example.com. 3600 IN CAA 0 issue "letsencrypt.org"
A CAA record (Certification Authority Authorization, RFC 8659) lists the certificate authorities allowed to issue TLS certificates for a domain. Every public CA must check CAA before issuing; if the records exist and the CA isn’t listed, it must refuse.
Tags
issue— CAs allowed to issue certificates for the name.issuewild— CAs allowed to issue wildcard certificates.iodef— where CAs should report rejected requests (mailto:orhttps:).
CAA is inherited: a record on example.com also covers www.example.com unless the subdomain has its own CAA records. No CAA records at all means any CA may issue.
Frequently asked questions
- Do I need a CAA record?
- It's optional but recommended: it reduces the risk of a certificate being mis-issued by a CA you don't use.
- Why did my certificate renewal fail after adding CAA?
- The CA you use isn't listed. Add an issue tag with its identifier, e.g. letsencrypt.org.