CAA Record Lookup
A CAA record states which certificate authorities may issue certificates for a domain. Look up any domain's CAA records across 21 global servers to confirm the policy is set and consistent.
Global DNS Propagation
New York, USA Google | --- |
Chicago, USA Gcore | --- |
Los Angeles, USA Cloudflare | --- |
Toronto, Canada CIRA | --- |
Mexico City, MX OpenDNS | --- |
London, UK Quad9 | --- |
Frankfurt, Germany DNS.Watch | --- |
Paris, France FDN | --- |
Amsterdam, NL OpenNIC | --- |
Moscow, Russia Yandex | --- |
Singapore Singtel | --- |
Tokyo, Japan IIJ | --- |
Mumbai, India Google India | --- |
Seoul, Korea KT | --- |
Dubai, UAE Etisalat | --- |
Sydney, Australia Telstra | --- |
Auckland, NZ Cloudflare | --- |
São Paulo, Brazil NIC.br | --- |
Buenos Aires, AR Telecom Arg | --- |
Johannesburg, ZA ISPA | --- |
Cairo, Egypt Telecom Egypt | --- |
DNS Map
About CAA records
A CAA (Certification Authority Authorization) record tells certificate authorities whether they are allowed to issue certificates for your domain. Before a CA issues a certificate, it checks the CAA record. If the record names a different CA, issuance is refused. This limits which authorities can mint certificates for your name.
Each row shows one of the 21 global servers and the CAA values it returned, for example 0 issue "letsencrypt.org". The issue tag allows standard certificates, issuewild covers wildcard certificates, and iodef sets a contact for reporting violations. A row with no value means the domain publishes no CAA, which lets any public CA issue.
CAA is optional but recommended. If you use one certificate authority, publishing a CAA that names only that CA reduces the risk of an unauthorized certificate. When you add or change a CAA record, confirm every region here shows the same policy before you request a new certificate, since a lagging server could cause an issuance check to fail.