Enter your domain and abr.cloud reads its CAA records — the DNS rule that says which certificate authorities are allowed to issue certificates for you — and explains whether you're protected against mis-issuance and what to add.
One quick verification, no account. We store nothing unless you start monitoring.
A CAA (Certification Authority Authorization) record lists which CAs may issue TLS certificates for your domain. With no CAA record, any CA in the world can issue a certificate for you — so a mis-issued or fraudulent cert is easier to obtain. A tight CAA record is a simple, high-leverage guardrail.
letsencrypt.org).iodef mailto so you're notified of policy violations.issuewild).iodef contact for violation reports.issuewild entry.Yes — free with a quick CAPTCHA, no account. It reads only public DNS.
TLS still works without it, but CAA reduces the risk of a wrongly-issued certificate — a cheap extra guardrail most domains skip.
List each one you legitimately use; only the named CAs will be allowed to issue.
abr.cloud puts 80+ network & security tools behind one fast interface — with AI analysis and always-on monitoring.
open abr.cloud →