Domains Help

Add a CAA record

Add a CAA record (Certification Authority Authorization record) to specify which certificate authority (CA) is allowed to issue SSL certificates for the domain. When issuing a certificate, all publicly trusted CAs are required to check and respect CAA records. If you need to authorize multiple certificate authorities, you can add one CAA record for each certificate authority. CAA record details are typically available through your SSL provider.

  1. Sign in to your GoDaddy Domain Portfolio. (Need help logging in? Find your username or password.)
  2. Select Screenshot showing the three-dot icon to select domain edit options Domain Edit Options next to your domain and then select Edit DNS. You may need to scroll down to see Edit DNS.
    screenshot showing the option for edit dns
  3. Select Add New Record.
    Screenshot showing the Add New Record button highlighted with a red rectangle
  4. Select CAA from the Type menu.
  5. Enter the details from your SSL provide for your new CAA record:
    • Name: The domain or subdomain for the CAA record. Enter @ to put the CAA record on your root domain.
    • TTL (Time to Live): The amount of time the server should cache information before refreshing. The default setting is 1 hour.
    • Flag: Choose one of the available options.
      • 0: Used for standard CAA records, where the Tag is issue, issuewild, or iodef.
      • 128: Used for non-standard CAA records, where the Tag is not issue, issuewild, or iodef.
    • Tag: Choose one of the available options, or manually enter the Tag.
      • issue: Explicitly authorizes a single certificate authority to issue any type of certificate for the hostname (the value entered in the Name field).
      • issuewild: Explicitly authorizes a single certificate authority to issue only a wildcard certificate for the hostname (the value entered in the Name field).
      • iodef: Specifies a method that certificate authorities can use to report invalid certificate requests.
      • Manually enter the tag if the Flag is set to 128.
        • Tag can only consists of letters and numbers.
        • Tag should be all lower case, but isn't explicitly case-sensitive.
    • Domain: Based on the Tag type you selected, enter the corresponding certificate authority or URI. Enter a semicolon (;) to prevent any CA from issuing the corresponding certificate type.
      • issue or issuewild: Enter the certificate authority allowed to generate a certificate for this domain.
        Internal Only Content: GoDaddy can issue certificates on domains when the Domain field is entered as or
      • iodef: Enter a full URI to specify the method certificate authorities can use to report invalid certificate requests, such as or
    • (Optional) Add Parameter: Select this option to enter additional specific parameters for your CAA record.
    • CAA RDATA: Enter the full CAA record from your SSL provider and we'll fill in the individual fields automatically. Or, after you fill in the individual fields, we'll provide the full CAA record here for you to copy.
  6. (Optional) Select Add More Records to add multiple DNS records at the same time. If you change your mind, select screenshot of the icon for deleting a dns record Delete to remove any records that haven't been saved yet.
  7. Select Save to add your new record. If you added multiple records at the same time, select Save All Records.

Most DNS updates take effect within an hour but could take up to 48 hours to update globally.

Related step

  • If there are no CAA records on your domain, any certificate authority is authorized to issue a certificate for the domain. Entering a single blank issue tag prevents all certificate authorities from issuing any certificates on your domain.
  • Edit an existing CAA record if you need to make any changes.
  • Create a DNS template to quickly apply DNS records to your domains.

More info