DNS issuance control
CAA Record Generator
Read a certificate issuer and create the DNS CAA records that authorise that certificate authority.
Public certificate data only
Upload only the public certificate. Never upload a private key. Certificate data is processed for this request and is not stored in the database.
How to add the record
- Open the DNS manager for the domain shown on your certificate.
- Add each suggested record at the zone root. Most DNS providers call this host
@. - Choose record type CAA, then enter flags, tag and value exactly as shown.
- Keep existing CAA records needed by other authorised certificate authorities.
- Allow DNS time to update, verify the record, and only then rely on it for certificate issuance policy.
Important CAA tips
- CAA controls which authorities may issue future certificates; it does not change or revoke the uploaded certificate.
issuecovers normal certificates.issuewildseparately controls wildcard issuance.- An issuer name is not always the required CAA value. Confirm unfamiliar results with your CA.
- CAA records are inherited from parent DNS labels unless a more specific label has its own CAA records.
Continue with SSLassist
Explore more SSL tools
Move straight to the next certificate task without returning to the tools index.