Flash Sale:75% Off Hosting + Free DomainEnds in13h47m14sView Plans
Hostvento logoHostvento

How to add, edit or delete a CAA record

This guide explains CAA records and shows you how to manage them. They decide which companies may issue SSL certificates for your domain.

How-To Guides2 min read11 steps

What is a CAA record?

DNS is like a phone book for the internet. It turns a website name into a number that computers understand. Each entry is called a record.

An SSL certificate is the padlock that keeps a website safe. A Certificate Authority, or CA, is a company that hands out those certificates.

A CAA record (Certificate Authority Authorization) is like a guest list. It tells the world which CAs may issue certificates for your domain. A CA must check the list first. If it is not on the list, it should refuse.

If you have no CAA record, any CA may issue a certificate. Adding one is optional, but it adds safety.

Parts of a CAA record

  • Flag: usually 0.
  • Tag: issue allows normal certificates. issuewild allows wildcard certificates (they cover all subdomains). iodef gives an address for reports.
  • Value: the CA's domain name, such as letsencrypt.org.

Before you start

Edit DNS where your nameservers point. Know which CA issues your certificate. If you are not sure, ask Hostvento support. If you block your CA by mistake, certificate renewal can fail.

Add a CAA record

  1. Log in to the client area.
  2. Open the DNS zone editor for your domain.
  3. Click to add a record.
  4. Set Type to CAA.
  5. In Name, enter your domain, or @ if the editor uses it.
  6. Set Flag to 0.
  7. Set Tag to issue.
  8. In Value, type the CA's name. For example, letsencrypt.org.
  9. Click Save.

Repeat for each CA you want to allow.

Edit or delete

  1. Find the record in the list.
  2. Click Edit to change it, or Delete to remove it.
Warning: Copy your current records first. If you add a CAA record that leaves out your real CA, new certificates will fail.

Check it

dig example.com CAA

This asks DNS for the CAA records of your domain.

Quick recap

  • A CAA record lists which CAs may issue certificates for your domain.
  • Use tag issue with the CA's name as the value.
  • Always include the CA you really use.
  • Check with dig example.com CAA.