CAA Record Helper

By SSLMate

Who Supports CAA?

If you want to publish a CAA record, your domain's DNS software (or provider) needs to support CAA. This page tells you which DNS software and providers support CAA.

If you don't want to publish a CAA record, it shouldn't matter whether or not your domain's DNS software supports CAA, since the DNS protocol provides a way to add new record types in a backwards compatible way. Unfortunately, some DNS software is broken and mishandles unsupported record types such as CAA. If your domain uses such DNS software, you may have trouble getting certificates for your domain.

Please open an issue if you have an addition to this page.

Software

Software/ProviderSupportComments
BINDYesPrior to version 9.9.6 use RFC 3597 syntax
dnsmasqYesUse --dns-rr option with hex data
Knot DNS≥2.2.0
ldns≥1.6.17
NSDYesPrior to version 4.0.1 use RFC 3597 syntax
OpenDNSSECYesWith ldns ≥1.6.17
PowerDNS≥4.0.0Versions 4.0.3 and below are buggy when DNSSEC is enabled.
Simple DNS Plus≥6.0
tinydnsYesUse generic record syntax
Windows Server 2016YesUse RFC 3597 syntax

Providers

Software/ProviderSupportComments
1&1Yes
123 RegNo
34SP.comYes
Afraid.org Free DNSYes
Alibaba Cloud DNSYes
AzureYes
BuddyNSYes
CloudflareYesCloudflare will add additional CAA records unless you disable Universal SSL.
CloudfloorDNSYes
ClouDNSYes
CloudXNSYes
Constellix DNSYes
core-networks.deYes
Crazy DomainsYes
deSECYes
Digital OceanYes
DNS Made EasyYes
DNSimpleYes
DNSPodYes
domaindiscount24Yes
Domeneshop (Domainnameshop)Yes
DreamhostYes
Dyn Managed DNSYes
easyDNSYes
Enom/TucowsNo
ezyreg.com (Netregistry)BrokenDoes not respond to CAA queries over UDP
FuturewebYes
GandiYes
Glauca HexDNSYes
GoDaddyYes
Google Cloud DNSYes
Google Domains DNSYes
GratisDNSYes
HetznerYes
hosting.deYes
HostwindsYes
HoverNo
http.netYes
Hurricane Electric Free DNSYes
InternapBrokenResponds to CAA queries with a SERVFAIL error
INWXYes
iwantmynameYesRequires opening a support ticket
Lightsail DNSNoRelevant forum thread
LinodeYes
LM DataBrokenResponds to CAA queries with a NOTIMP error
MetanameYes
Mythic BeastsYes
name.comNo
NameBrightNo
NamecheapYes
NameSiloYes
NetcupYes
Neustar UltraDNSYes
No-IP Dynamic DNSYes
NS1Yes
Nucleus NVYes
OpalstackYes
OVHYes
Pair DomainsYes
Rackspace Cloud DNSNo
Route 53Yes
schokokeks.orgYes
SoftLayerNo
STRATONo
UD MediaYes
UKFastYes
VultrYes
WebHostOneYes
ZiloreYes