DeNiSe using a certificate machine to create a protected DNS record in a data centre
DNS issuance control

CAA Record Generator

Read a certificate issuer and create the DNS CAA records that authorise that certificate authority.

Public certificate data only
Upload only the public certificate. Never upload a private key. Certificate data is processed for this request and is not stored in the database.
CRT, CER, PEM or DER certificate, maximum 2 MB.
or paste a certificate
Use only a value confirmed by the certificate authority.

How to add the record

  1. Open the DNS manager for the domain shown on your certificate.
  2. Add each suggested record at the zone root. Most DNS providers call this host @.
  3. Choose record type CAA, then enter flags, tag and value exactly as shown.
  4. Keep existing CAA records needed by other authorised certificate authorities.
  5. Allow DNS time to update, verify the record, and only then rely on it for certificate issuance policy.

Important CAA tips

  • CAA controls which authorities may issue future certificates; it does not change or revoke the uploaded certificate.
  • issue covers normal certificates. issuewild separately controls wildcard issuance.
  • An issuer name is not always the required CAA value. Confirm unfamiliar results with your CA.
  • CAA records are inherited from parent DNS labels unless a more specific label has its own CAA records.