CAA record checker
Avoid failed certificate renewals caused by a CAA record that does not list your current CA.
How it measures
- CAA records are fetched for the exact name; values show the critical flag and the issue, issuewild or iodef property (RFC 8659).
- No records means any CA may issue, which is the default for most domains.
Limits
- CAs walk up the name tree to the first CAA set; this tool queries only the name you enter, so check the parent domain too for subdomains.
- Whether your CA honours a given value is defined by that CA's documentation.
Troubleshooting
- Renewal fails with a CAA error
- Add an issue (and issuewild if needed) record for your CA, for example 0 issue "letsencrypt.org", and wait for the TTL before retrying.