RFC 6844 · PROPOSED STANDARD · 2013

DNS Certification Authority Authorization Resource Record

Overview

RFC 6844, “DNS Certification Authority Authorization Resource Record”, is a Proposed Standard document published in January 2013 by P. Hallam-Baker, R. Stradling. It has been obsoleted by RFC 8659 — refer to the newer document for the authoritative version. The canonical text is published by the RFC Editor.

Abstract

The Certification Authority Authorization (CAA) DNS Resource Record allows a DNS domain name holder to specify one or more Certification Authorities (CAs) authorized to issue certificates for that domain. CAA Resource Records allow a public Certification Authority to implement additional controls to reduce the risk of unintended certificate mis-issue. This document defines the syntax of the CAA record and rules for processing CAA records by certificate issuers. [STANDARDS-TRACK]

Abstract as published in the RFC, via rfc-editor.org.

What “Proposed Standard” means

An entry-level standards-track specification: stable, peer-reviewed and a solid basis for implementation, though it may still evolve before becoming an Internet Standard.

Read this RFC

The canonical text of RFC 6844 is hosted at rfc-editor.org. Available in TXT,HTML.

Relationships to other RFCs
Obsoleted by
RFC 8659
Other RFCs from 2013

Who Is Online

In total there are 72 users online: 0 registered, 66 guests and 6 bots.

Most users ever online was 1,226 on 13 Jun 2026, 3:56 am.

Bots: AhrefsBot Applebot Googlebot Other Bot SemrushBot Sogou

Users active in the past 15 minutes. Total registered members: 354