← Reference

CAA records and DNSSEC

Two DNS records, one of which can break your certificates if you get it wrong.

01

CAA

A CAA record names which certificate authorities may issue certificates for your domain. Without one, any of the hundred-plus authorities a browser trusts can.

0 issue "letsencrypt.org"

Check which authority your host uses BEFORE adding this. A CAA record that omits your host’s CA will stop your certificate renewing, which is a worse outcome than not having the record.

02

DNSSEC

DNSSEC signs your DNS records so a resolver can detect tampering. It matters against network-level attacks and is usually a single toggle at your registrar.

If your DNS is hosted somewhere other than your registrar, enable it at the DNS host and then add the DS record at the registrar — doing only one half leaves it inactive.

Not sure whether this applies to you?

Give us the address and we will tell you. No code, no access, no install — and every finding we have is shown in full, including on the free trial.

Check a site