This CAA and TLSA checker answers two questions that cause surprise certificate failures. First, which certificate authorities are allowed to issue for the domain, and will the next renewal from your current CA be accepted? Second, if you publish DANE TLSA records, are they protected by DNSSEC and do they still match the certificate the server presents?
Short answer: Enter a domain. The checker finds the CAA record set that applies (walking up to the parent domain if needed), lists the allowed issuers, and warns if the CA of the live HTTPS certificate is not among them, which would make the next renewal fail. It then looks up TLSA records for _443._tcp on the domain and _25._tcp on each MX host, confirms the zone is DNSSEC-validated, and compares DANE-EE records with the live HTTPS certificate.
Table of Contents
CAA in practice
A CAA record such as example.com. CAA 0 issue "letsencrypt.org" tells every public CA that only Let’s Encrypt may issue certificates for the domain. Add one issue line per CA you use, an issuewild line if wildcards come from a different CA, and an iodef address for violation reports. cPanel AutoSSL uses Let’s Encrypt or Sectigo depending on the provider selected in WHM, so allow the one your server uses before adding CAA.
TLSA and DANE
TLSA records pin a certificate or public key in DNS. They only have an effect when the zone is signed with DNSSEC, which is why an unsigned zone with TLSA records is flagged as a failure rather than a pass. The common form is 3 1 1: DANE-EE, the server’s public key, SHA-256. Before rotating keys, publish the new TLSA record alongside the old one and wait for the TTL to expire.
# generate a 3 1 1 TLSA value from a certificate
openssl x509 -in cert.pem -noout -pubkey | openssl pkey -pubin -outform DER | sha256sum
When to use it
Run it before adding CAA records, after changing CA or CDN, and whenever an automated renewal fails with a CAA error. For mail servers using DANE, run it before every certificate renewal that changes the key.
CAA and TLSA checker at a glance



Official documentation: RFC 8659: CAA, RFC 7671: DANE operations.
Related tools: DNSSEC checker · SSL certificate checker · Domain health checker.
Frequently asked questions
Can a CAA record break my existing certificate?
No. CAs check CAA only when issuing. An existing certificate keeps working until it expires, but the next renewal fails if its CA is not allowed by the CAA records.
Why is my TLSA record marked as failing when it is correct?
DANE only works with DNSSEC. If the zone is not signed, validating resolvers ignore TLSA records, so the checker reports them as ineffective until DNSSEC is enabled at the DNS host and registrar.
Does Cloudflare support CAA records?
Yes. Cloudflare DNS supports CAA records, and when Universal SSL is enabled it adds the CAA entries its own certificate authorities need automatically.