All Security Checks
DNSMedium PriorityPro
CAA DNS Records
Certificate Authority Authorization records specify which CAs are allowed to issue certificates for your domain.
Why It Matters
CAA prevents unauthorized certificate issuance. If an attacker compromises a CA you don't use, they still can't get certificates for your domain.
How We Check
We query CAA DNS records and verify they restrict certificate issuance to your intended CAs.
How to Fix
Add CAA records specifying allowed CAs: example.com. CAA 0 issue 'letsencrypt.org'. Add iodef for violation reporting.
Related Security Checks
Check Your Website Now
Run a free security scan to check for CAA DNS Records issues and 58+ other security vulnerabilities.
Scan Your Website Free