DNS Certification Authority Authorization
| Abbreviation | CAA |
|---|---|
| Status | Proposed Standard |
| First published | October 18, 2010 |
| Latest version | RFC 8659 November 2019 |
| Organization | IETF |
| Authors |
|
| Base standards | Domain Name System |
| Domain | Internet security |
DNS Certification Authority Authorization (CAA) is an Internet security policy mechanism for domain name registrants to indicate to certificate authorities whether they are authorized to issue digital certificates for a particular domain name. Registrants publish a "CAA" Domain Name System (DNS) resource record which compliant certificate authorities check for before issuing digital certificates.
CAA was drafted by computer scientists Phillip Hallam-Baker and Rob Stradling in response to increasing concerns about the security of publicly trusted certificate authorities. It is an Internet Engineering Task Force (IETF) proposed standard.