Check CAA records instantly across global resolvers to validate your SSL/TLS certificate issuance policies.
If your web host or service like AutoSSL/Let's Encrypt is failing to generate or renew a security certificate for your domain, an overly restrictive CAA record is often the cause. Enter your domain name above to instantly query its active CAA records. This confirms which Certificate Authorities (CAs) are officially permitted to issue SSL/TLS certificates for your site.
digicert.com, but you are trying to install a free certificate from letsencrypt.org, the issuance will fail. You must add an additional CAA record specifically authorizing Let's Encrypt.issue tag), but explicitly forbid wildcard certificates (using the issuewild tag).Learn how CAA records protect your site from rogue SSL certificates, and understand what the issue, issuewild, and iodef tags mean.
Read the CAA Record WikiCAA records restrict which certificate authorities are allowed to issue certificates for a domain. They help prevent unauthorized issuance and give domain owners more control over TLS certificates. A CAA lookup lets you confirm which CAs are permitted and whether contact or reporting directives are present.
Common issues include forgetting to include the CA you use, misconfiguring the issuewild directive for wildcard certificates, or publishing conflicting CAA entries. If a CA is not listed, certificate issuance may fail. This lookup helps confirm the policy before renewal or rollout.
If you need related checks, try SSL/PKI DNS check validator and SSL certificate check validator.
issue controls normal certificates, while issuewild applies specifically to wildcard certificates. If issuewild is absent, issue may apply to both depending on CA behavior.
iodef provides a reporting URI for CAA violations. It is optional but useful for monitoring unexpected issuance attempts.
The CA you used may not be authorized by your CAA policy. Update CAA to include the correct CA or adjust your provider.
Yes. CAA policies are inherited down the domain tree unless overridden by a more specific record.
Yes. You can publish multiple issue directives to allow more than one CA.
CAA is subject to normal DNS caching. Allow for TTL propagation before retrying issuance.