security / dns & domain / caa records
DNS & domain

CAA records

A CAA record controls which certificate authorities are allowed to issue SSL/TLS certificates for your domain.

Severity if missing
Low
Category
DNS & domain
Standard
RFC 8659

What it is

Any certificate authority (CA) can technically issue a certificate for any domain. A CAA (Certification Authority Authorization) record narrows that down: it names the specific CAs you trust to issue certificates for you, and tells every other CA to refuse.

It's a small DNS record that acts as a guardrail against certificates being issued for your domain without your knowledge.

Why it matters

If an attacker — or a mistaken CA — issues a certificate for your domain, they can impersonate your site convincingly over HTTPS. A CAA record shrinks that attack surface by allowing only the authorities you actually use, so a rogue certificate from anyone else is refused at issue time.

The risk
Without a CAA record, any certificate authority in the world can issue a certificate for your domain, increasing the risk of mis-issued or fraudulent certificates.

How Pentrawl checks it

Pentrawl looks up the CAA records for your domain. If one or more are present, the check passes. If none are set, we flag it as an informational finding — it's a hardening measure rather than a critical fault.

How to fix it

Add a CAA record through your DNS provider, naming the certificate authority you use (for example Let's Encrypt). You can list multiple authorities if you use more than one.

Example (Let's Encrypt)
yourdomain.com. CAA 0 issue "letsencrypt.org"
Check your domain's CAA records in seconds
Pentrawl scans this and 20+ other security checks in one automated pass.
Scan your website →