What is a CAA record?
DNS is like a phone book for the internet. It turns a website name into a number that computers understand. Each entry is called a record.
An SSL certificate is the padlock that keeps a website safe. A Certificate Authority, or CA, is a company that hands out those certificates.
A CAA record (Certificate Authority Authorization) is like a guest list. It tells the world which CAs may issue certificates for your domain. A CA must check the list first. If it is not on the list, it should refuse.
If you have no CAA record, any CA may issue a certificate. Adding one is optional, but it adds safety.
Parts of a CAA record
- Flag: usually
0. - Tag:
issueallows normal certificates.issuewildallows wildcard certificates (they cover all subdomains).iodefgives an address for reports. - Value: the CA's domain name, such as
letsencrypt.org.
Before you start
Edit DNS where your nameservers point. Know which CA issues your certificate. If you are not sure, ask Hostvento support. If you block your CA by mistake, certificate renewal can fail.
Add a CAA record
- Log in to the client area.
- Open the DNS zone editor for your domain.
- Click to add a record.
- Set Type to CAA.
- In Name, enter your domain, or
@if the editor uses it. - Set Flag to
0. - Set Tag to
issue. - In Value, type the CA's name. For example,
letsencrypt.org. - Click Save.
Repeat for each CA you want to allow.
Edit or delete
- Find the record in the list.
- Click Edit to change it, or Delete to remove it.
Check it
dig example.com CAA
This asks DNS for the CAA records of your domain.
Quick recap
- A CAA record lists which CAs may issue certificates for your domain.
- Use tag
issuewith the CA's name as the value. - Always include the CA you really use.
- Check with
dig example.com CAA.