Network

CAA Record Generator

Generate CAA records restricting certificate issuance to named authorities, with account and validation method pinning, wildcard control and an incident report address.

Last reviewed by the Radiatus Cloud team

Records appear here.

Need this monitored 24/7?

Radiatus delivers managed cloud & network operations.

Discuss managed ops

A DNS record that constrains every certificate authority

Certification Authority Authorisation lets a domain owner publish which authorities may issue certificates for it. Since 2017 every publicly trusted authority is required by the CA/Browser Forum baseline requirements to check CAA before issuing, and to refuse where the record does not permit them. That makes it the only mechanism a domain owner has to prevent an authority they have never used from issuing a certificate for their domain to someone who manages to pass its validation.

It is checked at issuance, not at connection

Browsers do not check CAA. A certificate issued in violation of a CAA record still works perfectly in every client, and the violation is only detectable afterwards through Certificate Transparency logs. CAA prevents the issuance rather than the use, which means it protects against a misdirected or compromised validation and does nothing about a certificate that has already been issued. Monitoring Certificate Transparency logs remains necessary alongside it.

Account and method pinning narrow it further

Beyond naming an authority, the accounturi parameter restricts issuance to a specific ACME account, and validationmethods restricts which challenge types are accepted. Together they mean that even someone who gains control of a DNS record or a web root cannot obtain a certificate unless they also hold your ACME account key. This is the strongest form of the control and is supported by Let's Encrypt and a growing number of other authorities.

Related tools

  • Port Scanner — Check which common ports respond on a host and understand what each exposed service means. Scan only systems you are authorised to test.
  • DNS Misconfiguration — Analyze DNS records (TXT, SPF) for security gaps.
  • TLS Compat Tester — Check client-server compatibility for TLS versions.
  • Firewall Rule Risk — Evaluate firewall rules for over-permissive exposure.

Frequently Asked Questions

Do I need CAA records?

They are not mandatory, but they are the only way to stop an authority you have never used from issuing for your domain. Without a CAA record, every publicly trusted authority is permitted to issue, which is roughly fifty organisations.

Does CAA stop a certificate that already exists?

No. It is checked at issuance and browsers ignore it entirely, so a certificate issued before the record existed, or in violation of it, works normally. Certificate Transparency monitoring is what detects that, and the two are complementary rather than alternatives.

How does inheritance work?

CAA is inherited down the tree, so a record at example.com applies to www.example.com unless that name has its own CAA record set, which replaces rather than supplements the parent. Authorities walk up from the requested name to the apex looking for the first record set.

What is the difference between issue and issuewild?

issue permits certificates for the exact names, and issuewild permits wildcard certificates specifically. If issuewild is absent, the issue record governs wildcards too. Setting issuewild to a semicolon blocks wildcard issuance entirely while allowing normal certificates.

What does the iodef record do?

It names a mailto or https endpoint that an authority should contact when it refuses issuance because of your CAA record. Support is inconsistent, but where it works it tells you someone attempted to obtain a certificate for your domain, which is worth knowing.

Privacy & Security

Everything runs in your browser; nothing is uploaded.

Data: None
Client-side-Side
Active
v1.0

How to Use

Choose your certificate authorities and options to generate the CAA records for your zone.

Disclaimer: This tool is provided "as is" without warranty of any kind. Results are for educational and utility purposes.