🔐 DNS CAA Record Lookup
Query DNS CAA (Certification Authority Authorization) records to see which certificate authorities are authorized to issue SSL/TLS certificates for a domain.
What a CAA record controls
A CAA record names the certificate authorities allowed to issue a certificate for a domain. It is read by the CA at the moment you ask for a certificate, and by nobody else — browsers never look at it, so it changes nothing for visitors and cannot revoke a certificate that already exists. Its whole job is to stop some other CA issuing for your name.
Each record is a flag, a tag and a value. The tool shows the tag beside the value it carries:
| Tag | Meaning |
|---|---|
issue | This CA may issue certificates for the name |
issuewild | This CA may issue wildcard certificates |
iodef | Where to report a refused request, usually a mailto: |
A value of ";" against issue means the opposite of
permission: no CA at all may issue.
Reading the lookup
The query runs on SimpleMoney's server, not in your browser, so you are seeing what a certificate authority anywhere on the internet would see when it checks your domain — which is the view that actually matters here.
An empty result is the normal case and not a fault. Most domains publish no CAA record, and the rule is permissive by default: with nothing published, any public CA may issue.
shop.example.com with no record of its own, a CA falls back to
example.com. This tool asks only about the exact name you type,
so look up the parent too before concluding there is no policy.Frequently asked questions
What happens if a domain has no CAA record?
Any publicly trusted CA may issue for it. CAA is opt-in: the absence of a record is read as no restriction, not as a refusal.
Will adding a CAA record break my existing certificate?
No. Certificates already issued keep working. The risk is at renewal — if the CA your host renews with is not listed, issuance fails, so check who actually issues for you before publishing.
Does a CAA record protect visitors to my site?
Not directly. No browser checks it. It reduces the chance of a mis-issued certificate existing at all, which is a different and earlier kind of protection.