CAA Record Checker
Enter a domain and Nivaronix looks up its CAA (Certification Authority Authorization) record to report whether certificate issuance is restricted to specific CAs, or open to any public CA by default.
What this checker reports
- CAA records published — the domain names the specific certificate authorities allowed to issue for it; other CAs must refuse.
- No CAA record — nothing is published, so any public CA may issue a certificate for the domain. This is not an active vulnerability, it removes a cheap safety net rather than opening a hole.
- Status could not be determined — the CAA lookup timed out or a nameserver failed to answer; some older resolvers cannot return CAA records at all, and this is reported as inconclusive.
Learn more
Check your domain's CAA record
Free, no signup for a single scan. CAA is part of every full Nivaronix scan alongside SPF, DMARC, DNSSEC, headers, and TLS.
Scan your domain free