100% Free • No Signup • Live DNS

CAA Record Checker

Check which certificate authorities are allowed to issue SSL certificates for your domain.

Try:

Free CAA check • Live DNS • No signup

Queries DNS CAA records and explains which certificate authorities may issue SSL certificates.

Why CAA records matter

CAA records let you control which certificate authorities may issue SSL certificates for your domain. Without them, any public CA can issue after normal validation — which is fine for many sites, but a gap if you want stricter issuance policy or to block unauthorized certificate requests.

What this checker validates

One check reviews CAA records, allowed certificate authorities and SSL issuance policy.

CAA record presence

Check whether the domain publishes CAA records.

Allowed certificate authorities

Review which CAs are allowed to issue certificates for the domain.

issue & issuewild

Check standard and wildcard certificate issuance rules.

Incident reporting

Find iodef reporting addresses for certificate issuance issues.

Common CAA issues this tool can detect

Find certificate issuance policy signals that may affect SSL management.

No CAA policy

  • No CAA records published
  • Issuance not restricted by CAA
  • Policy inherited from parent domain

Wildcard & issuewild

  • No issuewild tag configured
  • Wildcard issuance blocked or open
  • Wildcard CA differs from standard policy

Reporting & iodef

  • No iodef contact configured
  • Invalid reporting endpoint format
  • Missing incident notification path

Configuration review

  • Unknown CA value in issue tag
  • Invalid or unrecognized tag format
  • DNS lookup or parse errors

Missing CAA records are common and not a certificate failure. For installed certificate status, use SSL Checker and DNS Lookup.

How CAA checking works

The checker reads DNS CAA records and explains SSL certificate issuance policy.

  1. Enter a domain

    We normalize the domain and query CAA records that control certificate issuance.

  2. Query CAA records

    The tool checks CAA records in DNS for your domain and parent policy where available.

  3. Review issuance policy

    See allowed certificate authorities, wildcard rules, reporting contacts and recommended improvements.

When to check CAA records

  • Before switching certificate authorities
  • When setting up automated SSL renewal
  • After a DNS or hosting migration
  • To restrict unauthorized certificate issuance
  • Periodic SSL policy review
  • Before a security or compliance audit

Understanding CAA status

Protected

CAA records restrict issuance to specific certificate authorities.

Configured

CAA records were found and appear valid. Review allowed CAs and reporting.

No CAA policy

No CAA records found. This is common and does not invalidate existing SSL certificates.

Review needed

One or more CAA values may need attention before certificate renewal.

CAA records control certificate issuance policy. They do not prove the currently installed SSL certificate is valid.

Checking CAA records…

Need help fixing CAA or certificate issuance?

Send us your domain report and we’ll review the issue.

Learn more: What is CAA? · SSL Checker

CAA records control which CAs may issue certificates. Absence of CAA does not mean certificates are invalid. How we check

Frequently asked questions

Common questions about CAA records and certificate issuance policy.

A CAA record is a DNS record that tells certificate authorities which CAs are allowed to issue SSL certificates for a domain.
No. Many domains do not publish CAA records. However, CAA records can improve control over certificate issuance.
If no CAA record exists, public certificate authorities may issue certificates after completing normal domain validation.
The issue tag allows a specific certificate authority to issue standard certificates for the domain.
The issuewild tag controls which certificate authorities may issue wildcard certificates.
No. The CAA Record Checker is free and does not require signup.