Skip to content

Archive

Certificate Issuance

1 articles
Cybersecurity 15 Sep 2026 7 min read

CAA Records Constrain Public Certificate Issuance at the DNS Boundary

CAA Records Constrain Public Certificate Issuance at the DNS Boundary A public certificate can pass every browser check after issuance even if the domain operator never intended to use the certificate authority that created it. The Web PKI has several controls for detecting or responding to bad issuance, but DNS Certification Authority Authorization (CAA) acts earlier: it gives a domain holder a way to state which issuers are permitted to create certificates for a name.