Loading network utility...
Loading network utility...
Specifies which Certificate Authorities (CAs) are permitted to issue SSL/TLS certificates for a domain.
Query any domain name to inspect authoritative CAA records, response latency, and TTL values.
Standard BIND representation of this record in authoritative master zone files:
The CAA (Certification Authority Authorization) record allows domain owners to specify exactly which Certificate Authorities (such as Let's Encrypt, DigiCert, or Sectigo) are authorized to issue SSL/TLS certificates for their domain. RFC 8659 requires all public CAs to check CAA records before issuing certificates, preventing rogue or unauthorized certificate generation.
Technical answers and configuration advice for DNS CAA records.
Deep-dive networking articles and protocol specifications related to this utility.
What is DNS (Domain Name System)? Learn how DNS lookup works in 4 stages: Recursive Resolver, Root Server, TLD Server, and Authoritative Nameserver.
A complete technical guide to the most important DNS record types, their syntax, TTL settings, and practical configuration examples.
Understand reverse DNS lookups, pointer (PTR) records, in-addr.arpa zones, and why rDNS is mandatory for email deliverability and server security.
High-speed, zero-cost engineering tools built for network diagnostics and developer workflows.
Detect IP, GeoIP, ISP, ASN & PTR
Reverse IP to PTR hostname & verify FCrDNS
Domain registrar & expiry info
Audit SPF, DKIM & DMARC records
Check global DNS record propagation across Anycast resolvers
Calculate CIDR, masks & host ranges