CrawlCheck

Glossary · Security and privacy

CAA record

A DNS record naming which certificate authorities may issue certificates for a domain.

What CAA record means

A DNS record naming which certificate authorities may issue certificates for a domain. An authority that is not listed must refuse, which limits the damage of a compromised validation path; it does not affect certificates already issued and does nothing if no record exists.

What CAA record can and cannot support

It can supportIt cannot support
A DNS record naming which certificate authorities may issue certificates for a domain.An authority that is not listed must refuse, which limits the damage of a compromised validation path; it does not affect certificates already issued and does nothing if no record exists.

Related terms in Security and privacy

Where an agent, a tool or a page can be turned against its operator, and the controls that limit the damage without proving safety.

Indirect prompt injection · Direct prompt injection · Jailbreak · Data exfiltration · Sensitive information disclosure · Secret leakage · Insecure output handling · Excessive agency · Least privilege · Trust boundary · Input validation · Output validation · Allowlist · Denylist · SSRF · RCE · Credential scope · OAuth scope · API key · Bearer token · mTLS · Rate-limit policy · Audit log · PII · Data minimization · Purpose limitation · Retention period · Data residency · Tenant isolation · Threat model · DMARC · DMARC alignment · SPF · DKIM · MTA-STS · TLS-RPT · DNSSEC · hard bounce

Questions about CAA record

What is CAA record?

A DNS record naming which certificate authorities may issue certificates for a domain.

What does CAA record not show or guarantee?

An authority that is not listed must refuse, which limits the damage of a compromised validation path; it does not affect certificates already issued and does nothing if no record exists.

Which area of the glossary does CAA record belong to?

Security and privacy: Where an agent, a tool or a page can be turned against its operator, and the controls that limit the damage without proving safety.

← TLS-RPT  ·  DNSSEC →

See it in the full glossary · 668 terms across 19 areas.