CAA records
A CAA record controls which certificate authorities are allowed to issue SSL/TLS certificates for your domain.
What it is
Any certificate authority (CA) can technically issue a certificate for any domain. A CAA (Certification Authority Authorization) record narrows that down: it names the specific CAs you trust to issue certificates for you, and tells every other CA to refuse.
It's a small DNS record that acts as a guardrail against certificates being issued for your domain without your knowledge.
Why it matters
If an attacker — or a mistaken CA — issues a certificate for your domain, they can impersonate your site convincingly over HTTPS. A CAA record shrinks that attack surface by allowing only the authorities you actually use, so a rogue certificate from anyone else is refused at issue time.
How Pentrawl checks it
Pentrawl looks up the CAA records for your domain. If one or more are present, the check passes. If none are set, we flag it as an informational finding — it's a hardening measure rather than a critical fault.
How to fix it
Add a CAA record through your DNS provider, naming the certificate authority you use (for example Let's Encrypt). You can list multiple authorities if you use more than one.
yourdomain.com. CAA 0 issue "letsencrypt.org"