ะŸั€ะพะดะฒะธะถะตะฝะธะต ัะฐะนั‚ะพะฒ ะกะพะทะดะฐะฝะธะต ัะฐะนั‚ะพะฒ ะŸะพะดะดะตั€ะถะบะฐ ัะฐะนั‚ะฐ

CAA Checker

Who is authorized to issue SSL certificates for your domain

CAA Checker online: who can issue certificates for a domain

CAA (Certification Authority Authorization) is a DNS record type defined in RFC 6844/8659 that lets a domain owner explicitly specify which Certificate Authorities (CAs) are allowed to issue SSL/TLS certificates for the domain and its subdomains. Since 2017, every public CA is required to check the CAA record before issuing a certificate โ€” a mandatory CA/Browser Forum baseline requirement.

Why a CAA record matters

Without a CAA record, any of hundreds of public CAs can technically issue a certificate for a domain after a standard domain-validation challenge. If an attacker briefly gains control of a domain's DNS or web server, they could pass validation and obtain a valid certificate from an unrelated CA. An explicit CAA record narrows the set of CAs that will even consider a request, reducing the attack surface.

CAA record tags

Frequently asked questions

See also