Certificate rules for eu.wikipedia.org.
Which certificate authorities a domain allows, found the way the authorities themselves look, up through the parent domains.
Looking up…
What CAA does.
A CAA record lists the certificate authorities allowed to issue SSL certificates for a domain. Public authorities check it before they issue, so a domain that lists only the authorities it uses closes the door on a certificate obtained elsewhere by mistake or by an attacker.
How the check climbs.
An authority looks for CAA at the exact name first. If there is none, it tries the parent, then the parent's parent, and uses the first set it finds. So a CAA record on example.com also covers shop.example.com, unless the subdomain has its own. An alias (CNAME) is followed to its target. This page climbs the same way and shows where it found the rules.
The tags.
issue: this authority may issue certificates for the name.issuewild: rules for wildcard certificates (*.example.com). When present, they replaceissuefor wildcards.iodef: where an authority reports a refused request, as an email or web address.issue ";": no authority may issue at all.- Flag 128 ("critical"): an authority that does not understand the tag must refuse to issue.
No CAA record.
Without one, any public authority may issue once it has checked that you control the domain. Adding CAA is a small hardening step; list every authority your hosts use, or their automatic renewals will fail. Several records with the same tag add up: any of them allows issuance.
Questions people ask.
What is a CAA record?
A CAA record lists the certificate authorities allowed to issue SSL certificates for a domain. Public certificate authorities check it before they issue.
Do I need a CAA record?
No. Without one, any public certificate authority may issue for your domain. Adding one is a small hardening step that blocks certificates from authorities you do not use.
Why did my certificate renewal fail after I added CAA?
Your host's certificate authority is probably not listed. Many hosts use Let's Encrypt or Google Trust Services: add an issue record for every authority your hosts use.
Does a CAA record on my domain cover subdomains?
Yes. An authority checks the exact name first, then each parent, and uses the first CAA records it finds, unless a subdomain has its own.
Hivex index
Short names, still free to register.
Starting something new? Hivex keeps a live index of short, brandable .si names nobody has claimed yet, each checked with the registry.
From code, or an AI assistant.
The same lookup is a free JSON API, with no key and open CORS, and a tool any AI assistant that speaks MCP can call.
curl "https://hivex.si/api/v1/tools/dns?name=eu.wikipedia.org&type=CAA"More DNS tools
- DNS lookupAll records at once: A, AAAA, CNAME, MX, NS, TXT, CAA, SOA.
- MX lookupMail servers in priority order, the provider, SPF and DMARC at a glance.
- NS lookupName servers, the DNS host, SOA settings, and marketplace parking.
- TXT lookupSPF, DMARC, DKIM and verification tokens, joined and labelled.
- CNAME lookupThe full alias chain, the final addresses, and the platform behind it.
- DNS propagation checker13 public resolvers side by side, with how long each keeps its copy.
- Reverse DNSThe PTR hostname of an IPv4 or IPv6 address, checked both ways.
- DNS health checkEvery name server asked directly: one report, every check.
- DNSSEC checkerDS, keys and validation: where the chain of trust holds or breaks.
- Subdomain finderSubdomains from certificate logs, DNS and the archive.
- DNS historyPast IP addresses and hosts, from passive DNS.
- DNS setup helperThe records each platform asks for, checked live.
- Domain checkerIs a name free to register? Checked live on any extension.
Sources
- RFC 8659: DNS Certification Authority Authorization (CAA)
- Let's Encrypt: Certificate Authority Authorization (CAA)
By Hivex. Updated 10 October 2026. Lookups run live through Cloudflare's public resolver and are kept for at most five minutes.