Viewing the certificate issuance authority record for the current name does not replace the complete issuance policy check.
Only public DNS records are supported, please do not fill in internal or sensitive domain names.
No query has been made, filling in or loading examples will not initiate a request.
The above is a demonstration only, not real-time results. Public DNS records change, and an empty response has different meanings than a failed query.
You can't judge like this. This tool only looks at the current name response and does not fully implement the parent domain inheritance and alias chain rules; the actual issuance is also subject to other policy restrictions.
Read the original records and query status of issue, issuewild, iodef, etc.
Content check:2026-09-08 · About this site and content description