Definition · TLS & Certificates

What is CAA Record?

A CAA (Certification Authority Authorization) record is a DNS record type, defined in RFC 8659, that lets a domain owner declare which certificate authorities are allowed to issue certificates for the domain. Publicly trusted CAs are required by the CA/Browser Forum Baseline Requirements to check CAA records before issuing, and must refuse issuance if they are not authorised.

CAA record syntax

example.com.  CAA  0 issue "letsencrypt.org"
example.com.  CAA  0 issuewild ";"
example.com.  CAA  0 iodef "mailto:security@example.com"
  • issue — authorises a CA to issue certificates for the domain
  • issuewild — separately controls wildcard certificate issuance; ";" forbids it
  • iodef — an address where CAs should report policy violations or unauthorised requests

If no CAA record exists anywhere in the domain hierarchy, any CA may issue.

Why CAA matters

CAA reduces the risk of mis-issuance: a compromised account at an unused CA, a social-engineering attack against a CA’s validation process, or a well-meaning employee ordering a certificate from an unapproved provider. It narrows the set of CAs an attacker can target to obtain a certificate for your domain.

CAA is preventative; Certificate Transparency logs are the detective counterpart, recording every certificate that is actually issued. Together they give domain owners both control over and visibility into issuance.

See what your business is exposing

SurfaceLoop checks every internet-facing asset you own across seven risk categories, daily.