CAA records and DNSSEC
Two DNS records, one of which can break your certificates if you get it wrong.
CAA
A CAA record names which certificate authorities may issue certificates for your domain. Without one, any of the hundred-plus authorities a browser trusts can.
0 issue "letsencrypt.org"
Check which authority your host uses BEFORE adding this. A CAA record that omits your host’s CA will stop your certificate renewing, which is a worse outcome than not having the record.
DNSSEC
DNSSEC signs your DNS records so a resolver can detect tampering. It matters against network-level attacks and is usually a single toggle at your registrar.
If your DNS is hosted somewhere other than your registrar, enable it at the DNS host and then add the DS record at the registrar — doing only one half leaves it inactive.
Not sure whether this applies to you?
Give us the address and we will tell you. No code, no access, no install — and every finding we have is shown in full, including on the free trial.
Check a site