CAA
CAA records (RFC 8659) declare which certificate authorities may issue certificates for your domain. A compliant CA must check CAA before every issuance (RFC 8659 §3), so a tight allow-list markedly reduces the risk of mis-issuance. It is not a hard block: CAA works only as far as issuers observe it (RFC 8659 §5), and after a CAA check a CA may still issue within the record’s TTL or 8 hours, whichever is greater (CA/Browser Forum BR §4.2.2.1) — so a tightened policy is not effective instantly. Keep watching Certificate Transparency as well.
accounturi=
and validationmethods= to your issue/issuewild rules –
for example 0 issue "letsencrypt.org; validationmethods=dns-01". Until
15 March 2027 processing these parameters is a SHOULD in the CA/Browser Forum Baseline
Requirements (§4.2.2.1.2), and RFC 8657 §5.2 says not to assume support without an
explicit statement from the CA; from 15 March 2027 every publicly trusted TLS CA must
process them.
Records are built in your browser; “Load current record” has our server look up your domain’s DNS. Record Studio · Verify the result with the domain security check