XiaTools
DNS tool

CAA Lookup

See which certificate authorities are allowed to issue SSL certificates for a domain.

The CAA Lookup tool allows you to query Domain Name System records to see which certificate authorities are officially authorized to issue SSL or TLS certificates for your domain. By querying these specific DNS entries, you can verify that only your approved vendors can generate cryptographic certificates for your web properties.

What is it

A Certification Authority Authorization (CAA) record is an optional DNS resource record type defined in RFC 6844. It allows domain owners to declare which certificate authorities are permitted to issue digital certificates for their specific domain or subdomains. If a certificate authority receives a request to issue a certificate for a domain, it must check the domain's CAA records first. If the authority is not listed as authorized, it is strictly prohibited from issuing the certificate. This mechanism provides an extra layer of defense against mis-issued or fraudulent certificates, protecting your visitors from man-in-the-middle attacks and securing your brand reputation.

Why it matters

Historically, any publicly trusted certificate authority could issue an SSL certificate for any domain if the requester completed a basic validation challenge. This created significant security risks, as a compromised or rogue certificate authority could issue a valid certificate to an attacker without the domain owner's knowledge. Implementing CAA records closes this security gap by restricting certificate issuance exclusively to your trusted partners, such as Let's Encrypt, DigiCert, or Sectigo. It also interacts directly with Certificate Transparency logs, helping your IT security team maintain strict compliance standards, prevent unauthorized certificate generation, and ensure complete visibility into your organization's cryptographic assets.

How to use this tool

  1. Navigate to the CAA Lookup tool page on XiaTools.
  2. Locate the search input box in the center of the screen.
  3. Enter your fully qualified domain name, such as example.com, without any prefixes like https://.
  4. Click the Check button to initiate the DNS query across our global network of resolvers.
  5. Review the resulting records displayed in the output table below the input box.

How to read the results

When you query a domain like example.com, the tool displays all active CAA records found in your DNS zone. A standard result set includes several columns: Flags, Tag, and Value. For instance, a typical result for example.com might show a Flag of 0, a Tag of issue, and a Value of letsencrypt.org. The Flag field is an integer from 0 to 255, where a value of 128 indicates a critical record that the certificate authority must understand and obey, while 0 indicates a non-critical flag. The Tag field defines the directive type, which can be issue (authorizes a specific CA to issue any certificate), issuewild (authorizes a CA to issue wildcard certificates only), or iodef (specifies a URL or email address where certificate authorities can report policy violations). The Value field contains the domain name of the authorized certificate authority or the contact destination for incident reports. If the tool returns no records, it means your domain has no CAA restrictions in place, and any public certificate authority is currently allowed to issue certificates for your domain.

Common problems and how to fix them

No CAA Records Found

If the tool returns no records, your domain is entirely open to certificate issuance by any public authority. While this is the default state for most websites, it leaves you vulnerable to unauthorized certificate creation. To fix this, log into your DNS provider and add baseline CAA records specifying your preferred certificate authorities.

Incorrect Tag Syntax

Typographical errors in the Tag field will cause certificate authorities to ignore your restrictions entirely. Ensure you only use valid lowercase tags such as issue, issuewild, or iodef. For example, setting up a correct record in your DNS zone file looks like this:

example.com. IN CAA 0 issue "letsencrypt.org"

Blocking Your Own Automated Renewals

If you recently switched certificate authorities or implemented strict CAA records without including your current provider, automated SSL renewals will fail. Double-check that your active provider is explicitly listed in your DNS records. If you use Let's Encrypt, your record should look like:

example.com. IN CAA 0 issue "letsencrypt.org"

Best practices

Always define CAA records for both your root domain and all critical subdomains, as subdomains do not automatically inherit CAA records from their parent domain unless explicitly configured. Include an issuewild tag if you want to enforce stricter rules specifically for wildcard certificates, which inherently carry a higher security risk. Implement the iodef tag to provide a secure contact point for certificate authorities to alert your security team if an unauthorized issuance attempt occurs. Finally, test your configuration using this tool every time you update your DNS provider or migrate to a new certificate authority to ensure seamless SSL renewals and robust domain security.

Frequently asked questions

What is a CAA record?

A CAA (Certification Authority Authorization) record is a type of DNS record that lets domain owners specify which certificate authorities are allowed to issue SSL or TLS certificates for their domain.

Are CAA records mandatory for my domain?

No, CAA records are completely optional. However, implementing them is strongly recommended as a security best practice to prevent unauthorized certificate issuance.

What happens if my domain has no CAA records?

If your domain has no CAA records, any publicly trusted certificate authority is permitted to issue an SSL certificate for your domain as long as they complete their standard validation process.

What is the difference between issue and issuewild tags?

The issue tag authorizes a certificate authority to issue both standard and wildcard certificates for the domain. The issuewild tag specifically restricts or allows the issuance of wildcard certificates only.

Can subdomains inherit CAA records from the root domain?

No, certificate authorities follow a specific tree-walking algorithm up the domain hierarchy to find CAA records, but subdomains should ideally have their own explicit records to ensure predictable security enforcement.

How do I fix a failed SSL renewal caused by CAA records?

If your SSL renewal fails due to CAA restrictions, use this lookup tool to identify your current records and update your DNS zone to include your active certificate authority as an authorized issuer.

CAA Lookup guides

Related tools