RFC 8659 · PROPOSED STANDARD · 2019

DNS Certification Authority Authorization Resource Record

Overview

RFC 8659, “DNS Certification Authority Authorization Resource Record”, is a Proposed Standard document published in November 2019 by P. Hallam-Baker, R. Stradling, J. Hoffman-Andrews. It obsoletes RFC 6844. The canonical text is published by the RFC Editor.

Abstract

The Certification Authority Authorization (CAA) DNS Resource Record allows a DNS domain name holder to specify one or more Certification Authorities (CAs) authorized to issue certificates for that domain name. CAA Resource Records allow a public CA to implement additional controls to reduce the risk of unintended certificate mis-issue. This document defines the syntax of the CAA record and rules for processing CAA records by CAs.

This document obsoletes RFC 6844.

Abstract as published in the RFC, via rfc-editor.org.

What “Proposed Standard” means

An entry-level standards-track specification: stable, peer-reviewed and a solid basis for implementation, though it may still evolve before becoming an Internet Standard.

Read this RFC

The canonical text of RFC 8659 is hosted at rfc-editor.org. Available in HTML,TXT,PDF,XML.

Relationships to other RFCs
This RFC obsoletes
RFC 6844
Other RFCs from 2019

Who Is Online

In total there are 66 users online: 0 registered, 62 guests and 4 bots.

Most users ever online was 1,226 on 13 Jun 2026, 3:56 am.

Bots: AhrefsBot Applebot Other Bot SemrushBot

Users active in the past 15 minutes. Total registered members: 354