CAA Policy Checker: who can issue your certificates?

A certificate request can be blocked by a CAA policy inherited from a parent name. Enter the exact hostname to find the policy that applies and compare permission for normal and wildcard certificates. Being allowed by CAA is one requirement, not a promise that a certificate will be issued.

How to check a CAA policy

Enter the exact hostname the certificate will cover. www.example.com can give a different answer from example.com, so use the real name from the certificate request. We ask a recursive resolver for the CAA record, follow an alias if one is in the way, and then keep walking up the original name until we hit the first policy.

Where the effective policy comes from

A name does not have to carry its own CAA record. If it has one, that wins. If it does not, the check moves to its parent, then the parent above that, and stops at the first policy it finds. So the policy that governs a certificate is often written a level or two up, not on the exact name.

www.example.com → example.com → com → Policy in effect

The check climbs from the exact name toward the root and uses the first CAA policy it finds.

One thing an alias does not do: a CNAME can send the lookup to an alias target, but the alias target's parent domains do not join the original name's inheritance path. The result lists every place we looked, so you can see which record set actually won instead of guessing.

Normal and wildcard certificates

issue covers normal certificates, the ones for a specific hostname. issuewild covers wildcard certificates, the ones that match a whole level like *.example.com. If a name has no issuewild record, wildcard requests fall back to the issue policy. If a policy has only issuewild and no issue, then CAA is not restricting normal certificates at all.

How to read CAA records

FieldMeaning
issueLets the named authority issue normal certificates for the name.
issuewildLets the named authority issue wildcard certificates for the name.
iodefA mail or web address where an authority can report a policy problem it runs into.
Empty issuerAn empty issuer authorizes no authority by itself. It blocks issuance only when no other applicable record authorizes an issuer.
Critical flagIf a property is marked critical and an authority does not understand it, that authority must refuse to issue.

Several issue or issuewild records stack rather than compete. An authority can be authorized by a matching record, subject to its parameters and the other applicable CAA rules. An empty issuer does not cancel a separate authorization.

What this result does not promise

CAA is one permission gate in the process, not a list of certificates that already exist. This page does not read certificate history, contact an iodef address, or promise that an allowed authority will actually issue. That authority still has to confirm you control the domain and apply its own rules on top of the CAA answer.

The CAA specification defines policy lookup and issuer authorization. This check sends DNS queries from stack127's server, not from your network. A failed query leaves policy unresolved; use the DNS lookup or DNSSEC checker to investigate the underlying response.