CAA Record Generator

CAA DNS Record āļ„āļ·āļ­āļ­āļ°āđ„āļĢ

āļœāļđāđ‰āļ­āļ­āļāđƒāļšāļĢāļąāļšāļĢāļ­āļ‡ SSL āļĄāļĩāļāļēāļĢāļāļģāļŦāļ™āļ” āļĄāļēāļ•āļĢāļāļēāļ™āđƒāļŦāļĄāđˆÂ āđƒāļŦāđ‰āđ€āļˆāđ‰āļēāļ‚āļ­āļ‡āđ‚āļ”āđ€āļĄāļ™āđ€āļ™āļĄ āļ•āđ‰āļ­āļ‡āļ—āļģāļāļēāļĢāđ€āļžāļīāđˆāļĄ CAA Record āđ€āļžāļ·āđˆāļ­āđāļˆāđ‰āļ‡āđƒāļŦāđ‰āļ™āļēāļĒāļ—āļ°āđ€āļšāļĩāļĒāļ™ SSL āļ—āļĢāļēāļšāļ§āđˆāļē āđ‚āļ”āđ€āļĄāļ™āļ‚āļ­āļ‡āļ—āđˆāļēāļ™āļ­āļ™āļļāļāļēāļ•āļīāļ™āļēāļĒāļ—āļ°āđ€āļšāļĩāļĒāļ™ SSL āđāļšāļĢāļ™āļ”āđŒāđƒāļ”āļŠāļēāļĄāļēāļĢāļ–āļ­āļ­āļāđƒāļšāļĢāļąāļšāļĢāļ­āļ‡ SSL Certificate āđƒāļŦāđ‰āđ„āļ”āđ‰āļšāđ‰āļēāļ‡Â 

āļĒāļĩāđˆāļŦāđ‰āļ­āđƒāļšāļĢāļąāļšāļĢāļ­āļ‡ SSL Certificate  DNS Type   Flags  Tag     Value/Answer/Destination    
Digicert CAA 0 issue digicert.com
GlobalSign, AlphaSSL CAA 0 issue globalsign.com
Entrust CAA 0 issue entrust.net
GeoTrust CAA 0  issue  geotrust.com
Thawte CAA 0 issue thawte.com
RapidSSL CAA 0 issue rapidssl.com
Sectigo , Comodo CAA 0 issue sectigo.com
Godaddy    CAA 0 issue starfieldtech.com

āđ€āļ„āļĢāļ·āđˆāļ­āļ‡āļĄāļ·āļ­āļŠāđˆāļ§āļĒāļŠāļĢāđ‰āļēāļ‡ CAA DNS Record


CA Name Non-Wildcard Wildcard
DigiCert
(Symantec, GeoTrust, Thawte, RapidSSL)
Comodo
(Sectigo)
āļ•āļīāđŠāļ None-Wildcard āđāļĨāļ° Wildcard āļŦāļĄāļēāļĒāļ–āļķāļ‡ āđƒāļŦāđ‰ CAA Record āļ„āļĢāļ­āļšāļ„āļĨāļļāļĄāļ–āļĩāļ‡āđ‚āļ”āđ€āļĄāļ™āļŦāļĨāļąāļ āđāļĨāļ° Sub-Domain āļ—āļļāļāļ•āļąāļ§


Certification Authority Authorization (CAA) is a powerful record in your DNS settings that allows you to control which Certificate Authorities (CA) can issue SSL certificates for specific domains in your organization. Think of the record as your domain’s medical record. Hospitals will refer to the record before issuing any remedies to ensure they’re not providing you with any medicine that might trigger an allergic reaction! The same concept applies with CAA Records, but with domains and SSL certificates - and a lot less nausea.

Starting September 8, 2017, CAs will be required by the industry’s governing body to check the CAA record before issuing any type of SSL certificates (DV, OV, EV) for your domain(s). This DNS setting allows organizations to further protect their brand reputation, security integrity, and customers’ trust, while minimizing the possibilities of finding random expired SSL certificates from rogue employees.

Let’s face it. Nobody ever wants to have their website down because of an SSL Certificate issue. Nobody wants to miss out on revenue. So, let’s prevent those issues and specify your CAA Record today!

Using your Domain Registrar’s DNS or another Service?

No worries! Many of the most popular domain registrars and DNS providers support CAA Records, with many more adopting the record on a daily basis! Below is a brief overview of some of the largest providers of DNS services that support CAA Records. Don’t see your provider? Drop them a support ticket and ask

- cPanel v66+

- Cloudflare

- DNS Made Easy

- DYN Managed DNS

- Gandi

- Hurricane Electric (HE) DNS

- Amazon Route 53