CAA narrows who may issue certificates
A CAA record is a note in your DNS saying which certificate authorities are allowed to issue for your domain.
Without it, any trusted authority in the world can issue for your name, which is a lot of organisations to depend on. With it, the others are supposed to refuse. It is a small record, costs nothing, and reduces the number of parties who can accidentally or maliciously vouch for you.
More on DNS and domains
- DNS is a directory, not proof of safetyIt only answers where
- DNSSEC signs answers but does not hide themA sealed postcard
- Encrypted DNS protects the resolver path, not the destinationCovered to the desk, open to the door
- Registrar compromise can outrank server securityIt all hangs from one fitting
- Registrar locks add friction to domain theftThe pin that makes them stop
- Dangling DNS can point to somebody else's resourceYour plate, their locker
