple distinct CAA records within your Ionos DNS manager for the same domain name. Simply add a separate CAA record line for each authorized CA, such as one for Let's Encrypt and another for DigiCert.

Why is my SSL certificate failing after adding a CAA record?

This usually happens because the CA currently attempting to issue your certificate is not included in your new CAA whitelist. Check your automated certificate manager, review your DNS records, and ensure the CA domain name is spelled correctly without syntax errors.

Do CAA records apply to subdomains automatically?

Yes. CAA records follow a inheritance model defined by the DNS tree. If a CAA record is set on the root domain (example.com), it applies to all subdomains (like sub.example.com) unless a specific CAA record is explicitly defined on the subdomain itself.

How long does it take for Ionos CAA changes to take effect?

DNS changes made in Ionos typically propagate globally within a few minutes, though global DNS caching and TTL settings can occasionally cause a delay of up to one to two hours before all external CAs recognize the new policy.

Related articles

Free tools