CAA record lookup

A CAA record names the certificate authorities permitted to issue certificates for your domain. Without one, any CA in the world may issue for you, and the first you would hear about it is a certificate you did not ask for.

Try:

Free, no signup, no daily limit. We do not store what you check here.

What a CAA record actually prevents

It does not stop an attacker who controls your DNS — they would simply change the record. What it stops is the accidental and the opportunistic: an employee obtaining a certificate through an unapproved provider, a hosting panel issuing one on your behalf, or a CA with weak validation being used against you. CAs are required to check it, so the enforcement is real even though the record itself is unauthenticated without DNSSEC.

The iodef tag nobody sets

An iodef entry gives a mailto or URL for a CA to report a failed issuance attempt. Almost nobody publishes one, which means the most useful signal — somebody just tried to obtain a certificate for your domain and was refused — goes nowhere. It costs one line and is the closest thing to an alarm on your certificates.

Questions

Will a CAA record break my automatic renewals?

It will if you forget the CA you actually use. Check which authority issues your current certificate before publishing, and remember that some providers issue through a different CA than the brand suggests.

Do subdomains inherit the record?

Yes. A CA walks up the tree from the name it is issuing for until it finds a CAA record, so one at the apex covers everything unless a subdomain publishes its own.

Related tools

When you need more than a free tool

This page answers what can be determined offline and from public DNS. The API adds live carrier and mailbox verification, a calibrated confidence score, and the full evidence trail behind every verdict.

Credits never expire. Inconclusive verdicts are never billed. Cancel in one call. See pricing or read the docs.