All checks

CAA Records

Which certificate authorities may issue certificates for the domain

What it is

CAA records list the certificate authorities allowed to issue TLS certificates for a domain, and every public CA must check them before issuing. The CA starts at the hostname and works up through its parent domains, using the first set it finds, so CAA on example.com also covers www.example.com. The records can also name an address where CAs report requests that break the policy.

Why it matters

Without CAA, any publicly trusted CA will issue a certificate for the domain, so an attacker only needs to fool whichever one has the weakest checks. With it, the rest refuse. The allowed list also shows which CAs the organisation gets its certificates from.

Related checks