RFC 8659: DNS Certification Authority Authorization (CAA) Resource Record
In plain English — editorial summary, not part of the RFC
The Certification Authority Authorization (CAA) DNS Resource Record allows a DNS domain name holder to specify one or more Certification Authorities (CAs) authorized to issue certificates for that domain name. CAA Resource Records allow a public CA to implement additional controls to reduce the risk of unintended certificate mis-issue. This document defines the syntax of the CAA record and rules for processing CAA records by CAs. This document obsoletes RFC 6844.
Document record
- Document ID
- RFC8659
- Published
- November 2019
- Authors
- P. Hallam-Baker; R. Stradling; J. Hoffman-Andrews
- Status
- PROPOSED STANDARD
- Stream
- IETF
- Area
- sec
- Pages
- 17
- Also known as
- —
- Obsoletes:
- RFC 6844
Topics
Related documents
Ranked automatically by shared keywords, IETF area and stream — not by editorial selection.
- RFC 9773ACME Renewal Information (ARI) ExtensionCurrent
June 2025
- RFC 8555Automatic Certificate Management Environment (ACME)Current
March 2019
- RFC 4211Internet X.509 Public Key Infrastructure Certificate Request Message Format (CRMF)Updated
September 2005
- RFC 4210Internet X.509 Public Key Infrastructure Certificate Management Protocol (CMP)Obsoleted
September 2005
- RFC 6010Cryptographic Message Syntax (CMS) Content Constraints ExtensionCurrent
September 2010
- RFC 8737Automated Certificate Management Environment (ACME) TLS Application-Layer Protocol Negotiation (ALPN) Challenge ExtensionCurrent
February 2020
- RFC 8410Algorithm Identifiers for Ed25519, Ed448, X25519, and X448 for Use in the Internet X.509 Public Key InfrastructureUpdated
August 2018
- RFC 9216S/MIME Example Keys and CertificatesCurrent
April 2022
Also filed under
About this page
The document record above — title, authors, date, status, stream, area, relationships, DOI and errata — is imported verbatim from the public RFC Editor index. The “in plain English” section is editorial: written by The metasystema editorial team, not part of the RFC. Where the two differ, the RFC text governs.
Last checked against the RFC Editor index on . RFCs are never revised after publication; changes are issued as new documents.
Data sources · Editorial policy · Report a correction · What is an RFC?