Skip to main content

Viewing the certificate issuance authority record for the current name does not replace the complete issuance policy check.

Only public DNS records are supported, please do not fill in internal or sensitive domain names.

No query has been made, filling in or loading examples will not initiate a request.

Instructions for use

  1. Enter the name you want to view and click Query CAA records.
  2. Read the original records and query status of issue, issuewild, iodef, etc.
  3. View records, TTL, status and query time, which can be copied or cleared; modifying the input will cancel the old query.

Input and output examples

Example input
example.com,CAA
Example output
0 issue "ca.example"

The above is a demonstration only, not real-time results. Public DNS records change, and an empty response has different meanings than a failed query.

FAQ

You can't judge like this. This tool only looks at the current name response and does not fully implement the parent domain inheritance and alias chain rules; the actual issuance is also subject to other policy restrictions.

Calculation basis and reference materials

Read the original records and query status of issue, issuewild, iodef, etc.

Content check: · About this site and content description

Related tools