DNS record tool · CAA

CAA record lookup

Check CAA record answers through Cloudflare and Google without exposing a provider credential to the browser. Results remain separate so propagation and cache differences stay visible.

Human verification protects this service from automated spam and abuse.

Enter a hostname to inspect its CAA answers, TTL and DNSSEC authenticated-data signal.

Certificate issuance policy

CAA records let a domain restrict which certificate authorities may issue certificates. The issue tag applies to ordinary certificates, issuewild to wildcard certificates, and iodef can publish an incident-reporting destination. Absence of CAA does not mean TLS is insecure.

DNS answers are cached for their time to live. A lower TTL can make a planned change appear sooner, but it does not force every resolver to refresh immediately. Compare the hostname, value and TTL with the zone editor, then verify the authoritative source before assuming a public resolver is wrong.

Read the result responsibly

An empty answer does not always mean a configuration is broken. The requested name may intentionally omit this record type, a CNAME may redirect the lookup, a negative response may still be cached, or DNSSEC validation may have failed. Test the exact label, including any service prefix or subdomain.

IP CONFIG is a diagnostic viewer. It does not change DNS and cannot certify ownership, email delivery, TLS security or global propagation. Save the timestamp, resolver and full record value when escalating a problem to a registrar, DNS provider or hosting team.

Next diagnostic step

Compare related records before changing the zone

DNS services work as a chain. Address records depend on the correct hostname, mail routing relies on host addresses and policy TXT records, certificates can be affected by CAA, and every public answer depends on correct authoritative delegation. Use the DNS hub to compare another record type before editing production.

Open the complete DNS checker