CAA Record Lookup

Free IPMYP account Save your results with a free account

Create a free account to unlock more allowance, saved reports, and trial API access.

Live lookup
Active tool
CAA
Checks CAA records and authorized certificate authorities.
Ready Ready to run a new check.
CAA records and authorized certificate authorities are checked.
Tool output
The exact result for the selected operation appears here.

        

Use the CAA Record Lookup tool to check which Certificate Authorities are allowed to issue SSL certificates for a domain. CAA records help domain owners control SSL certificate issuance and reduce the risk of unauthorized certificates being created for their domain.

If you manage a website, SaaS platform, ecommerce store, API, or business domain, checking CAA records can help you confirm whether your SSL certificate policy is correctly published in DNS.

If you first need to confirm the IP address currently visible from your own connection, you can check your current public IP Address before reviewing DNS security records.

What Is a CAA Record?

A CAA record, short for Certification Authority Authorization, is a DNS record that tells Certificate Authorities which organizations are allowed to issue SSL or TLS certificates for a domain.

For example, if a domain has a CAA record that only allows Let’s Encrypt, then other certificate authorities should not issue certificates for that domain unless they are also authorized in DNS.

CAA records are especially useful for improving domain security, controlling SSL issuance, and reducing the chance of certificate misissuance.

Why CAA Records Matter

SSL certificates are essential for secure HTTPS connections. But without a CAA policy, more certificate authorities may be able to issue certificates for your domain. A properly configured CAA record gives domain owners more control over who can issue certificates.

CAA records are useful for:

  • Restricting SSL certificate issuance to approved Certificate Authorities.
  • Improving domain and HTTPS security.
  • Supporting compliance and security audit requirements.
  • Reducing the risk of unauthorized or unexpected certificate issuance.
  • Documenting which CA should be used for domain certificates.

How to Use the CAA Record Lookup Tool

Using the IPMYP CAA Record Lookup tool is simple and does not require command-line tools or DNS software.

  1. Enter a domain name, such as example.com.
  2. Run the CAA record check.
  3. IPMYP sends a DNS query for the domain’s CAA records.
  4. Review the result to see which certificate authorities are authorized.
  5. Use the result to confirm whether your SSL issuance policy is configured correctly.

For a broader technical review that includes DNS records, SSL, WHOIS, Ping, Traceroute, MTR, and related checks, use the main online network tools hub.

What Information Does a CAA Report Show?

A CAA lookup report may show several important DNS fields.

  • Host: The domain being checked.
  • Type: The DNS record type, which should be CAA.
  • Flag: A numeric value that controls record behavior.
  • Tag: The CAA property, such as issue, issuewild, or iodef.
  • Value: The Certificate Authority or reporting endpoint defined in the record.
  • TTL: The Time To Live value for DNS caching.

Common CAA Tags

issue

The issue tag defines which Certificate Authority is allowed to issue normal SSL certificates for the domain.

example.com. CAA 0 issue "letsencrypt.org"

issuewild

The issuewild tag defines which Certificate Authority is allowed to issue wildcard certificates for the domain.

example.com. CAA 0 issuewild "digicert.com"

iodef

The iodef tag can define a reporting address where Certificate Authorities may send incident reports related to certificate issuance problems.

example.com. CAA 0 iodef "mailto:[email protected]"

When Should You Check CAA Records?

CAA record lookup is useful whenever you need to verify SSL certificate issuance policy for a domain.

  • Before issuing or renewing an SSL certificate.
  • After changing SSL providers.
  • After moving DNS to a new provider.
  • During website security audits.
  • When SSL certificate issuance fails unexpectedly.
  • When reviewing HTTPS security for business-critical domains.

CAA Records and SSL Certificate Issues

If your SSL provider cannot issue a certificate, a restrictive CAA record may be one possible reason. For example, if your domain only authorizes one Certificate Authority, another provider may reject the certificate request.

After checking CAA records, you may also want to use the SSL Checker to verify certificate validity, expiry date, issuer, domain match, and certificate chain status.

CAA Records and DNS Security

CAA records are one part of a stronger DNS and HTTPS security setup. They do not encrypt DNS by themselves and they do not replace DNSSEC, but they help control who can issue SSL certificates for your domain.

For a more complete DNS security review, also check DNSSEC, Email Security Records, and DNS Delegation.

Common CAA Record Problems

  • No CAA record exists when a strict SSL issuance policy is required.
  • The wrong Certificate Authority is listed.
  • Wildcard certificates are blocked because issuewild is missing or restrictive.
  • The CAA record was added to the wrong DNS provider.
  • DNS cache still returns older CAA values.
  • The record syntax is malformed.

Frequently Asked Questions

What does a CAA Record Lookup do?

A CAA Record Lookup checks the DNS CAA records of a domain and shows which Certificate Authorities are authorized to issue SSL certificates for that domain.

Do I need a CAA record?

A CAA record is not required for every basic website, but it is recommended for domains that need stronger control over SSL certificate issuance.

Can CAA records block SSL issuance?

Yes. If a CAA record only authorizes specific Certificate Authorities, other providers may not be allowed to issue certificates for the domain.

What is the difference between CAA and SSL Checker?

CAA checks DNS policy for certificate issuance. SSL Checker inspects the actual certificate installed on a website.

Should I check CAA before renewing SSL?

Yes. If you recently changed DNS or SSL providers, checking CAA records before renewal can help avoid certificate issuance failures.

Check CAA Records Online With IPMYP

IPMYP’s CAA Record Lookup tool helps you quickly check which Certificate Authorities are allowed to issue SSL certificates for your domain. Enter a domain above, run the check, and review the CAA policy to confirm that your domain’s SSL issuance settings are correct.