Emergency server help: get in touch

CAA and TLSA Checker: Free CAA Record and DANE Test

Reads CAA records (including those inherited from parent domains), compares them with the CA of the live certificate, and checks TLSA records for HTTPS and the MX hosts against DNSSEC and the served certificate.

Status
Live
Last updated
October 3, 2026

This CAA and TLSA checker answers two questions that cause surprise certificate failures. First, which certificate authorities are allowed to issue for the domain, and will the next renewal from your current CA be accepted? Second, if you publish DANE TLSA records, are they protected by DNSSEC and do they still match the certificate the server presents?

Short answer: Enter a domain. The checker finds the CAA record set that applies (walking up to the parent domain if needed), lists the allowed issuers, and warns if the CA of the live HTTPS certificate is not among them, which would make the next renewal fail. It then looks up TLSA records for _443._tcp on the domain and _25._tcp on each MX host, confirms the zone is DNSSEC-validated, and compares DANE-EE records with the live HTTPS certificate.

CAA in practice

A CAA record such as example.com. CAA 0 issue "letsencrypt.org" tells every public CA that only Let’s Encrypt may issue certificates for the domain. Add one issue line per CA you use, an issuewild line if wildcards come from a different CA, and an iodef address for violation reports. cPanel AutoSSL uses Let’s Encrypt or Sectigo depending on the provider selected in WHM, so allow the one your server uses before adding CAA.

TLSA and DANE

TLSA records pin a certificate or public key in DNS. They only have an effect when the zone is signed with DNSSEC, which is why an unsigned zone with TLSA records is flagged as a failure rather than a pass. The common form is 3 1 1: DANE-EE, the server’s public key, SHA-256. Before rotating keys, publish the new TLSA record alongside the old one and wait for the TTL to expire.

# generate a 3 1 1 TLSA value from a certificate
openssl x509 -in cert.pem -noout -pubkey | openssl pkey -pubin -outform DER | sha256sum

When to use it

Run it before adding CAA records, after changing CA or CDN, and whenever an automated renewal fails with a CAA error. For mail servers using DANE, run it before every certificate renewal that changes the key.

CAA and TLSA checker at a glance

CAA and TLSA Checker summary card: Enter a domain. The checker finds the CAA record set that applies (walking up to the parent domain if needed), lists…
In short: Enter a domain. The checker finds the CAA record set that applies (walking up to the parent domain if needed), lists the allowed issuers, and warns if the CA of the live HTTPS certificate is not among them, which would make the next renewal fail.
CAA and TLSA Checker sections: CAA in practice, TLSA and DANE and When to use it
Covers: CAA in practice, TLSA and DANE and When to use it.
CAA and TLSA Checker questions answered: Can a CAA record break my existing certificate? Why is my TLSA record marked as failing when it is correct?
Answers: Can a CAA record break my existing certificate? Why is my TLSA record marked as failing when it is correct?

Official documentation: RFC 8659: CAA, RFC 7671: DANE operations.

Related tools: DNSSEC checker · SSL certificate checker · Domain health checker.

Frequently asked questions

Can a CAA record break my existing certificate?

No. CAs check CAA only when issuing. An existing certificate keeps working until it expires, but the next renewal fails if its CA is not allowed by the CAA records.

Why is my TLSA record marked as failing when it is correct?

DANE only works with DNSSEC. If the zone is not signed, validating resolvers ignore TLSA records, so the checker reports them as ineffective until DNSSEC is enabled at the DNS host and registrar.

Does Cloudflare support CAA records?

Yes. Cloudflare DNS supports CAA records, and when Universal SSL is enabled it adds the CAA entries its own certificate authorities need automatically.

Free website test

Is your website set up right?

Check SSL, security headers, redirects, robots.txt, sitemap, llms.txt and security.txt in one test. It takes about 30 seconds.