ActiScan

Free CAA Record Checker

Check which certificate authorities may issue TLS certificates for a domain.

Need to monitor this across every client domain you manage? ActiScan does bulk scanning, scoring, and white-labeled reporting for MSPs.

What Is a CAA Record?

A CAA (Certificate Authority Authorization) record restricts which certificate authorities are allowed to issue TLS/SSL certificates for a domain. Every publicly trusted CA is required to check for a CAA record before issuing a certificate – if one exists and doesn't list them, issuance must be refused.

  • •Restricting certificate issuance to only the CA(s) you actually use
  • •Reducing the risk of a mis-issued certificate from an unauthorized CA
  • •Requesting a CA notify a specific email address (via the iodef tag) about issuance requests

Example

0 issue "letsencrypt.org"

Authorizes only Let's Encrypt to issue certificates for this domain.

Things to Know

No CAA record means no restriction

If a domain has no CAA record at all, any publicly trusted CA may issue a certificate for it – CAA is opt-in hardening, not a default protection.

issue vs. issuewild

The issue tag authorizes certificates for the exact domain; issuewild specifically covers wildcard certificates (*.example.com). A domain can set one, the other, or both.

Next Steps

DNSSEC Checker

Another opt-in DNS hardening layer, protecting the records themselves from tampering.

DNSSEC Checker →

General DNS Checker

Look up A, AAAA, MX, TXT, CNAME, NS, SOA, or PTR records too.

General DNS Checker →

Domain Security Analyzer

A full scan across every email-security record type at once, with an A-F grade.

Domain Security Analyzer →

Frequently Asked Questions

Is this CAA record checker free?

Yes – look up CAA records for any domain, for free, no signup required.

Do I need a CAA record?

It's optional but recommended as a low-effort hardening step – it costs nothing and closes off issuance from any CA you haven't explicitly authorized.

I set a CAA record and now certificate renewal is failing

Confirm the CA you actually use is listed exactly as it identifies itself (e.g. "letsencrypt.org", "pki.goog", "digicert.com") – a typo or an unlisted CA will cause every future issuance attempt from that CA to be refused.

What resolver does this use?

Cloudflare's public DNS-over-HTTPS resolver. Every lookup is live, not a cached snapshot.

Use the free CAA checker as often as you need

Start free trial