CAA Record Lookup

A CAA record lookup shows which certificate authorities may issue for a domain, and where issuance reports should go.

This check runs on our server. The address you enter is used only for this check and is not stored.
Updated

This check runs on our server. The address you enter is used only for this check and is not stored.

How to use the CAA Record Lookup

  1. Enter the domain.
  2. Pick a resolver.
  3. Tick the robot check and press Look up.
  4. Read the tag. issue and issuewild name the authorities. iodef is a report address.

How it works

This check runs on our server. The domain is not stored.

CAA is a DNS policy that certificate authorities are supposed to honor before they issue. The flag is usually 0. A critical flag (bit 0 set, value 128) means a CA that does not understand the tag must refuse to issue. The tag issue lists a CA allowed to issue host certificates. issuewild is the same for wildcard names. iodef is a mailto or https URL for reports. An empty issue value means no CA may issue.

If the domain has no CAA records, CAs are not restricted by this policy. The tool reports that absence as no CAA records. A ban is an empty issue value, which is a record that is present.

Examples

  • 0 issue letsencrypt.org allows Let's Encrypt to issue host certificates.
  • 0 issuewild letsencrypt.org allows that CA to issue wildcards such as *.example.com.
  • 0 iodef mailto:[email protected] is where a CA can send a report. It does not by itself allow or deny issuance.

Limitations

  • The lookup shows the policy. It does not ask a certificate authority what it would do.
  • CAA on a parent name can apply when the child has none. This page queries the name you entered.
  • A CA that ignores CAA will not be caught here.

Frequently asked questions

What if there is no CAA record?

Then this DNS policy does not limit issuance. Any CA may issue, subject to its own checks. Missing CAA is not the same as an empty issue tag, which means nobody may issue.

What is the critical flag?

When the flags value has the critical bit set (128), a CA that does not understand the tag must not issue. Most published records use 0.

Does CAA replace certificate monitoring?

No. CAA is a request to CAs. You still want to watch the certificates that were actually issued, with Certificate Transparency logs or your own inventory.

Often used together with the CAA Record Lookup.

  • TXT Record Lookup

    TXT strings for a domain, with SPF and DMARC labeled, including the _dmarc name.

  • NS Lookup

    Name servers from the NS records, with TTL.

  • DNS Lookup

    One table of A, AAAA, MX, NS, TXT, SOA, and CAA records for a domain.