RFC 6844: DNS Certification Authority Authorization (CAA) Resource Record
This RFC has been replaced. Do not implement against it for new work — it was formally obsoleted by RFC 8659.
Current version: RFC 8659 — DNS Certification Authority Authorization (CAA) Resource Record
In plain English — editorial summary, not part of the RFC
The Certification Authority Authorization (CAA) DNS Resource Record allows a DNS domain name holder to specify one or more Certification Authorities (CAs) authorized to issue certificates for that domain. CAA Resource Records allow a public Certification Authority to implement additional controls to reduce the risk of unintended certificate mis-issue. This document defines the syntax of the CAA record and rules for processing CAA records by certificate issuers. [STANDARDS-TRACK]
Document record
- Document ID
- RFC6844
- Published
- January 2013
- Authors
- P. Hallam-Baker; R. Stradling
- Status
- PROPOSED STANDARD
- Stream
- IETF
- Area
- sec
- Pages
- 18
- Also known as
- —
- Obsoleted by:
- RFC 8659
Topics
Referenced by
One later RFC formally updates or obsoletes part of this document.
Related documents
Ranked automatically by shared keywords, IETF area and stream — not by editorial selection.
- RFC 6841A Framework for DNSSEC Policies and DNSSEC Practice StatementsCurrent
January 2013
- RFC 6975Signaling Cryptographic Algorithm Understanding in DNS Security Extensions (DNSSEC)Current
July 2013
- RFC 6604xNAME RCODE and Status Bits ClarificationCurrent
April 2012
- RFC 7344Automating DNSSEC Delegation Trust MaintenanceUpdated
September 2014
- RFC 7646Definition and Use of DNSSEC Negative Trust AnchorsCurrent
September 2015
- RFC 5910Domain Name System (DNS) Security Extensions Mapping for the Extensible Provisioning Protocol (EPP)Current
May 2010
- RFC 7828The edns-tcp-keepalive EDNS0 OptionCurrent
April 2016
- RFC 8027DNSSEC Roadblock AvoidanceCurrent
November 2016
Also filed under
About this page
The document record above — title, authors, date, status, stream, area, relationships, DOI and errata — is imported verbatim from the public RFC Editor index. The “in plain English” section is editorial: written by The metasystema editorial team, not part of the RFC. Where the two differ, the RFC text governs.
Last checked against the RFC Editor index on . RFCs are never revised after publication; changes are issued as new documents.
Data sources · Editorial policy · Report a correction · What is an RFC?