Skip to content

CAA Record Checker

Enter a domain and Nivaronix looks up its CAA (Certification Authority Authorization) record to report whether certificate issuance is restricted to specific CAs, or open to any public CA by default.

What this checker reports

  • CAA records published — the domain names the specific certificate authorities allowed to issue for it; other CAs must refuse.
  • No CAA record — nothing is published, so any public CA may issue a certificate for the domain. This is not an active vulnerability, it removes a cheap safety net rather than opening a hole.
  • Status could not be determined — the CAA lookup timed out or a nameserver failed to answer; some older resolvers cannot return CAA records at all, and this is reported as inconclusive.

Learn more

Check your domain's CAA record

Free, no signup for a single scan. CAA is part of every full Nivaronix scan alongside SPF, DMARC, DNSSEC, headers, and TLS.

Scan your domain free

See everything Nivaronix's website security scanner checks