A CAA record specifies exactly which Certificate Authorities are allowed to issue an SSL certificate for your domain — without one, any trusted CA can issue a certificate for your domain, which becomes a real risk if any single CA in the entire ecosystem is ever compromised.
CAA records restrict which Certificate Authorities can issue SSL certificates for your domain. Without one, any CA can issue a certificate for your domain — a significant security risk.
A CAA (Certification Authority Authorization) DNS record addresses a genuine, specific risk in the certificate issuance system — without this record, any certificate authority trusted by browsers generally can issue a valid SSL certificate for your domain, meaning a compromised or careless certificate authority, or an attacker who's compromised your domain's control at some level, could potentially obtain a fraudulent certificate.
This record explicitly restricts which specific certificate authorities are authorized to issue certificates for your domain — any certificate authority not listed in your CAA record should refuse to issue a certificate for your domain, and compliant certificate authorities check this record before issuance, providing a genuine additional layer of control beyond simply trusting the broader certificate authority ecosystem's overall security.
The real-world risk this record addresses, while relatively uncommon, has genuine documented precedent — certificate authorities have occasionally issued fraudulent or mistaken certificates due to internal errors or successful attacks against their own systems, and a CAA record specifically limits your domain's exposure to this category of risk by narrowing the pool of authorities capable of issuing valid certificates for your domain.
Implementation requires identifying which certificate authority you actually use for your legitimate certificates and configuring the CAA record accordingly — this is a genuinely low-effort, low-risk addition to your DNS configuration that provides real, if narrow, additional protection against a specific, documented category of certificate-related risk.
A CAA record exists, restricting certificate issuance to your actual certificate provider(s).
Fix it, then re-scan — the check confirms itself. No manual checkbox, the scan is the truth.
Run this check in H.I.V.E. →