The CAA Lookup tool allows you to query Domain Name System records to see which certificate authorities are officially authorized to issue SSL or TLS certificates for your domain. By querying these specific DNS entries, you can verify that only your approved vendors can generate cryptographic certificates for your web properties.
What is it
A Certification Authority Authorization (CAA) record is an optional DNS resource record type defined in RFC 6844. It allows domain owners to declare which certificate authorities are permitted to issue digital certificates for their specific domain or subdomains. If a certificate authority receives a request to issue a certificate for a domain, it must check the domain's CAA records first. If the authority is not listed as authorized, it is strictly prohibited from issuing the certificate. This mechanism provides an extra layer of defense against mis-issued or fraudulent certificates, protecting your visitors from man-in-the-middle attacks and securing your brand reputation.
Why it matters
Historically, any publicly trusted certificate authority could issue an SSL certificate for any domain if the requester completed a basic validation challenge. This created significant security risks, as a compromised or rogue certificate authority could issue a valid certificate to an attacker without the domain owner's knowledge. Implementing CAA records closes this security gap by restricting certificate issuance exclusively to your trusted partners, such as Let's Encrypt, DigiCert, or Sectigo. It also interacts directly with Certificate Transparency logs, helping your IT security team maintain strict compliance standards, prevent unauthorized certificate generation, and ensure complete visibility into your organization's cryptographic assets.
How to use this tool
- Navigate to the CAA Lookup tool page on XiaTools.
- Locate the search input box in the center of the screen.
- Enter your fully qualified domain name, such as
example.com, without any prefixes likehttps://. - Click the Check button to initiate the DNS query across our global network of resolvers.
- Review the resulting records displayed in the output table below the input box.
How to read the results
When you query a domain like example.com, the tool displays all active CAA records found in your DNS zone. A standard result set includes several columns: Flags, Tag, and Value. For instance, a typical result for example.com might show a Flag of 0, a Tag of issue, and a Value of letsencrypt.org. The Flag field is an integer from 0 to 255, where a value of 128 indicates a critical record that the certificate authority must understand and obey, while 0 indicates a non-critical flag. The Tag field defines the directive type, which can be issue (authorizes a specific CA to issue any certificate), issuewild (authorizes a CA to issue wildcard certificates only), or iodef (specifies a URL or email address where certificate authorities can report policy violations). The Value field contains the domain name of the authorized certificate authority or the contact destination for incident reports. If the tool returns no records, it means your domain has no CAA restrictions in place, and any public certificate authority is currently allowed to issue certificates for your domain.
Common problems and how to fix them
No CAA Records Found
If the tool returns no records, your domain is entirely open to certificate issuance by any public authority. While this is the default state for most websites, it leaves you vulnerable to unauthorized certificate creation. To fix this, log into your DNS provider and add baseline CAA records specifying your preferred certificate authorities.
Incorrect Tag Syntax
Typographical errors in the Tag field will cause certificate authorities to ignore your restrictions entirely. Ensure you only use valid lowercase tags such as issue, issuewild, or iodef. For example, setting up a correct record in your DNS zone file looks like this:
example.com. IN CAA 0 issue "letsencrypt.org"
Blocking Your Own Automated Renewals
If you recently switched certificate authorities or implemented strict CAA records without including your current provider, automated SSL renewals will fail. Double-check that your active provider is explicitly listed in your DNS records. If you use Let's Encrypt, your record should look like:
example.com. IN CAA 0 issue "letsencrypt.org"
Best practices
Always define CAA records for both your root domain and all critical subdomains, as subdomains do not automatically inherit CAA records from their parent domain unless explicitly configured. Include an issuewild tag if you want to enforce stricter rules specifically for wildcard certificates, which inherently carry a higher security risk. Implement the iodef tag to provide a secure contact point for certificate authorities to alert your security team if an unauthorized issuance attempt occurs. Finally, test your configuration using this tool every time you update your DNS provider or migrate to a new certificate authority to ensure seamless SSL renewals and robust domain security.