CAA
CAA records (RFC 8659) declare which certificate authorities may issue certificates for your domain. CAs are required to check CAA before every issuance, so a tight allow-list blocks mis-issued certificates at the source.
Need to pin issuance to a specific ACME account or validation method? Use the
ACME binding (RFC 8657) fields below to add
accounturi=
and validationmethods= to your issue/issuewild rules –
for example 0 issue "letsencrypt.org; validationmethods=dns-01". From
15 March 2027 every publicly trusted CA must honour these parameters (CA/Browser Forum Baseline Requirements).
Runs entirely in your browser. Record Studio · Verify the result with the domain security check