Definition · TLS & Certificates
What is CAA Record?
A CAA (Certification Authority Authorization) record is a DNS record type, defined in RFC 8659, that lets a domain owner declare which certificate authorities are allowed to issue certificates for the domain. Publicly trusted CAs are required by the CA/Browser Forum Baseline Requirements to check CAA records before issuing, and must refuse issuance if they are not authorised.
CAA record syntax
example.com. CAA 0 issue "letsencrypt.org"
example.com. CAA 0 issuewild ";"
example.com. CAA 0 iodef "mailto:security@example.com"
- issue — authorises a CA to issue certificates for the domain
- issuewild — separately controls wildcard certificate issuance;
";"forbids it - iodef — an address where CAs should report policy violations or unauthorised requests
If no CAA record exists anywhere in the domain hierarchy, any CA may issue.
Why CAA matters
CAA reduces the risk of mis-issuance: a compromised account at an unused CA, a social-engineering attack against a CA’s validation process, or a well-meaning employee ordering a certificate from an unapproved provider. It narrows the set of CAs an attacker can target to obtain a certificate for your domain.
CAA is preventative; Certificate Transparency logs are the detective counterpart, recording every certificate that is actually issued. Together they give domain owners both control over and visibility into issuance.