Developer · Validator
CAA record checker & generator.
Paste CAA lines from your DNS zone to check flags, tags and values against RFC 8659, with a plain reading of which certificate authorities may issue. Or build records from the CA identifiers you type. Runs in your browser; nothing is sent anywhere and no DNS lookup is made.
Check records
Generate records
Result
Paste records and press Check, or fill in the generator.
What a CAA record says, and what this tool checks
A CAA record tells certificate authorities (CAs) which of them may issue certificates for a domain. Each record has three fields: flags, a tag and a value, written as CAA 0 issue "ca.example.net".
Flags is a number from 0 to 255. Only one bit is defined: 128 is the issuer critical flag. All other bits are reserved and records should leave them at 0. If a critical property has a tag the CA does not understand, the CA must not issue for that name.
Tag is at least one character, using only a-z, A-Z and 0-9. Matching ignores case. RFC 8659 defines three: issue, issuewild and iodef.
issue authorizes the CA whose issuer domain name you give. The value may be followed by a semicolon and name=value parameters that the CA defines. A bare ";" authorizes nobody. Several issue records add up. A value that does not match the grammar is treated as empty, so it blocks issuance.
issuewild has the same syntax but covers wildcard names only. If any issuewild record exists, issue records are ignored for wildcard names.
iodef is a URL where CAs may report requests that violate your policy. The only defined schemes are mailto:, http: and https:.
If the records for a name contain no issue or issuewild property (for example, only iodef), CAA does not restrict issuance. A value with spaces must be in quotes.
Not covered: tags defined after RFC 8659 are shown as unknown; a CA that supports them may treat them differently. This tool does not climb the DNS tree, follow CNAMEs or know which CAs exist, so it never guesses a CA's identifier.
Source: RFC 8659, sections 3, 4.1 to 4.5 (syntax, issue, issuewild, iodef, critical flag). Read against the published text, 2026-09-30.
Frequently asked questions
What does issue ";" do?
It is an issue record with no CA named, which asks every CA not to issue. If you also list a real CA in another issue record, that CA is still authorized, because authorizations add up.
Do I need issuewild?
Only if wildcard certificates should follow a different rule. Without issuewild, your issue records cover wildcard names too.
What happens with flags 128 and an unknown tag?
A CA that does not support that tag must not issue for the name. Most people should use flags 0.
Where do I find my CA's identifier?
In your CA's documentation. It is the issuer domain name to put after issue. This tool does not list them, so check your CA's own page.
Does a valid result mean my CAA is live?
No. It means the text follows the RFC 8659 format. The tool makes no DNS query, so it cannot tell whether the records are published, or whether a CA will honour them.
Format check only
This tool checks record text against RFC 8659 and does not query DNS. A pass confirms format, not that the records are published or that any CA will issue or refuse a certificate.