XiaTools

What Is a CAA Record and Why Your SSL Needs It

Updated 30 Sept 2026

A DNS Certification Authority Authorization (CAA) record is a resource record that lets domain owners specify which certificate authorities are allowed to issue SSL or TLS certificates for their domain. Without a CAA record, any public certificate authority can issue a certificate for your web properties if they validate your domain control. Implementing these records adds an essential layer of security to your public key infrastructure and prevents rogue or mis-issued certificates.

Understanding the Basics of CAA Records

When a certificate authority receives a request to issue an SSL/TLS certificate for example.com, standard security guidelines require them to check for existing CAA records before processing the request. If the certificate authority finds a policy that restricts issuance to specific vendors, they must decline the request if they are not on the approved list.

How Certificate Authorities Process CAA Records

During the validation phase, the certificate authority queries your authoritative name servers for CAA records. The lookup process follows strict fallback rules defined in technical standards.

  • Exact Match: The certificate authority looks for a CAA record on the exact host name requested, such as www.example.com.
  • Tree Climbing: If no record exists at the exact host level, the resolver climbs up the domain tree to parent domains, eventually reaching the apex domain like example.com.
  • No Records Found: If the certificate authority traverses all the way to the root without finding any CAA records, any public certificate authority is permitted to issue the certificate.

The Core Components of a CAA Record

A standard CAA record consists of three primary components that define the operational behavior for certificate issuance:

  1. Flags: An unsigned integer representing specific directives. A flag value of 0 is standard, while a flag value of 1 (critical) means that any certificate authority encountering the record must understand the associated tag; if they do not recognize or support the tag, they must refuse to issue the certificate.
  2. Tag: A property identifier that tells the certificate authority what type of rule is being enforced. The three main tags are issue (authorizes a specific certificate authority to issue any certificate), issuewild (authorizes a specific certificate authority to issue wildcard certificates), and iodef (specifies a URL or email address where certificate authorities can report policy violations).
  3. Value: The domain name of the authorized certificate authority or the endpoint for violation reports, such as letsencrypt.org or digicert.com.

Why Your Infrastructure Needs CAA Records

While domain validation methods like HTTP-01 and DNS-01 challenge responses prove that you control a domain at the time of request, they do not stop a compromised or rogue certificate authority from issuing a certificate if their validation systems fail or are tricked.

Mitigating Mis-Issuance Risks

Even robust organizations can fall victim to internal misconfigurations or compromised third-party vendor accounts that possess domain validation privileges. By publishing a strict set of CAA rules, you shrink the attack surface. If an unauthorized entity attempts to obtain an SSL certificate through an unapproved vendor, the request is automatically blocked at the issuance stage.

Compliance and Industry Standards

Since 2017, the baseline requirements set by the governing body for public certificates mandated that all certificate authorities check for CAA records before issuing certificates. Neglecting to implement them leaves your domain exposed to a vulnerability vector that is easily closed with a few simple DNS entries.

Step-by-Step Guide to Creating CAA Records

Configuring CAA records requires access to your DNS hosting provider's management console. Before making changes, decide which certificate authorities your organization actually uses for web servers, mail servers, and internal applications.

Step 1: Identify Your Authorized Certificate Authorities

Make a definitive list of the certificate authorities you trust. Common examples include Let's Encrypt, DigiCert, Sectigo, and GlobalSign. Note down their exact domain identifiers as recognized by the industry, such as letsencrypt.org for Let's Encrypt.

Step 2: Formulate Your DNS Entries

Translate your authorized list into standard DNS record syntax. For instance, if you want to allow Let's Encrypt to issue standard certificates and forbid wildcard certificates across your domain, create records matching this structure:

example.com. IN CAA 0 issue "letsencrypt.org"
example.com. IN CAA 0 issuewild ";"

The semicolon value for issuewild explicitly disables the issuance of wildcard certificates for example.com by any certificate authority, including the one permitted to issue standard certificates.

Step 3: Add the Records to Your DNS Provider

Log into your DNS management panel, create a new record for your apex domain, select CAA as the record type, and paste the flags, tags, and values provided by your configuration plan. Save the changes and wait for DNS propagation.

Step 4: Verify Your Configuration

Always verify that your newly added records are publicly visible and syntactically correct. You can easily test your setup by running a CAA lookup to confirm that the correct certificate authorities are returned and that no syntax errors exist in your zone file.

Common Configuration Examples

Different organizational needs require different CAA policies. Here are three common scenarios you can adapt for your own infrastructure.

Scenario A: Restricting to a Single Provider

If your organization exclusively uses a single certificate authority for all internal and external needs, your zone file should list only that provider and block everything else:

example.com. 3600 IN CAA 0 issue "digicert.com"
example.com. 3600 IN CAA 0 issuewild "digicert.com"

Scenario B: Allowing Multiple Providers with Incident Reporting

If you use different providers for different services and want to receive forensic reports when an unauthorized issuance is attempted, configure multiple lines alongside an iodef tag:

example.com. 3600 IN CAA 0 issue "letsencrypt.org"
example.com. 3600 IN CAA 0 issue "sectigo.com"
example.com. 3600 IN CAA 0 iodef "mailto:security@example.com"

Scenario C: Locking Down a Domain Completely

If a specific subdomain or root domain should never have any certificates issued under any circumstances, you can lock it down by explicitly denying all issuance:

staging.example.com. 3600 IN CAA 0 issue ";"

Pre-Deployment Checklist

Before pushing your CAA records to a live production environment, run through this quick checklist to ensure seamless operations and avoid accidental outages.

  • Identified all active and legacy certificate authorities currently used by your applications.
  • Determined whether wildcard certificates are required for your infrastructure.
  • Verified that your DNS provider natively supports CAA record types in their management interface.
  • Tested the record syntax using a staging zone or validation tool.
  • Configured an operational contact email for iodef alerts if monitoring policy breaches.
  • Performed a post-deployment verification lookup to ensure resolvers return expected results.

Troubleshooting Common CAA Issues

Even with careful planning, misconfigurations can happen. If your automated certificate renewal processes suddenly fail, investigate the following common failure points.

Typographical Errors in Provider Domain Names

Certificate authorities are strict about the domain strings used in CAA values. Entering letsencrypt instead of letsencrypt.org will cause validation engines to reject the record or fall back incorrectly, potentially breaking automated renewal scripts.

Conflicting Critical Flags

Be cautious when using a flag value of 1 (critical). If you set a critical flag on a tag that a modern certificate authority does not fully parse or recognize, their security policy will force them to abort the issuance process to maintain compliance. Stick with flag 0 unless you have an advanced compliance requirement.

Caching Delays

DNS resolvers cache records according to the Time To Live (TTL) value. If you update your CAA records and immediately attempt a certificate renewal, the certificate authority may read stale DNS data from a cached resolver. Lower your TTL before making major changes or wait for the standard propagation window to elapse.

Frequently asked questions

What happens if I do not set up a CAA record for my domain?

If you do not publish a CAA record, any public certificate authority is legally and technically permitted to issue an SSL or TLS certificate for your domain as long as they complete standard domain validation checks. While this allows flexibility, it leaves your domain vulnerable to unauthorized or accidental certificate issuance.

Can I use CAA records to block specific certificate authorities while allowing others?

Yes. By default, adding an 'issue' record for one specific certificate authority implicitly blocks all other certificate authorities from issuing certificates for your domain. You do not need to list every unauthorized vendor; simply listing your approved providers is sufficient.

What is the difference between the 'issue' and 'issuewild' tags?

The 'issue' tag controls authorization for standard single-name and multi-domain certificates. The 'issuewild' tag specifically controls authorization for wildcard certificates, such as *.example.com. If 'issuewild' is not explicitly defined, certificate authorities typically fall back to the rules set by the 'issue' tag.

What does a critical flag value of 1 do in a CAA record?

A critical flag value of 1 instructs any certificate authority reading the record that they must understand and support the specified tag. If a certificate authority encounters a critical flag on a tag they do not support, they are required by protocol standards to refuse certificate issuance.

How long does it take for certificate authorities to recognize new CAA records?

Certificate authorities recognize new CAA records as soon as the changes propagate across the global DNS network and expire from their internal resolver caches. This process typically takes anywhere from a few minutes to a few hours depending on the Time To Live value configured on your DNS records.

Related articles

Free tools