DNSTrustCheck

← All tools

CAA Record Checker & Builder

Checks which certificate authorities a domain has authorized to issue for it, walking up to the parent domain the way a real CA has to when the exact name has no CAA record of its own (RFC 8659). If a domain has none at all, any publicly trusted CA can issue a certificate for it. Build a new record below once you know which CA you actually use.

📖 Guide: How CAA records work

Last updated: August 30, 2026

Build a CAA record

Add the certificate authority (or authorities) you actually use. Most domains only need one "issue" line.

Generated record
Common CA hostnames
Let's Encryptletsencrypt.org
DigiCert (also covers Thawte, GeoTrust, RapidSSL)digicert.com
Sectigosectigo.com
Google Trust Servicespki.goog
Amazon (AWS Certificate Manager)amazon.com
GlobalSignglobalsign.com

Check with your hosting provider or certificate issuer if you're not sure which CA actually issues your certificates today. Publishing a CAA record that excludes it will break the next renewal.