Driver FixRecommendedSound, Wi-Fi or graphics acting up? Check drivers firstFind missing or outdated drivers fast.Check DriversOctober DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsWindows FixRecommendedWindows errors stealing your time? Find the fix fastScan stability, cleanup and performance issues.Fix Now×
Skip to content
CAA records

CAA Record Lookup: Check DNS Certificate Authority Authorization

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Use dig example.com CAA +short to check which certificate authorities (CAs) DNS authorizes for a domain. If nothing is returned, check parent names and any CNAME target before concluding that issuance is unrestricted. CAA policy can explain a blocked certificate request or renewal, especially when a provider uses a CA that is missing from your allow-list.

What a CAA record controls

Certification Authority Authorization (CAA) is a DNS resource record that lets the holder of a domain specify which public CAs may issue certificates for it. Under RFC 8659, a compliant CA must check for a relevant CAA record set before issuing. This is an authorization check performed by the CA; it is separate from the certificate validation that browsers and other relying parties perform after issuance.

A restrictive policy reduces the set of CAs that can issue for your names, but it also creates an operational dependency: every CA used by your hosting, CDN, certificate manager or internal process must be represented in DNS.

Run the basic CAA lookup

Query with dig

dig example.com CAA +short
# equivalent spelling
dig example.com caa +short

Run the query for the exact fully qualified domain name (FQDN) covered by the certificate. The answer should come from the DNS service authoritative for that name. A response might look like:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
0 issue "letsencrypt.org"
0 issuewild "letsencrypt.org"
0 issue "pki.goog"
0 issue "sectigo.com"

The leading number is the CAA flags field. Most ordinary policies use 0. The tag and quoted value carry the authorization rule.

When dig returns no answer

An empty result means there is no CAA RRset at that exact DNS name. It does not by itself prove that the hostname is unrestricted. CAA processing can find a policy at a parent DNS level, and a CNAME target can contribute to the effective result. Continue with the inheritance checks below.

Understand each CAA field

Tag Purpose What to verify
issue Authorizes a CA for ordinary, non-wildcard certificates. Confirm the CA identifier matches the issuer your service actually uses.
issuewild Controls authorization for wildcard certificates. Check it separately whenever you request names such as *.example.com.
iodef Provides a reporting contact or URL for policy-violation reports. Support and handling vary by CA; verify that the issuing CA uses the destination before relying on it.

Values are CA domain identifiers, for example letsencrypt.org, pki.goog, sectigo.com or digicert.com. Multiple records can authorize multiple CAs. Do not replace a provider’s exact identifier with a guessed brand or a web URL.

Check parent domains and CNAME targets

CAA policy is found by walking from the requested FQDN toward its parents and stopping at the first level that has a CAA RRset. For shop.example.com, inspect the host and then example.com (and any intervening level that your DNS design uses).

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

If the name is an alias, query both the original name and the target. A CA can follow the CNAME target’s CAA process, and a chain may introduce policy that is not visible in the original hostname’s direct answer.

dig shop.example.com CAA +short
dig shop.example.com CNAME +short
dig target.example.net CAA +short
dig example.com CAA +short

Interpret the result

  • If the exact name has a CAA RRset, that is the relevant policy level; do not assume a parent record also expands it.
  • If the exact name has no CAA records, inspect parent levels until you find the first RRset.
  • If a CNAME is present, include the target (and each target in a chain) in your investigation.
  • For a wildcard certificate, verify the wildcard-specific rule rather than inferring it from an ordinary certificate rule.

A repeatable lookup workflow

  1. Identify every certificate name. Include the apex, subdomains, wildcard names and alternate names in the certificate request.
  2. Query each exact name. Use dig <name> CAA +short and save the output.
  3. Resolve aliases. Query CNAME +short and inspect every target’s CAA records.
  4. Walk upward. Check parent labels when the exact name has no RRset.
  5. Map identifiers to issuers. Compare each returned value with the CA identifier documented by your platform or certificate provider.
  6. Separate certificate types. Confirm both issue and issuewild when wildcard issuance is part of the design.
  7. Check from more than one resolver. Resolver differences can reveal propagation delays or split DNS views.
  8. Validate at the authoritative service. Confirm that the record is published in the DNS provider that is actually authoritative for the zone.
  9. Retry only after the CA sees the change. Do not label issuance successful until the issuing CA confirms it.

Why CAA blocks issuance or renewal

The CA is missing

A record such as 0 issue "letsencrypt.org" can reject a request from a different CA. List every CA your organization intentionally uses, including one managed automatically by a CDN, hosting platform or certificate manager, then add the required issue rule. Add issuewild as well when that CA must issue wildcards.

A stale provider-managed policy remains

Managed SSL products may add CAA records automatically when a zone already contains them. Cloudflare, for example, can add records for Universal SSL; records that are not obvious in its dashboard may still appear in dig output. The automatically included CA set can change, so consult the provider’s current documentation before hard-coding a narrow allow-list.

The wildcard rule does not match

Ordinary and wildcard authorization can differ. A hostname certificate may work while a request for *.example.com fails because the effective issuewild policy does not authorize the selected CA.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

DNS data is not the data you edited

Common causes include updating a non-authoritative DNS provider, querying a different view from the CA, an incomplete CNAME chain, DNSSEC errors or normal propagation delay. Compare authoritative answers and multiple recursive resolvers before changing policy again.

Correcting a restrictive policy safely

  • Inventory all issuance workflows before editing records.
  • Use the CA identifiers supplied by each platform; do not guess them.
  • Keep separate, explicit rules for ordinary and wildcard certificates when both are needed.
  • Do not delete an existing provider-managed rule until you know which service depends on it.
  • Apply the smallest policy that covers every intended issuer, then test a staging or renewal request.
  • Record who owns the DNS change and review the list whenever a CDN, host or certificate manager changes.

CAA changes authorize future issuance; they do not repair an already issued certificate or bypass domain-control validation. The CA still performs its normal validation and may reject a request for unrelated reasons.

Performance, reliability and operational notes

A CAA lookup is a small DNS query, but certificate automation depends on the complete DNS path: authoritative availability, delegation, DNSSEC validation, CNAME resolution and resolver caching. Keep TTL and change-management practices consistent with your renewal window. For high-risk changes, capture answers from the authoritative servers and at least two public recursive resolvers, then wait for the CA’s own check rather than relying on one local result.

CAA records do not tell a browser whether a certificate is trusted, whether a site supports modern TLS or whether a private CA is configured correctly. They only constrain which public CAs may issue according to the CA’s CAA processing.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Or skip the browser setup

If you need a visual record of a DNS-management page, certificate dashboard or deployment result, ScreenshotNeo can capture the URL with one request. It accepts cookie and consent banners before capture and removes more than 60 known consent platforms, newsletter popups and chat widgets; each step can be disabled. Bot checks, CAPTCHAs, blank pages, timeouts, failed loads and cache hits are not billed, and the response identifies the page verdict and billing status with X-Page-Verdict and X-Billed headers. An MCP server provides take_screenshot, get_page_info and capture_pdf tools for Claude, Cursor and other MCP clients.

For API parameters and the full option set, see the ScreenshotNeo documentation. A direct capture looks like this:

curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://example.com -o shot.webp
import requests
r = requests.get("https://api.screenshotneo.com/v1/shot", params={"access_key": "YOUR_API_KEY", "url": "https://example.com"}, timeout=90)
open("shot.webp", "wb").write(r.content)
const q = new URLSearchParams({ access_key: 'YOUR_API_KEY', url: 'https://example.com' });
const res = await fetch(`https://api.screenshotneo.com/v1/shot?${q}`);

Every plan includes the features: full-page and element captures, device and retina settings, PDF controls, custom CSS and JavaScript, waits, request blocking, headers and cookies, geolocation and timezone, resizing, caching, signed links, asynchronous webhooks, bulk capture of up to 100 URLs per call, usage data and an OpenAPI specification. The parameter names used by other screenshot APIs also work. The Free plan includes 1,000 screenshots per month with no card; paid plans start at $5 for 3,000. Create a free ScreenshotNeo account.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

CAA lookup troubleshooting checklist

Symptom Likely cause Fix
dig is empty but issuance is denied Policy exists on a parent or CNAME target. Walk parents and query every CNAME target.
One provider works and another fails The failing CA is not authorized. Add its documented identifier to the appropriate tag.
Regular certificate works; wildcard fails issuewild is absent or restrictive. Define and verify wildcard authorization separately.
Different resolvers disagree Propagation, split DNS or DNSSEC trouble. Query authoritative servers, compare recursive answers and correct delegation or signing errors.
Renewal still fails after editing The CA has not observed the change, or another validation error remains. Wait for propagation, inspect the CA’s diagnostic, and retry only after its check succeeds.

FAQ

Does a CAA record encrypt my website?

No. CAA controls which public CA may issue; encryption and browser trust come from the certificate and TLS configuration that follow.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Can I authorize more than one CA?

Yes. Publish multiple CAA records, provided each identifier is intentional and maintained.

Should I publish an iodef record?

Only if you have confirmed that the relevant CAs support and handle reports sent to the chosen destination.

Will removing CAA revoke an existing certificate?

No. It changes authorization for subsequent issuance; revocation is a separate CA operation.

The Bottom Line

Start with dig <certificate-name> CAA +short, then check parent levels, CNAME targets and wildcard-specific policy. A missing issuing CA in the effective RRset is a common, fixable cause of blocked issuance.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Read next

Recommended PC Tool
Recommended PC Tool
Windows Errors? Fix Them Before They SpreadFree repair scan
Outdated Drivers Are Slowing You DownFree scan - exact matches

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.