Skip to content
Inspect My DNS

Web & TLS

CAA permits the current CA

web.caa-issuer

A CA not named in CAA must refuse to issue, so a record that omits the CA serving the site breaks the next renewal.

What this check measures

This check compares two things the scan already has: the CAA records at the apex, and the certificate authority that issued the certificate the site is serving right now. If the CAA records restrict issuance and do not name that CA, nothing is wrong today — the certificate is already issued and browsers never read CAA. The failure arrives at renewal: every publicly trusted CA is required to check CAA before issuing, and the one renewing this certificate will find itself excluded and refuse.

That makes it one of the quieter outages. Automated renewal fails in a log nobody reads, the old certificate runs out a few weeks later, and the site goes dark behind a browser interstitial with no change anywhere near it. The usual cause is a CAA record written for one CA while a CDN, load balancer or hosting platform in front of the site issues from another — issue "digicert.com" over an edge certificate Cloudflare obtained from Google Trust Services or Let’s Encrypt, for example.

The CA is identified by the organisation in the certificate’s issuer, not its common name, because intermediates are renamed every time a CA rotates them while the organisation stays put. The CAA identifiers each CA recognises come from the CA’s own declaration in the Common CA Database. A CA we have no mapping for produces no result rather than a guess.

For a certificate that includes a wildcard name, issuewild takes precedence over issue when the domain publishes any (RFC 8659 §4.3), so both property sets are checked against the issuer. An issue ";" record, which forbids every CA, is reported whoever issued the current certificate. Parameters after the identifier, such as accounturi or validationmethods, can narrow issuance further and are not graded here.

How to fix it

Add a record naming the CA that is issuing today, alongside the ones already there — for example 0 issue "letsencrypt.org", or 0 issue "pki.goog" for Google Trust Services. CAA records are additive: each issue record authorises one more CA.

If the certificate includes a wildcard and the domain publishes issuewild, add the same identifier there too.

If the CA in the record is the one you mean to use, the record is right and the renewal path is not: change whatever provisions this certificate — the CDN’s certificate settings, the load balancer, the ACME client — to use that CA before the current certificate expires.

Before narrowing CAA anywhere, check the Certificate Transparency logs for every CA that has issued for the domain and its subdomains in the last year. Anything automatic shows up there.

References

Run this check on a domain

CAA permits the current CA is one of 62 checks in every report, alongside delegation, mail authentication, TLS and registration.