DNSFly

CAA Record Lookup

A CAA record states which certificate authorities may issue certificates for a domain. Look up any domain's CAA records across 21 global servers to confirm the policy is set and consistent.

CAA

Global DNS Propagation

US flag
New York, USA Google
---
US flag
Chicago, USA Gcore
---
US flag
Los Angeles, USA Cloudflare
---
CA flag
Toronto, Canada CIRA
---
MX flag
Mexico City, MX OpenDNS
---
GB flag
London, UK Quad9
---
DE flag
Frankfurt, Germany DNS.Watch
---
FR flag
Paris, France FDN
---
NL flag
Amsterdam, NL OpenNIC
---
RU flag
Moscow, Russia Yandex
---
SG flag
Singapore Singtel
---
JP flag
Tokyo, Japan IIJ
---
IN flag
Mumbai, India Google India
---
KR flag
Seoul, Korea KT
---
AE flag
Dubai, UAE Etisalat
---
AU flag
Sydney, Australia Telstra
---
NZ flag
Auckland, NZ Cloudflare
---
BR flag
São Paulo, Brazil NIC.br
---
AR flag
Buenos Aires, AR Telecom Arg
---
ZA flag
Johannesburg, ZA ISPA
---
EG flag
Cairo, Egypt Telecom Egypt
---

DNS Map

0 0

About CAA records

A CAA (Certification Authority Authorization) record tells certificate authorities whether they are allowed to issue certificates for your domain. Before a CA issues a certificate, it checks the CAA record. If the record names a different CA, issuance is refused. This limits which authorities can mint certificates for your name.

Each row shows one of the 21 global servers and the CAA values it returned, for example 0 issue "letsencrypt.org". The issue tag allows standard certificates, issuewild covers wildcard certificates, and iodef sets a contact for reporting violations. A row with no value means the domain publishes no CAA, which lets any public CA issue.

CAA is optional but recommended. If you use one certificate authority, publishing a CAA that names only that CA reduces the risk of an unauthorized certificate. When you add or change a CAA record, confirm every region here shows the same policy before you request a new certificate, since a lagging server could cause an issuance check to fail.