CAA Record Checker
This tool requires network access: only public information such as the domain is sent to our server. No private key or CSR is ever uploaded.
CAA records can block unauthorized CAs from issuing certificates for your domain.
About CAA Record Checker
The CSR.plus CAA Record Checker queries a domain’s DNS CAA records to reveal which Certificate Authorities are permitted to issue certificates for it. Enter a hostname to see the issuer list and flags, and confirm that only the CAs you trust are authorised.
A CAA record is a simple, powerful control: it tells every CA which issuers may certificate your domain, and it is checked by certificate authorities before issuance. Administrators use this online CAA lookup to verify a policy was published correctly, to audit what third parties could issue for their domains, and to harden their certificate posture.
Why use
- Verify which CAs are authorised to issue certificates for your domain
- Confirm a published CAA policy is correct and complete
- Audit third parties that could issue for your domains
- Instant DNS lookup — no account or configuration required
How to use
- Enter the domain to query (for example example.com).
- The tool performs a DNS lookup for CAA records.
- Review the listed issuers and flags (issue, issuewild, iodef).
- Confirm only trusted CAs are authorised — add records for missing ones if needed.
Frequently asked questions
▸What is a CAA record?
A DNS record that specifies which CAs are allowed to issue certificates for a domain.
▸If no CAA record exists, who can issue?
Any publicly trusted CA may issue, because the absence of CAA means no restriction is set.
▸Can CAA block all issuance?
You can restrict issuance to specific CAs, but you cannot use CAA to forbid every CA while still obtaining certificates.
▸What do the CAA tags mean?
issue restricts domain certificates, issuewild restricts wildcard certificates, and iodef provides a contact address for policy violation reports.
Namecheap
Need a new SSL certificate?
DV, OV, EV and wildcard certificates from just $5.98/yr — issued in minutes.
Affiliate link — we may earn a commission at no extra cost to you.
More free tools
Certificate Viewer
Paste or upload an X.509 certificate to inspect its subject, issuer, validity, key, fingerprints, SAN and extensions — all locally.
Certificate / Key Matcher
Check whether a private key and a certificate belong to the same key pair — computed locally, the key never leaves your browser.
PEM Viewer
Paste a PEM bundle (certificates, keys, CSRs) and see a structured breakdown of every block — locally.
SSL Format Converter
Convert between PEM, PFX/PKCS#12 and P7B/PKCS#7 — all locally in your browser.
SSL Checker (A-F Grade)
Grade any domain from A to F: TLS versions, certificate health, chain trust and HSTS.
SSL Bulk Checker
Check multiple SSL certificates at once
ACME Challenge Preflight
Test HTTP-01 and DNS-01 validation before Let's Encrypt does: DNS, port 443, well-known reachability and TXT records with fix suggestions.
Let's Encrypt Checker
Detect Let's Encrypt certificates (R3/R10/E5/E6), see the 90-day renewal countdown, chain health and renewal advice.
DNS Propagation Checker
Check TXT, A, AAAA, NS and MX records across Cloudflare, Google and AdGuard resolvers and confirm propagation.
LE Chain Compatibility
See whether your site serves the new ISRG E5/E6 chain or the legacy cross-signed chain and whether old devices trust it.
ACME Command Generator
Generate copy-paste issuance commands for Certbot, acme.sh, lego and win-acme with HTTP-01 or DNS-01.
Certificate Inspector
Enter a domain to inspect certificate validity, expiry, TLS protocol and full chain integrity.
SSL Expiry Checker
Quickly check a domain's SSL certificate expiry date and remaining days.
Certificate Transparency Lookup
List every certificate ever issued for a domain in public CT logs — discover shadow and unauthorized certs.
Certificate Revocation Checker
Verify whether a certificate has been revoked via its CRL distribution points, and view embedded OCSP endpoints.
SSL Handshake Tracer
Perform a real TLS handshake and record every step: DNS, TCP, negotiated TLS version and cipher, and each certificate returned.