Guides · Your domain name and DNS
CAA records explained: who may issue certificates for your domain
Last reviewed by a person on October 4, 2026
Anyone can ask a certificate authority (CA) for a certificate for your domain, but the CA issues it only after the requester proves control of the domain (domain validation). A CAA record adds a second safeguard that you control: a line in your DNS that says which CAs are allowed to issue certificates for your domain at all. A CA that follows the rules looks it up before it issues anything, and refuses if it is not on your list.
What a CAA record looks like
example.com. CAA 0 issue "letsencrypt.org" example.com. CAA 0 issuewild ";" example.com. CAA 0 iodef "mailto:security@example.com"
issue: the CA named here may issue certificates for this name (and, if there is noissuewildrecord, wildcard certificates too).issuewild: who may issue wildcard certificates (*.example.com). A value of";"means nobody.iodef: an address (usuallymailto:, or a web URL) where a CA may report requests that break your CAA policy. Optional; CAs aren't required to send reports, and few do.- The leading
0is the flag.128marks a record as "critical": a CA that does not understand the tag must refuse. Almost everyone uses0.
How a CA uses it
- No CAA records anywhere: any CA may issue. That is the default for most domains.
- It checks the name itself first, then its parents. For
shop.example.comthe CA looks for CAA records onshop.example.com; if there are none, onexample.com. So a record on your main domain covers every subdomain, and a subdomain can set its own to override it. - If there are records, only the CAs named in an
issuerecord may issue. Records that exist but name nobody (issue ";") block issuance completely. - The match is on the CA's CAA name, not its brand: for example DigiCert's certificates need
digicert.com.
Why add one
- It limits where a mistake or an attack can come from. If an attacker or a careless colleague requests a certificate for your name from a CA you never use, a CA that checks CAA refuses.
- It documents your choice. The record says plainly which CA you use, which helps whoever manages the domain next.
- It is cheap. One or two DNS records, no software.
Why you might not want one (or must be careful)
- It is a limit that can break your own renewals. The most common CAA problem is a record that lists your old CA. When you or your host switch to another one, issuance and renewal are refused, often right when the certificate is about to expire. Add the new CA before you switch.
- Services that issue certificates for you need to be on the list. A CDN, a hosting control panel, a load balancer or a managed platform may get its certificates from one CA or several, and it may change CAs without telling you. If you use one, check what it needs before you add records. Many publish the exact CAA values they use.
- It is not a lock. It limits which CAs may issue; it doesn't replace their validation. A CA you allow still issues to anyone who passes its domain validation, and someone who controls your DNS can change the record.
- It needs a DNS host that supports CAA records. Nearly all do now, but a few small providers and old control panels do not.
A sensible rule: if one CA issues all your certificates and nothing else issues them for you, add a CAA record for it. If several services issue certificates for you and you cannot list them with confidence, leave it off until you can.
Common CAA names
The value to put in issue for some common authorities:
- Let's Encrypt:
letsencrypt.org - DigiCert:
digicert.com - Sectigo (formerly Comodo):
sectigo.com - GlobalSign:
globalsign.com - Google Trust Services:
pki.goog - Amazon (AWS Certificate Manager):
amazon.com,amazontrust.com,awstrust.comoramazonaws.com(any one of them; see AWS's Configure a CAA record)
When in doubt, ask your CA: they all document it.
How to look at and add records
See what a domain has now:
dig CAA example.com +short # or, on Windows: nslookup -type=CAA example.com
Or use the DNS checker, which lists the CAA records that apply to a name (also when they are on a parent name).
An empty answer for the name does not always mean there are none: the CA also looks at the parent names, so check the main domain too. To add or change a record, use the DNS control panel of the company that hosts your DNS (see how to tell who that is). Most have a "CAA" record type with fields for flag, tag and value.
After a change, test a renewal before you rely on it. With certbot, certbot renew --dry-run asks the CA without issuing anything.
When a renewal is refused because of CAA
The error usually says "CAA record for example.com prevents issuance". Add the CA that is actually trying to issue to the
issue record (or remove the record), wait for DNS to update, and retry. See
Let's Encrypt renewal failed for the other usual suspects.
How CertAvert helps
On each domain's DNS tab CertAvert lists the CAA records that apply to it (and which parent name they were found on), and compares them with the authority that issued your current certificate. If your records do not allow that authority, it says so, because your next renewal could be refused. It only judges authorities it knows by name and never calls an unknown one "blocked". Monitor a domain with CertAvert to see it.
Don't wait for the browser warning
Check any site's certificate in a few seconds with the SSL/TLS checker, or sign up free and CertAvert emails you before certificates expire.