Free CAA Record Checker
Check which certificate authorities may issue TLS certificates for a domain.
Need to monitor this across every client domain you manage? ActiScan does bulk scanning, scoring, and white-labeled reporting for MSPs.
What Is a CAA Record?
A CAA (Certificate Authority Authorization) record restricts which certificate authorities are allowed to issue TLS/SSL certificates for a domain. Every publicly trusted CA is required to check for a CAA record before issuing a certificate – if one exists and doesn't list them, issuance must be refused.
- •Restricting certificate issuance to only the CA(s) you actually use
- •Reducing the risk of a mis-issued certificate from an unauthorized CA
- •Requesting a CA notify a specific email address (via the iodef tag) about issuance requests
Example
0 issue "letsencrypt.org"
Authorizes only Let's Encrypt to issue certificates for this domain.
Things to Know
No CAA record means no restriction
If a domain has no CAA record at all, any publicly trusted CA may issue a certificate for it – CAA is opt-in hardening, not a default protection.
issue vs. issuewild
The issue tag authorizes certificates for the exact domain; issuewild specifically covers wildcard certificates (*.example.com). A domain can set one, the other, or both.
Next Steps
DNSSEC Checker
Another opt-in DNS hardening layer, protecting the records themselves from tampering.
DNSSEC Checker →General DNS Checker
Look up A, AAAA, MX, TXT, CNAME, NS, SOA, or PTR records too.
General DNS Checker →Domain Security Analyzer
A full scan across every email-security record type at once, with an A-F grade.
Domain Security Analyzer →Frequently Asked Questions
Is this CAA record checker free?
Yes – look up CAA records for any domain, for free, no signup required.
Do I need a CAA record?
It's optional but recommended as a low-effort hardening step – it costs nothing and closes off issuance from any CA you haven't explicitly authorized.
I set a CAA record and now certificate renewal is failing
Confirm the CA you actually use is listed exactly as it identifies itself (e.g. "letsencrypt.org", "pki.goog", "digicert.com") – a typo or an unlisted CA will cause every future issuance attempt from that CA to be refused.
What resolver does this use?
Cloudflare's public DNS-over-HTTPS resolver. Every lookup is live, not a cached snapshot.