Free · no signup
CAA Record Generator & Checker
See which certificate authorities a domain currently allows to issue — and build a correct CAA record set for your own domain in seconds.
Build your CAA records
Everything below runs in your browser — nothing is sent to our server. Tick the CAs you use, copy the lines into your DNS zone.That doesn’t look like a domain — using example.com in the output for now.
For parked domains that should never have a certificate. Overrides the CA selection above.
Enter a valid email address for the iodef report line.
Adds an iodef record so CAs can report requests your policy rejected.
128 means “CAs that don’t understand this tag must refuse to issue”. All CAs understand issue, issuewild and iodef, so 0 is what you almost always want.
Paste these lines into your DNS zone (or add each as a CAA record in your DNS provider’s dashboard: flags, tag and value are separate fields there). Then re-check your domain above to confirm what resolvers actually serve.
The flags byte, decoded
Who is allowed to issue certificates for your domain?
A CAA record (Certification Authority Authorization, RFC 8659) is a small DNS record with a big job: it names the certificate authorities that are allowed to issue certificates for your domain. Before any publicly trusted CA signs a certificate, it must look up your CAA records and refuse if it isn’t listed. One line of DNS turns “hundreds of CAs could be tricked into issuing for my name” into “only the one or two I actually use”.
The lookup works the way our checker above does: the CA queries CAA at the exact name it wants to
issue for, and if nothing is there, climbs the tree one label at a time —
shop.example.com, then example.com — until it finds a CAA record set.
The first set found is the whole policy; records higher up are ignored after that. And if the
climb reaches the top empty-handed, nothing is restricted: no CAA means every publicly
trusted CA may issue for your domain. That’s the default state of most of the internet,
which is exactly why adding a record is such cheap insurance.
The values must name the CA’s issuer domain, not its brand. The classic trap is ZeroSSL:
it issues certificates from Sectigo’s roots, so the correct value is
issue "sectigo.com" — authorize zerossl.com instead and your renewals
quietly start failing. Wildcards get their own tag (issuewild), and an
iodef record tells CAs where to report requests your policy rejected — a free
tripwire that emails you when someone tries. Our generator above gets all of this right for the
common CAs; for the deeper story, read our
guide to CAA records.
One honest caveat: CAA is enforced at issuance time only, and it lives in DNS — anyone who can change your DNS can change your CAA. It narrows who can issue; it doesn’t tell you what was issued, and it’s not a substitute for monitoring your certificates. CompleteStatus covers that side: a Certificate Transparency monitor alerts you when a certificate is issued for your domain, and a DNS monitor alerts you when your NS or A records change — start monitoring free.