CAA Record Checker & Builder
Checks which certificate authorities a domain has authorized to issue for it, walking up to the parent domain the way a real CA has to when the exact name has no CAA record of its own (RFC 8659). If a domain has none at all, any publicly trusted CA can issue a certificate for it. Build a new record below once you know which CA you actually use.
Last updated: August 30, 2026
Build a CAA record
Add the certificate authority (or authorities) you actually use. Most domains only need one "issue" line.
Generated record
Common CA hostnames
| Let's Encrypt | letsencrypt.org |
|---|---|
| DigiCert (also covers Thawte, GeoTrust, RapidSSL) | digicert.com |
| Sectigo | sectigo.com |
| Google Trust Services | pki.goog |
| Amazon (AWS Certificate Manager) | amazon.com |
| GlobalSign | globalsign.com |
Check with your hosting provider or certificate issuer if you're not sure which CA actually issues your certificates today. Publishing a CAA record that excludes it will break the next renewal.