TXT Record Lookup
TXT strings for a domain, with SPF and DMARC labeled, including the _dmarc name.
A CAA record lookup shows which certificate authorities may issue for a domain, and where issuance reports should go.
This check runs on our server. The address you enter is used only for this check and is not stored.
This check runs on our server. The domain is not stored.
CAA is a DNS policy that certificate authorities are supposed to honor before they issue. The flag is usually 0. A critical flag (bit 0 set, value 128) means a CA that does not understand the tag must refuse to issue. The tag issue lists a CA allowed to issue host certificates. issuewild is the same for wildcard names. iodef is a mailto or https URL for reports. An empty issue value means no CA may issue.
If the domain has no CAA records, CAs are not restricted by this policy. The tool reports that absence as no CAA records. A ban is an empty issue value, which is a record that is present.
0 issue letsencrypt.org allows Let's Encrypt to issue host certificates.0 issuewild letsencrypt.org allows that CA to issue wildcards such as *.example.com.0 iodef mailto:[email protected] is where a CA can send a report. It does not by itself allow or deny issuance.Then this DNS policy does not limit issuance. Any CA may issue, subject to its own checks. Missing CAA is not the same as an empty issue tag, which means nobody may issue.
When the flags value has the critical bit set (128), a CA that does not understand the tag must not issue. Most published records use 0.
No. CAA is a request to CAs. You still want to watch the certificates that were actually issued, with Certificate Transparency logs or your own inventory.
Often used together with the CAA Record Lookup.
TXT strings for a domain, with SPF and DMARC labeled, including the _dmarc name.
Name servers from the NS records, with TTL.
One table of A, AAAA, MX, NS, TXT, SOA, and CAA records for a domain.