Skip to content

CAA record checker

Avoid failed certificate renewals caused by a CAA record that does not list your current CA.

Anonymous checks are limited to 10 per minute and 60 per hour per address. Results are cached for 60 seconds and not published anywhere.

How it measures

  • CAA records are fetched for the exact name; values show the critical flag and the issue, issuewild or iodef property (RFC 8659).
  • No records means any CA may issue, which is the default for most domains.

Limits

  • CAs walk up the name tree to the first CAA set; this tool queries only the name you enter, so check the parent domain too for subdomains.
  • Whether your CA honours a given value is defined by that CA's documentation.

Troubleshooting

Renewal fails with a CAA error
Add an issue (and issuewild if needed) record for your CA, for example 0 issue "letsencrypt.org", and wait for the TTL before retrying.

Related tools